This is an automated email from the ASF dual-hosted git repository.
asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/jena-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new 41e128375 Staged site from advisory
(4bf1e20dc447851c22d38d7ad767b7410cfb0c51)
41e128375 is described below
commit 41e1283757738a897bacf66523072ae7046dd085
Author: jenkins <[email protected]>
AuthorDate: Mon Aug 3 15:27:37 2026 +0000
Staged site from advisory (4bf1e20dc447851c22d38d7ad767b7410cfb0c51)
---
content/download/maven.html | 32 ++++++--------------------------
content/index.json | 2 +-
content/security/advisories.html | 7 +++++++
content/sitemap.xml | 8 ++++----
4 files changed, 18 insertions(+), 31 deletions(-)
diff --git a/content/download/maven.html b/content/download/maven.html
index 03e5b8781..301694882 100644
--- a/content/download/maven.html
+++ b/content/download/maven.html
@@ -209,8 +209,8 @@ on a version of Jena:</p>
<div class="highlight"><pre tabindex="0"
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code
class="language-xml" data-lang="xml"><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"><dependency></span>
</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><groupId></span>org.apache.jena<span
style="color:#008000;font-weight:bold"></groupId></span>
</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><artifactId></span>apache-jena-libs<span
style="color:#008000;font-weight:bold"></artifactId></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><version></span>X.Y.Z<span
style="color:#008000;font-weight:bold"></version></span>
</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><type></span>pom<span
style="color:#008000;font-weight:bold"></type></span>
+</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><version></span>X.Y.Z<span
style="color:#008000;font-weight:bold"></version></span>
</span></span><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"></dependency></span>
</span></span></code></pre></div><p>This will transitively resolve all the
dependencies for you: <code>jena-core</code>,
<code>jena-arq</code>, <code>jena-tdb</code> and <code>jena-iri</code> and
their dependencies.</p>
@@ -219,24 +219,7 @@ on a version of Jena:</p>
<div class="highlight"><pre tabindex="0"
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code
class="language-xml" data-lang="xml"><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"><dependency></span>
</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><groupId></span>org.apache.jena<span
style="color:#008000;font-weight:bold"></groupId></span>
</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><artifactId></span>jena-text<span
style="color:#008000;font-weight:bold"></artifactId></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><version></span>X.Y.Z<span
style="color:#008000;font-weight:bold"></version></span>
-</span></span><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"></dependency></span>
-</span></span></code></pre></div><p>There is also a BOM (Bill of
Materials):</p>
-<div class="highlight"><pre tabindex="0"
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code
class="language-xml" data-lang="xml"><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"><dependencyManagement></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><dependency></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><groupId></span>org.apache.jena<span
style="color:#008000;font-weight:bold"></groupId></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><artifactId></span>jena-bom<span
style="color:#008000;font-weight:bold"></artifactId></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><version></span>X.Y.Z<span
style="color:#008000;font-weight:bold"></version></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><type></span>pom<span
style="color:#008000;font-weight:bold"></type></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><scope></span>import<span
style="color:#008000;font-weight:bold"></scope></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"></dependency></span>
-</span></span><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"></dependencyManagement></span>
-</span></span></code></pre></div><p>which uses
<code><type>pom</type></code> and
<code><scope>import</scope></code>.</p>
-<p>This gives version number for all artifacts so that an artifact can
-be included with needing to give version number for each artifact.</p>
-<div class="highlight"><pre tabindex="0"
style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code
class="language-xml" data-lang="xml"><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"><dependency></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><groupId></span>org.apache.jena<span
style="color:#008000;font-weight:bold"></groupId></span>
-</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><artifactId></span>jena-shacl<span
style="color:#008000;font-weight:bold"></artifactId></span>
+</span></span><span style="display:flex;"><span> <span
style="color:#008000;font-weight:bold"><version></span>x.y.z<span
style="color:#008000;font-weight:bold"></version></span>
</span></span><span style="display:flex;"><span><span
style="color:#008000;font-weight:bold"></dependency></span>
</span></span></code></pre></div><p>Please check for the latest versions.</p>
<h3 id="major-artifacts">Major Artifacts</h3>
@@ -253,11 +236,6 @@ structuring Jena development.</p>
<td><code>apache-jena-libs</code></td>
<td><code>pom</code></td>
<td>A POM artifact that may be referenced to pull in all the standard Jena
Libraries (Core, ARQ, IRI, and TDB) with a single dependency.</td>
- <tr>
- <td><code>jena-bom</code></td>
- <td><code>pom</code></td>
- <td>The Apache Jena BOM - uses for dependencyManagement and
-<p>A POM artifact that may be referenced to pull in all the standard Jena
Libraries (Core, ARQ, IRI, and TDB) with a single dependency.</td></p>
</tr>
<tr>
<td><code>apache-jena</code></td>
@@ -276,8 +254,8 @@ structuring Jena development.</p>
</tr>
<tr>
<td><code>jena-fuseki-main</code></td>
- <td><code>jar</code></td>
- <td>The java code for Fuseki server for embedded use.<td>
+ <td><code>war</code></td>
+ <td>Fuseki packaged for standalone and embedded use.<td>
</tr>
<tr>
<td><code>jena-text</code></td>
@@ -306,6 +284,8 @@ structuring Jena development.</p>
</td>
</tr>
</table>
+<p>There are also a number of artifacts used in development.
+The full list can be seen by browsing Maven</p>
<p><a href="https://repo1.maven.org/maven2/org/apache/jena/">Released Jena
artifacts</a></p>
<p>(This includes historic artifacts which are no longer active.)</p>
<p>You can run <code>mvn dependency:tree</code> to print the dependency
diff --git a/content/index.json b/content/index.json
index 719f10c71..3524b2c76 100644
--- a/content/index.json
+++ b/content/index.json
@@ -1 +1 @@
-[{"categories":null,"contents":"This page is historical \u0026ldquo;for
information only\u0026rdquo; - there is no Apache release of Eyeball and the
code has not been updated for Jena3.\nThe original source code is available. So
you\u0026rsquo;ve got Eyeball installed and you\u0026rsquo;ve run it on one of
your files, and Eyeball doesn\u0026rsquo;t like it. You\u0026rsquo;re not sure
why, or what to do about it. Here\u0026rsquo;s what\u0026rsquo;s going
on.\nEyeball inspects your model a [...]
\ No newline at end of file
+[{"categories":null,"contents":"This page is historical \u0026ldquo;for
information only\u0026rdquo; - there is no Apache release of Eyeball and the
code has not been updated for Jena3.\nThe original source code is available. So
you\u0026rsquo;ve got Eyeball installed and you\u0026rsquo;ve run it on one of
your files, and Eyeball doesn\u0026rsquo;t like it. You\u0026rsquo;re not sure
why, or what to do about it. Here\u0026rsquo;s what\u0026rsquo;s going
on.\nEyeball inspects your model a [...]
\ No newline at end of file
diff --git a/content/security/advisories.html b/content/security/advisories.html
index 5f5220c59..77b786a18 100644
--- a/content/security/advisories.html
+++ b/content/security/advisories.html
@@ -191,6 +191,13 @@ and relevant <a
href="#cves-in-jena-dependencies">Dependency CVEs</a>.</p>
addressed by the project. Per our policy above we advise users to always
utilise
the latest Jena release available.</p>
<p>Please refer to the individual CVE links for further details and
mitigations.</p>
+<p><strong>CVE-2026-61372 Web requests using SPARQL Update can escape file
restrictions</strong></p>
+<p><a href="https://www.cve.org/CVERecord?id=CVE-20-613372">CVE-2026-61372</a>
affects Jena
+up to version 6.1.0.</p>
+<p>URL references to local resources in SPARQL Update requests were not being
+correctly restricted, and could include access to data on the local
machine.</p>
+<p>Users are recommended to upgrade to version 6.2.0 where such URLs are
restricted
+to be HTTP or FTP URLs.</p>
<p><strong>CVE-2025-50151 - Configuration files uploaded by administrative
users are not checked properly</strong></p>
<p><a
href="https://www.cve.org/CVERecord?id=CVE-2025-50151">CVE-2025-50151</a>
affects Jena
Fuseki in versions up to 5.4.0.</p>
diff --git a/content/sitemap.xml b/content/sitemap.xml
index 48e746c04..09f4da09d 100644
--- a/content/sitemap.xml
+++ b/content/sitemap.xml
@@ -60,7 +60,7 @@
<lastmod>2024-10-18T14:24:57+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/security/advisories.html</loc>
- <lastmod>2026-07-24T11:22:34+01:00</lastmod>
+ <lastmod>2026-07-28T19:01:56+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/documentation/shacl/</loc>
<lastmod>2023-04-09T15:11:22+02:00</lastmod>
@@ -212,7 +212,7 @@
<lastmod>2026-06-05T12:41:47+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/download.html</loc>
- <lastmod>2026-08-03T15:49:33+01:00</lastmod>
+ <lastmod>2026-07-28T19:03:33+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/documentation/notes/event-handler-howto.html</loc>
<lastmod>2023-06-06T21:08:29+02:00</lastmod>
@@ -533,7 +533,7 @@
<lastmod>2023-02-12T15:23:22+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/security.html</loc>
- <lastmod>2026-07-24T11:22:34+01:00</lastmod>
+ <lastmod>2026-07-28T19:01:56+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/documentation/fuseki2/fuseki-security.html</loc>
<lastmod>2025-07-15T11:51:08+01:00</lastmod>
@@ -727,7 +727,7 @@
<lastmod>2024-03-17T17:44:27+00:00</lastmod>
</url><url>
<loc>https://jena.apache.org/download/maven.html</loc>
- <lastmod>2026-08-03T15:49:33+01:00</lastmod>
+ <lastmod>2025-07-15T11:51:08+01:00</lastmod>
</url><url>
<loc>https://jena.apache.org/tutorials/using_jena_with_eclipse.html</loc>
<lastmod>2023-11-23T00:10:28+01:00</lastmod>