chore(deps): update dependency hugo to v0.167.0 #63
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/hugo-0.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.161.1→0.167.0Release Notes
gohugoio/hugo (hugo)
v0.167.0Compare Source
This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.
Relative partial references. A partial name starting with
./or../is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g.{{ partial "./item.html" . }}from withinlayouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #15373 and the documentation.Slugs for section, taxonomy and term pages. The
slugfront matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g.content/help/_index.es.mdwithslug: ayudagives/es/ayuda/,/es/ayuda/avanzado/etc. See #14352.Other notable improvements include the new
build.cleanDestinationDirconfig withkeepFiles/keepDirsGlob patterns (#14937, docs),hugonow builds without a config file (#15393), exact numeric comparisons ineq,where,inand the set functions (#15322, #15358), and automatic summaries that no longer end inside an open list or blockquote (#14044).Security
This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.
security.allowReadroots as the Node.js tools andjs.Build.41040cc(thanks to @Hama1cco)/assetswere resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it.2aa51f3(thanks to @Hama1cco)2fe9bab## Foo {id="..."}) were written unescaped into the table of contentshref, allowing attribute breakout.671fbf2Note
baseURLis nowhttps://example.org/(it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, setbaseURLexplicitly.bc68654@bep #14625 #15384cleanDestinationDirconfig key is deprecated in favour ofbuild.cleanDestinationDir.enable. The--cleanDestinationDirflag maps to the new key. Note that.gitfiles in the publish dir are now kept by default.9086193@bep #14937eqnow compares numeric values the same way aslt,leetc., so e.g.eq 1 1.0is nowtrue. Also,in,intersect,union,uniq,symdiff,complementandwhere'sin/not innow compare numbers exactly rather than viafloat64, and no longer require the Go types to match.4d628bb366377b@bep #15322 #15358140d936@jmooring #15389summaryLengthwhen needed so they don't end inside an open container element. This may change the summary for some pages.d692a24@bep #14044Bug fixes
fdbba5a@jmooring2782bfd@flyn-org5edd05b@bep #11266 #153691d87ee5@bepffbcdba@hktitof #15323a374b86@bep #15330Improvements
f6606f1@bep41040cc@bep2aa51f3@bepc7f9999@bep #15393dd16df1@jakezwang #11131140d936@jmooring #1538983ab799@bep5d43ab7@bep #14352806a62e@bep #153858bac4de@bepbd1588b@bep #153739086193@bep #14937a74b753@bep #843307b9fba@jmooring #843309fa49b@bep2fe9bab@bep671fbf2@bep25f2856@bep #15367cb6a707@bep #15355 #15361366377b@bep #15358 #1535910bb97b@bep51cd9e6@bepec578f0@jmooring #153555698de9@bepd692a24@bep #14044 #149273be817e@bep4d628bb@bep #15322 #15347aaacd12@jmooring #15332881c0ec@bepDependency Updates
1567bde@dependabot[bot]9e4059c@dependabot[bot]8e3bbe6@dependabot[bot]753c5fc@dependabot[bot]facde8a@dependabot[bot]c7e1a8e@dependabot[bot]ec57bb7@dependabot[bot] #15324Documentation
7a46cd2@mikoxyzBuild Setup
34d8cdb@bepv0.166.0Compare Source
This release is mostly about hardening and bug fixes, but there are some notable changes:
.Rendernow takes an optional context argument:{{ .Render "view" $ctx }}, mirroring thepartialAPI. This makes it possible to pass e.g. a dict to a content view. See #15077.returnkeyword in templates has been reimplemented. It now works in any template (not just partials) and can be used anywhere, e.g. insideiforrangeblocks. See #15212.resources.Publishtemplate function andIndexOfmethod onPages.relatedconfig: newtokenizeoption for index values, and index creation is faster.Note
8d88b8b@bep #15267d19e0a4@bep #12536 #12543 #15266ec52e63@bep #15254c05c012@bepe6abb9c@bep6a2a955@bep #15301 #15302efd2456@bep #15273938c820@bep8405b80@bep #1521239507d5@ipince #4092 #3577 #5571 #4090Glob patterns
The glob library used for e.g. module mounts (
includeFiles,excludeFiles),cascadetargets,segments,deploymentmatchers andnoVendorhas been upgraded to v1.0.0. This is a complete rewrite of the matching engine that fixes a long list of correctness bugs, but it also means that some patterns may behave differently:{, an empty[]class) now fail with a syntax error instead of being silently accepted.**matches any sequence of characters including separators, but it is not the**/"globstar" of shells:**/xrequires the literal/and does not matchx, anda/**/bdoes not matcha/b. Use{**/,}xif you need both.\is the escape character, so a literal backslash must be written as\\.If a pattern that used to match no longer does (or vice versa), it was most likely relying on a bug in the old engine.
Security
text/orgcontent is now denied by default, as Org mode's export blocks and@@html:...@@snippets pass raw HTML through unescaped, making it the same XSS sink astext/html. Sites with Org content can opt back in viasecurity.allowContent.resources.GetRemoteetc.) now validate the resolved address at dial time and reject loopback, private, link-local, CGNAT and similar ranges. This only applies under the defaultsecurity.http.urlsallowlist; if you have customized it, you have opted into your own hosts and the check stands down. Proxies fromHTTP_PROXY/HTTPS_PROXYhide the destination address from this check and are now ignored unless you setsecurity.http.proxyFromEnvironment = true.security.node.permissions.allowRead.themes/mytheme/assets -> /somewhere/else) are now dropped. This closes a gap in thethemes/confinement; absolute mountsourcevalues are still allowed.Other
{{ return <value> }}outside a partial is now an error; it was previously silently ignored.slugwhose title contains a/(e.g.Watch/listen to this) now gets a single URL segment (.../watch-listen-to-this/) instead of a nested one (.../watch/listen-to-this/). Taxonomy and term pages are not affected.KaTeX
When upgrading to Hugo v0.166.0, sites using
transform.ToMathwith theoutputoption set tohtmlorhtmlAndMathmlmust update the KaTeX stylesheet referenced in their template(s) to version 0.18.4 or higher. Using older CSS versions like 0.16.21 will cause certain mathematical or chemical expressions to render incorrectly.Example update:
See these examples:
Bug fixes
ae07063@youdie0065130d00@youdie0067785668@bep #12536 #12543efe5cbc@jmooring #152617b5199f@bep87260e4@jmooring #1522349dceb1@bep #152075e70992@jmooring #15206Improvements
857120b@bep #15307938c820@bep3b2d3b8@bep9c2527f@bepa36bd27@bep24d5e42@bep9e7c978@bep #125436b5b7d8@bep #1254362e24b7@bep #12536 #12543f61346e@bep850f11c@jmooring #7515 #1519939507d5@ipince #4092 #3577 #5571 #409090fe506@jmooring #1525349835f8@Soundcreates #15234d6e6f9e@bep #15247e4dc48c@bep #15247bcde806@bep #15077df4ac34@bep #15245166d3ee@Soundcreates #15237a25af7f@Shiwang0-0 #15027723579f@bep85ad5e4@bepe31ff54@bep #152288405b80@bep #15212bf05832@Shiwang0-0 #13589a05736c@bep #15208423e9ce@jmooring #15271 #15280Dependency Updates
3fbfd27@dependabot[bot]393de58@dependabot[bot]870f746@dependabot[bot]6152e22@dependabot[bot]5b6e7c2@dependabot[bot]dc03bb2@dependabot[bot]701dd33@dependabot[bot]b4062c8@dependabot[bot]cdd1627@dependabot[bot]efd2456@bep #15273d462968@dependabot[bot]fd5f7c6@dependabot[bot]6b33517@dependabot[bot]5f0d88b@dependabot[bot]9171dae@dependabot[bot]d1ee825@dependabot[bot]v0.165.0Compare Source
The two main new things is the new
css.ChromaStylestemplate func and the newimportContextoption demonstrated below.The
importContextis relevant forcss.Build,js.Build,css.Sass, andcss.PostCSS. and it allows you to make resources (e.g. built fromresources.FromString) resolvable in e.g. CSS@importstatements.Note
8a55df7@bep #15178 #15171Bug fixes
f772998@bep #151892ffaf1f@bepa808f6e@bep #151746bf1524@bep #15130f961093@jmooring #15121984358f@jmooring #15114Improvements
995a215@bep #15189 #15189f88f0a9@bep #1516952c9bd7@bep44da086@bep #1517333d1f2c@bep #1516764da6d7@bep #1516170db201@bep #151038a468df@bep615e45d@bep #15112a243a61@Soundcreates7d90277@bep861ede6@bep #15101f228c87@bep7df45f6@bep89b8c32@jmooring #15116Dependency Updates
0bb337b@dependabot[bot]03dc917@dependabot[bot]c829b73@dependabot[bot]94f3908@dependabot[bot]75fcc75@dependabot[bot]b5fa03d@dependabot[bot]9da472d@dependabot[bot]635532a@dependabot[bot]9c71f60@dependabot[bot]420527f@dependabot[bot]7fe786e@dependabot[bot]03b244f@dependabot[bot]9611813@dependabot[bot]e35b7f0@dependabot[bot]0796fa7@dependabot[bot]1b701b7@dependabot[bot]a32d70b@dependabot[bot]948cfb9@dependabot[bot]8930802@dependabot[bot]Documentation
dd3f273@bep #15190d1f191c@jmooringv0.164.0Compare Source
Notable new features in this release are:
Notes
29ed932@bep #15086Changes
5a5f4a5@bepd83ce27@bep #15056c6acc24@bep #534929ed932@bep #15086671897a@bejaratommy #11794499794d@sjh9714 #1507865c8217@bepdfb35dc@bep #15072a5ec542@bep #15068 #15060e46d37a@jmooring #15057fe06735@jmooring #15052128fb17@jmooring #15062Dependency Updates
921db7b@dependabot[bot]786ce71@dependabot[bot]5ad2846@dependabot[bot]36ad9f5@dependabot[bot]7c0a0bc@dependabot[bot]a879ebf@dependabot[bot]332d5ec@dependabot[bot]212cc11@dependabot[bot]884439b@bep #15033790a8aa@bep #15017v0.163.3Compare Source
What's Changed
ce1a7e0@bep thanks to @k0ngj1 for reporting this issue.70a9068@bep9d66d51@jmooring #15039 #15040 #15043f013346@jmooring #15046v0.163.2Compare Source
What's Changed
134674f@bep #15041147f605@jmooring #14222v0.163.1Compare Source
The majority of the fixes in this release are security related (including the upstream fix in
93c8c7d(golang.org/x/image)). Thanks to @vnth4nhnt for finding the issues fixed ina00b5c7andcf9c8f9(I will do the CVE work on this later). There has been a uptick in security reports lately, which doesn't mean that Hugo has gotten less secure, this is mostly the work of the new and powerful AI tools using Hugo's restrictive security model as their baseline. Just take a look at Go's recent security issue list to see a demonstration of this.What's Changed
93c8c7d@dependabot[bot]95e5e9f@bep #15024a00b5c7@bepcf9c8f9@bep #150192602796@jmooring #15012v0.163.0Compare Source
The main topic in this release is improvements to the AVIF image handling that we introduced in
v0.162.0. See the docs for details, but:qualityfor AVIF to 60. Turns out, JPEG/WebP with quality 75 is comparable to AVIF with quality 60. You can now also set quality per image format in your project config (and also per image processed if needed).hintto the AVIF with the same values as forWEBP. Forlossycompression, the photo/picture hints (and the default) encodes with YUV420 chroma subsampling instead of YUV444, keeping 444 for text/icon/drawing. This greatly reduces the memory needed to encode these images.Improvements
ff2903a@bep #14991 #14996ca68936@jmooring781fabf@bep1d018ef@anupamojha-eng #14999121bc6c@bepcf18b82@bep #1499898ad9b3@bep #14997b89e7fe@bep #11574e8fefc8@bep #14990a043d3e@bep #14992341f575@bep #14987248241b@bep #149814e47d95@bep #1497903b4b54@bep #1497979be053@bep #149830f44046@bep #149774e17421@bep #14985b01ecd4@bep #1495745c00b7@jmooring #14936 #14950 #1496528d882a@bepDependency Updates
0d29fc8@dependabot[bot]bb57404@dependabot[bot]7d1b1fb@dependabot[bot]77a1147@dependabot[bot]v0.162.1Compare Source
What's Changed
59f35cd@jmooring #14959c270975@bep #14958ea8b48a@jmooring #14948v0.162.0Compare Source
The notable new feature in this release is support for AVIF images (both encoder and decoder). There's a demo site set up that demonstrates the difference between HDR AVIF and SDR JPEG images. Note that that demo is only really interesting if viewed on an HDR capable screen (e.g. Apple Retina).
Security fixes
There are some notable security fixes in this release.
Security fixes in Go
This release upgrades from Go 1.26.1 to 126.3, which brings a set of security fixes. Some relevant for Hugo are:
Security fixes and hardening in Hugo
The following changes either fix a concrete issue or reduce the default attack surface of
hugobuilds.text/htmlcontent files by default (e41a064). A newsecurity.allowContentpolicy gates which content media types may be used for pages under/content.text/htmlis denied by default; sites that rely on hand-authored or adapter-emitted HTML content can opt back in withsecurity.allowContent = ['.*'].security.http.urlson every redirect hop inresources.GetRemote(86fbb0f).resources.Get(f8b5fa0).We will update this section later with links to CVEs where applicable.
All changes
df54219@bep #149424bc7cae@bep5d51b82@jmooring #1492181d7762@jmooring #14795 #14906f8b5fa0@bep88d838a@xndvaz #14831e41a064@bep90d9f81@bep #783780e6084@jmooring #14944aeb9a5c@bep #14939c4bbc28@bepd8c7021@jmooring #14932ee4f1ac@bep #14855b613365@bep #11872d2c821b@bep4ed7600@bepcbe4339@bep #149126475d30@bep #14912 #1491767aede4@bep87f194b@bep #14897d81e3c2@bep #148977c65a4d@bepd31a927@bepc36608c@jmooring #149092f361a8@xndvaz #148865559263@jmooring #13869656fc04@bep #14062a20cb5b@bep #148984d775cb@bep #13492ae7bf74@bep #13987ba5d812@bep #12899 #14882be4a0df@bepe4cf565@bep9e64953@xndvaz #13737f0cfc28@xndvaz #1368816e854a@bep86fbb0f@bep #148717d4af7a@xndvaz #712828147cb@bep #14862e51e761@bep #148497011239@bep #14848694906f@cyphercodes #14820d27b9c0@ogulcanaydogan #1406262cef36@bep #14837ff22c62@jmooring #148174f444c8@dependabot[bot]fe6c726@dependabot[bot]6a2a038@dependabot[bot]cf1de59@dependabot[bot]97f990c@dependabot[bot]b99634e@dependabot[bot]fdd977e@dependabot[bot]123018d@dependabot[bot]b88fa8c@bep #14839Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
1dc7bcff81cf43ffa2d8chore(deps): update dependency hugo to v0.166.0to chore(deps): update dependency hugo to v0.167.0View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.