chore(deps): use version 2.7.1 of jinjava #1152
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Here are snippets from
$ ./gradlew orca-web:dependencies
before:
after:
Note the following CVE exposure before this PR:
After this PR, all these are resolved. jinjava 2.7.1 brings in commons-net 3.9 and jsoup 1.15.3, though jsoup is shaded. See
https://github.com/HubSpot/jinjava/blob/jinjava-2.7.1/pom.xml#L34 and https://github.com/HubSpot/jinjava/blob/jinjava-2.7.1/pom.xml#L240.
Use version 2.7.1 of jinjava since it's the first version that fixes HubSpot/jinjava#429 via HubSpot/jinjava#1008.