This is an automated email from the ASF dual-hosted git repository.

jongyoul pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/zeppelin.git


The following commit(s) were added to refs/heads/master by this push:
     new ed6bbb9  ZEPPELIN-5690 use jinjava 2.5.4 due to cves (#4329)
ed6bbb9 is described below

commit ed6bbb982d4d106cad46c762c73d334fd004772c
Author: PJ Fanning <pjfann...@users.noreply.github.com>
AuthorDate: Mon Mar 28 16:55:09 2022 +0200

    ZEPPELIN-5690 use jinjava 2.5.4 due to cves (#4329)
    
    add comment to force rebuild
---
 scalding/pom.xml                         | 2 ++
 submarine/pom.xml                        | 2 +-
 zeppelin-plugins/launcher/docker/pom.xml | 2 +-
 3 files changed, 4 insertions(+), 2 deletions(-)

diff --git a/scalding/pom.xml b/scalding/pom.xml
index 4dc5914..54beb0b 100644
--- a/scalding/pom.xml
+++ b/scalding/pom.xml
@@ -47,6 +47,8 @@
       <name>Concurrent Maven Repo</name>
       <url>https://conjars.org/repo</url>
     </repository>
+
+    <!-- the twitter repo is unreliable 
(https://github.com/twitter/hadoop-lzo/issues/148) -->
     <repository>
       <id>twitter</id>
       <name>Twitter Maven Repo</name>
diff --git a/submarine/pom.xml b/submarine/pom.xml
index 65c2263..9de6ec7 100644
--- a/submarine/pom.xml
+++ b/submarine/pom.xml
@@ -34,7 +34,7 @@
     <!--library versions-->
     <interpreter.name>submarine</interpreter.name>
     <hadoop.version>${hadoop2.7.version}</hadoop.version>
-    <jinjava.version>2.4.0</jinjava.version>
+    <jinjava.version>2.5.4</jinjava.version>
     <squirrel.version>0.3.8</squirrel.version>
     <guava.version>24.1.1-jre</guava.version>
     <!--test library versions-->
diff --git a/zeppelin-plugins/launcher/docker/pom.xml 
b/zeppelin-plugins/launcher/docker/pom.xml
index 5adec5e..ab7ce31 100644
--- a/zeppelin-plugins/launcher/docker/pom.xml
+++ b/zeppelin-plugins/launcher/docker/pom.xml
@@ -48,7 +48,7 @@
     <dependency>
       <groupId>com.hubspot.jinjava</groupId>
       <artifactId>jinjava</artifactId>
-      <version>2.4.12</version>
+      <version>2.5.4</version>
     </dependency>
     <dependency>
       <groupId>com.spotify</groupId>

Reply via email to