We specify Jinja version both in repository_locations.bzl and various requirements.txt in the repository. Ideally we keep these in sync, e.g. to deal with security releases.
Ideally we can do this mechanically (e.g. presubmit check, single source of truth).