-
Notifications
You must be signed in to change notification settings - Fork 270
chore(deps): update dependency gohugoio/hugo to v0.152.2 #969
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/gohugoio-hugo-0.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
f628f70 to
c9c3a0a
Compare
c9c3a0a to
9b871d1
Compare
9b871d1 to
97c8a6b
Compare
97c8a6b to
6a03c81
Compare
6a03c81 to
4e312a2
Compare
4e312a2 to
baf55df
Compare
baf55df to
724f931
Compare
724f931 to
4d4d6d5
Compare
4d4d6d5 to
333a5f4
Compare
333a5f4 to
10b3e59
Compare
10b3e59 to
83c4700
Compare
83c4700 to
3de403c
Compare
3de403c to
73d18a8
Compare
73d18a8 to
cdff3c4
Compare
cdff3c4 to
ff8424c
Compare
8c30415 to
b4b0326
Compare
b4b0326 to
70534f1
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.147.2->v0.152.2Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.152.2Compare Source
In
v0.152.0we tightened the source validation for file mounts. We always said that project mounts can mount with absolute file/directorynames, modules/themes are restricted to relative. Inv0.152.0we narrowed module/themes mounts to be local, which made the setup in the bug report listed below fail:One part of this is security. But the construct above is usually very odd (the project uses files in a theme/module, not the other way around) and not very portable. But the example above demonstrates a valid exception, that we now have added support for in a portable way. The above example now works as it did before
v0.152.0, but going forward you can also write:We now have the
node_modulesas a special case: For themes/modules we first check if the mounted source exists locally, if not we try relative to the project root.What's Changed
1c8c21e@jmooring #14086809ebe0@bep #1408908a0679@jordelverv0.152.1Compare Source
These fixes are are all related to the YAML library upgrade in v0.152.0.
e08278d@bep #14079df4f80d@bep #14081d4c7888@bep #1407929e2c2f@bep #140780579afc@bep #14074v0.152.0Compare Source
The big new thing and the motivation behind this release is the upgrade to a more modern YAML library in @goccy 's github.com/goccy/go-yaml. It's been a surprisingly long and winding road to get here. Note that this upgrade comes with some minor breaking changes, most notably that the old YAML 1.1 spec listed a set of strings that, when unquoted, were treated as boolean
trueorfalse. So if you're using any of the values in the table below as booleans, you need to adjust your YAML, but I suspect that fixing this very surprising behavior will fix more issues than it introduces. A big new thing with this new YAML library is the support for YAML anchors and aliases which helps to reduce duplication in e.g. your configuration. There are some examples in Hugo's release build configuration and in the Hugo's CI release setup.yes,Yes,YES,y,Y,on,On,ONtrue(bool)yes,Yes,YES,y,Y,on,On,ON(string)no,No,NO,n,N,off,Off,OFFfalse(bool)no,No,NO,n,N,off,Off,OFF(string)Note
a3d9548@bep #8822 #13043 #14053Improvements
a130770@bep #140729425b93@bep #14072bd50c9c@bep #14067a8e0ca9@bep #14069559a029@jmooring #140615bad0d5@bep #14061Dependency Updates
184b10e@bep9e344bb@dependabot[bot]Build Setup
d51adca@bepv0.151.2Compare Source
What's Changed
989454a@bep #140541e91e46@bep #14054v0.151.1Compare Source
This release is mostly motivated by some upstream security fixes:
net/htmlpackage also has one security patchI, @bep, have inspected the above issues, and none of them seem to be relevant for Hugo, but we understand that many want to have a clean security report.
Bug fixes
88aea56@oishikazuo #14039a133393@bepImprovements
e2fb0b0@bep29cf874@imomaliev1b4dd43@jmooring #140464414ef7@bep9197deb@bepDependency Updates
f4c1157@dependabot[bot]54075ac@dependabot[bot]8b52303@dependabot[bot]3d45d30@dependabot[bot]095157c@dependabot[bot]v0.151.0Compare Source
Some notable new features in Hugo v0.151.0 are:
Note
7fd6762@AndrewChubatiukImprovements and bug fixes
03b33ec@bep #14019b462980@jmooring #1143447678d8@jmooring #8045510d98b@bepc5dca3b@bep #13946ec463c0@bep105d3bc@toddy153e46ba5@bep #139904d13035@bepDependency Updates
584f052@dependabot[bot]b76d717@dependabot[bot]4d2743e@dependabot[bot]c20f70d@dependabot[bot]1b55621@dependabot[bot]106c8e6@dependabot[bot]9928122@dependabot[bot]9943c1b@dependabot[bot]7667573@dependabot[bot]d71c07c@dependabot[bot]v0.150.1Compare Source
What's Changed
64f4073@jmooring1140314@jmooring #13991404fd9e@jmooring #13988b1b0cde@maxkapur3eea082@maxkapurv0.150.0Compare Source
The big new feature in this relase is the new
versionconfig option on Module imports, which allows you to set the requested module version query directly in your Hugo configuration (e.g.hugo.toml). This is a feature that have been requested by many, and I (@bep) was reminded about it by this recent thread, which also outlines a common use case for this: Mounting multiple old versions/branches of API documentation into the project.What's Changed
d1f6a1d@dependabot[bot]747cf4a@bep #13964d8774d7@jmooring #13967 #139683b8947d@jmooringv0.149.1Compare Source
The main motivation behind this release is the Go 1.25.1 upgrade, which comes with a security fix. Hugo does not use the feature in question, but we understand that many Hugo users like to have a clean security report.
Note
Note that CSS minification now targets CSS3, removing certain optimizations that were specific to CSS2.
What's Changed
25c0f24@lzap4f2d2b2@bep #11843b8eb45c@bep #139521d90aff@bep #13960e751afa@PikachuTW #13950a09b8a6@jmooring #11893 #13947 #13948v0.149.0Compare Source
Hugo
v0.149.0comes with bug fixes and a set of new features/improvements, notably::sectionslugand:sectionslugs, especially useful in multilingual Hugo projects.--omitClassCommentsflag onhugo gen chromastylesformatoption in transform.UnmarshalNote
80e973e@bepBug fixes
bb4e66c@justuswilhelm #1259913b43e6@bep #1392587e100e@bepImprovements
84b5123@bep1ba8087@bep61ec7a2@bepc289fca@bepecdef2b@minxinyi12ace3a@DustinFischer #13788c14fddd@bep #13924 #13931186934f@bepbff4ddd@cuiweixie348aae9@Nigel239261482cf@jmooring #126055fdcc09@jmooring #134012216028@n1xx1 #13889ecc3dd1@n1xx1 #13887de4a7f1@bepDependency Updates
45ec2f8@dependabot[bot]84dd495@dependabot[bot]327bbc6@dependabot[bot]2447138@dependabot[bot]cfc38ec@bep #1391722e579e@dependabot[bot]b886615@dependabot[bot]885cd29@dependabot[bot]debf3c5@dependabot[bot]1649f31@dependabot[bot]ccd6a4b@dependabot[bot]6dc1a17@dependabot[bot]806d484@dependabot[bot]04ee1b9@dependabot[bot]7a86fe9@dependabot[bot]f5245a7@dependabot[bot]5029676@jmooring #13846Documentation
2912415@jmooring01b0eda@bepv0.148.2Compare Source
What's Changed
7ff5ec7@bep #138683937ab2@bep #138689c57af1@bep #13864d240a70@bepv0.148.1Compare Source
What's Changed
6f42cfb@bep #13853a84beee@bep #13846v0.148.0Compare Source
Note
b8ba33c@bep #4428 #7497f967212@bep #13829Bug fixes
1b4c423@jmooring #13830Improvements
3e2f1cd@bep #13839bba6996@bep90d397b@bep #569361e6c73@jenbroek #5693266d46d@pixel36584b3172@jmooring #13535cfc8d31@jmooring #13826dd6e2c8@davidejonesDependency Updates
0a5b870@dependabot[bot]94e2c27@dependabot[bot]e77b2ad@dependabot[bot]9487acf@dependabot[bot]1e9a0b9@dependabot[bot]v0.147.9Compare Source
Improvements and fixes
6a4a3ab@bep #1380636f6f98@bep #1381018a9ca7@jmooring #13351b6c8dfa@jmooring #138034217fee@jmooring #82094ef5720@bepDependency Updates
621ea42@dependabot[bot]34e8378@dependabot[bot]4d3ebe4@dependabot[bot]b5c0383@jmooringv0.147.8Compare Source
The primary motivation behind this release is to get the Docker package security patched and up to date.
Improvements
8e61f1f@bep #13783f37412a@bep #1378001241d5@jmooring #1353832eb1a8@bepDependency Updates
21a4a9a@dependabot[bot]7a4a479@dependabot[bot]54065b7@dependabot[bot]e333836@dependabot[bot]cc7bfee@dependabot[bot]v0.147.7Compare Source
Bug fixes
5273a88@bep #13767766a2e7@bep #13748843ffeb@jmooring #13755Improvements
6334948@bep #13735bff5d19@pixel365da370d3@pixel3656bd328c@bepDependency Updates
7525963@dependabot[bot]0df9f35@dependabot[bot]302e6a7@dependabot[bot]202fe0d@dependabot[bot]13e1617@bepv0.147.6Compare Source
What's Changed
e57dcd3@deiningeaf5ace@bep #137439ad26b6@bep #13740f471936@bep #13727013c8cf@jmooring #13729v0.147.5Compare Source
We have gotten some requests about updating the minifier library we use, so here you go @myitcv and others. I'm probably going to regret doing that particular upgrade on a Thursday, but so be it.
What's Changed
0c7b1a3@bep #13723970b887@dependabot[bot]v0.147.4Compare Source
What's Changed
a03a245@bep #137195a81a3a@bep #136996131782@bep #136986142bc7@bep #13715v0.147.3Compare Source
Mostly bug fixes here, but also a new template func to get a really big number. You can read about why that is useful in the documentation.
8142699@jmooring #13700bc98e7a@bep #13707c745a3e@bep #136929d1d8c8@jmooring #1370184d7a10@jmooring #13687325a0db@jmooring #13693Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.