Also SQL injection attacks are not coming here, how does findbugs can asses that...
Nonconstant string passed to execute method on an SQL statement incorrectly marked