Skip to content

chore(deps): update dependency gohugoio/hugo to v0.167.0 - #59

Merged
Stensel8 merged 1 commit into
mainfrom
renovate/build-tooling-versions
Sep 29, 2026
Merged

Stensel8 merged 1 commit into
mainfrom
renovate/build-tooling-versions

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
gohugoio/hugo minor 0.166.0 → 0.167.0

Release Notes

gohugoio/hugo (gohugoio/hugo)

v0.167.0

Compare Source

This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.

Relative partial references. A partial name starting with ./ or ../ is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g. {{ partial "./item.html" . }} from within layouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #​15373 and the documentation.

Slugs for section, taxonomy and term pages. The slug front matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g. content/help/_index.es.md with slug: ayuda gives /es/ayuda/, /es/ayuda/avanzado/ etc. See #​14352.

Other notable improvements include the new build.cleanDestinationDir config with keepFiles/keepDirs Glob patterns (#​14937, docs), hugo now builds without a config file (#​15393), exact numeric comparisons in eq, where, in and the set functions (#​15322, #​15358), and automatic summaries that no longer end inside an open list or blockquote (#​14044).

Security

This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.

  • Sass imports not found in Hugo's file systems were resolved by the Sass compiler itself, which follows symlinks and knows nothing about the project root. A theme could import a file outside the project and get its content into the published CSS. These imports are now resolved by Hugo and checked against the same security.allowRead roots as the Node.js tools and js.Build. 41040cc (thanks to @​Hama1cco)
  • Likewise, imports not found in /assets were resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it. 2aa51f3 (thanks to @​Hama1cco)
  • A symlinked directory in a theme at the parent of a nested mount could expose files outside the module. 2fe9bab
  • Explicit heading IDs (e.g. ## Foo {id="..."}) were written unescaped into the table of contents href, allowing attribute breakout. 671fbf2
Note
  • The default baseURL is now https://example.org/ (it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, set baseURL explicitly. bc68654 @​bep #​14625 #​15384
  • The root cleanDestinationDir config key is deprecated in favour of build.cleanDestinationDir.enable. The --cleanDestinationDir flag maps to the new key. Note that .git files in the publish dir are now kept by default. 9086193 @​bep #​14937
  • eq now compares numeric values the same way as lt, le etc., so e.g. eq 1 1.0 is now true. Also, in, intersect, union, uniq, symdiff, complement and where's in/not in now compare numbers exactly rather than via float64, and no longer require the Go types to match. 4d628bb 366377b @​bep #​15322 #​15358
  • A user table render hook is now preferred over the embedded one. 140d936 @​jmooring #​15389
  • Automatic summaries are expanded past summaryLength when needed so they don't end inside an open container element. This may change the summary for some pages. d692a24 @​bep #​14044
Bug fixes
Improvements
Dependency Updates
Documentation
Build Setup

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 51d7d66e-b367-4fcf-9dd6-bbb635b44698

📥 Commits

Reviewing files that changed from the base of the PR and between 9943103 and e288668.

📒 Files selected for processing (2)
  • .github/workflows/deploy-bunny.yml
  • .github/workflows/pr-checks.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

Both the deploy and PR-check workflows now use Hugo version 0.167.0 instead of 0.166.0.

Changes

Hugo Version Update

Layer / File(s) Summary
Update workflow Hugo versions
.github/workflows/deploy-bunny.yml, .github/workflows/pr-checks.yml
Both workflows change the configured Hugo version from 0.166.0 to 0.167.0.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to e2886

Both CI and deployment now use Hugo 0.167.0. The changed cleanup behavior remains disabled, and no concrete user-facing or deployment risk is established, so the update is ready to merge.

Architecture Summary

Architecture risk: 🔵 Low · up to e2886

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/deploy-bunny.yml: The workflow’s HUGO_VERSION changes from 0.166.0 to 0.167.0, updating the version used by the Hugo installation step.
  • observed — Modified behavior in .github/workflows/pr-checks.yml: The workflow’s Hugo version changed from 0.166.0 to 0.167.0.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description is relevant and detailed, but it does not use the required Summary, Type of change, Checklist, and Notes sections. It also does not complete the repository checklist. Rewrite the description using the repository template. Add a Summary section, select chore under Type of change, complete the applicable checklist items, and add Notes if needed. Preserve the Hugo 0.166.0 to 0.167.0 update details and relea…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the Hugo dependency update from 0.166.0 to 0.167.0, which matches the main changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Resolution

Rewrite the description using the repository template. Add a Summary section, select chore under Type of change, complete the applicable checklist items, and add Notes if needed. Preserve the Hugo 0.166.0 to 0.167.0 update details and release notes.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@Stensel8
Stensel8 merged commit cd13e84 into main Sep 29, 2026
11 of 14 checks passed
@renovate
renovate Bot deleted the renovate/build-tooling-versions branch September 29, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant