chore(deps): update dependency gohugoio/hugo to v0.167.0 - #59
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughBoth the deploy and PR-check workflows now use Hugo version 0.167.0 instead of 0.166.0. ChangesHugo Version Update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to Both CI and deployment now use Hugo 0.167.0. The changed cleanup behavior remains disabled, and no concrete user-facing or deployment risk is established, so the update is ready to merge. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkResolution Rewrite the description using the repository template. Add a Summary section, select chore under Type of change, complete the applicable checklist items, and add Notes if needed. Preserve the Hugo 0.166.0 to 0.167.0 update details and release notes.
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
This PR contains the following updates:
0.166.0→0.167.0Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.167.0Compare Source
This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.
Relative partial references. A partial name starting with
./or../is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g.{{ partial "./item.html" . }}from withinlayouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #15373 and the documentation.Slugs for section, taxonomy and term pages. The
slugfront matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g.content/help/_index.es.mdwithslug: ayudagives/es/ayuda/,/es/ayuda/avanzado/etc. See #14352.Other notable improvements include the new
build.cleanDestinationDirconfig withkeepFiles/keepDirsGlob patterns (#14937, docs),hugonow builds without a config file (#15393), exact numeric comparisons ineq,where,inand the set functions (#15322, #15358), and automatic summaries that no longer end inside an open list or blockquote (#14044).Security
This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.
security.allowReadroots as the Node.js tools andjs.Build.41040cc(thanks to @Hama1cco)/assetswere resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it.2aa51f3(thanks to @Hama1cco)2fe9bab## Foo {id="..."}) were written unescaped into the table of contentshref, allowing attribute breakout.671fbf2Note
baseURLis nowhttps://example.org/(it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, setbaseURLexplicitly.bc68654@bep #14625 #15384cleanDestinationDirconfig key is deprecated in favour ofbuild.cleanDestinationDir.enable. The--cleanDestinationDirflag maps to the new key. Note that.gitfiles in the publish dir are now kept by default.9086193@bep #14937eqnow compares numeric values the same way aslt,leetc., so e.g.eq 1 1.0is nowtrue. Also,in,intersect,union,uniq,symdiff,complementandwhere'sin/not innow compare numbers exactly rather than viafloat64, and no longer require the Go types to match.4d628bb366377b@bep #15322 #15358140d936@jmooring #15389summaryLengthwhen needed so they don't end inside an open container element. This may change the summary for some pages.d692a24@bep #14044Bug fixes
fdbba5a@jmooring2782bfd@flyn-org5edd05b@bep #11266 #153691d87ee5@bepffbcdba@hktitof #15323a374b86@bep #15330Improvements
f6606f1@bep41040cc@bep2aa51f3@bepc7f9999@bep #15393dd16df1@jakezwang #11131140d936@jmooring #1538983ab799@bep5d43ab7@bep #14352806a62e@bep #153858bac4de@bepbd1588b@bep #153739086193@bep #14937a74b753@bep #843307b9fba@jmooring #843309fa49b@bep2fe9bab@bep671fbf2@bep25f2856@bep #15367cb6a707@bep #15355 #15361366377b@bep #15358 #1535910bb97b@bep51cd9e6@bepec578f0@jmooring #153555698de9@bepd692a24@bep #14044 #149273be817e@bep4d628bb@bep #15322 #15347aaacd12@jmooring #15332881c0ec@bepDependency Updates
1567bde@dependabot[bot]9e4059c@dependabot[bot]8e3bbe6@dependabot[bot]753c5fc@dependabot[bot]facde8a@dependabot[bot]c7e1a8e@dependabot[bot]ec57bb7@dependabot[bot] #15324Documentation
7a46cd2@mikoxyzBuild Setup
34d8cdb@bepConfiguration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.