Commit e40562e
authored
chore(deps): update dependency hugo to v0.167.0 (#2506)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [hugo](https://redirect.github.com/gohugoio/hugo) | tools | minor |
`0.166.0` → `0.167.0` |
---
### Release Notes
<details>
<summary>gohugoio/hugo (hugo)</summary>
###
[`v0.167.0`](https://redirect.github.com/gohugoio/hugo/releases/tag/v0.167.0)
[Compare
Source](https://redirect.github.com/gohugoio/hugo/compare/v0.166.0...v0.167.0)
This release brings relative partial references, slug support for branch
pages, and a handful of security hardening fixes.
**Relative partial references.** A partial name starting with `./` or
`../` is now resolved relative to the directory of the calling partial.
This makes it much easier to write self-contained, movable partial
trees, e.g. `{{ partial "./item.html" . }}` from within
`layouts/_partials/card/list.html`. Relative paths are only allowed from
within partials, and paths resolving outside the partials directory is
an error. See
[#​15373](https://redirect.github.com/gohugoio/hugo/issues/15373)
and the
[documentation](https://gohugo.io/functions/partials/include/#relative-paths).
**Slugs for section, taxonomy and term pages.** The `slug` front matter
now works for branch pages, not just regular pages, and it cascades to
descendants. This is particularly useful in multilingual sites, where
e.g. `content/help/_index.es.md` with `slug: ayuda` gives `/es/ayuda/`,
`/es/ayuda/avanzado/` etc. See
[#​14352](https://redirect.github.com/gohugoio/hugo/issues/14352).
**Other notable improvements** include the new
`build.cleanDestinationDir` config with `keepFiles`/`keepDirs` Glob
patterns
([#​14937](https://redirect.github.com/gohugoio/hugo/issues/14937),
[docs](https://gohugo.io/configuration/build/#clean-destination-directory)),
`hugo` now builds without a config file
([#​15393](https://redirect.github.com/gohugoio/hugo/issues/15393)),
exact numeric comparisons in `eq`, `where`, `in` and the set functions
([#​15322](https://redirect.github.com/gohugoio/hugo/issues/15322),
[#​15358](https://redirect.github.com/gohugoio/hugo/issues/15358)),
and automatic summaries that no longer end inside an open list or
blockquote
([#​14044](https://redirect.github.com/gohugoio/hugo/issues/14044)).
#### Security
This release contains several hardening fixes. None of them are known to
be exploited, but if you build sites with untrusted themes or modules,
you should upgrade.
- Sass imports not found in Hugo's file systems were resolved by the
Sass compiler itself, which follows symlinks and knows nothing about the
project root. A theme could import a file outside the project and get
its content into the published CSS. These imports are now resolved by
Hugo and checked against the same `security.allowRead` roots as the
Node.js tools and `js.Build`.
[`41040cc`](https://redirect.github.com/gohugoio/hugo/commit/41040cc7)
(thanks to [@​Hama1cco](https://redirect.github.com/Hama1cco))
- Likewise, imports not found in `/assets` were resolved and read by
ESBuild itself. The resolved path is now checked against the allowed
read paths before ESBuild loads it.
[`2aa51f3`](https://redirect.github.com/gohugoio/hugo/commit/2aa51f34)
(thanks to [@​Hama1cco](https://redirect.github.com/Hama1cco))
- A symlinked directory in a theme at the parent of a nested mount could
expose files outside the module.
[`2fe9bab`](https://redirect.github.com/gohugoio/hugo/commit/2fe9bab7)
- Explicit heading IDs (e.g. `## Foo {id="..."}`) were written unescaped
into the table of contents `href`, allowing attribute breakout.
[`671fbf2`](https://redirect.github.com/gohugoio/hugo/commit/671fbf2c)
#### Note
- The default `baseURL` is now `https://example.org/` (it was empty).
Hugo has always required a valid URL to work properly, so this mostly
affects new and test sites, but if you relied on the empty default for
relative URLs, set `baseURL` explicitly.
[`bc68654`](https://redirect.github.com/gohugoio/hugo/commit/bc686541)
[@​bep](https://redirect.github.com/bep)
[#​14625](https://redirect.github.com/gohugoio/hugo/issues/14625)
[#​15384](https://redirect.github.com/gohugoio/hugo/issues/15384)
- The root `cleanDestinationDir` config key is deprecated in favour of
`build.cleanDestinationDir.enable`. The `--cleanDestinationDir` flag
maps to the new key. Note that `.git` files in the publish dir are now
kept by default.
[`9086193`](https://redirect.github.com/gohugoio/hugo/commit/90861931)
[@​bep](https://redirect.github.com/bep)
[#​14937](https://redirect.github.com/gohugoio/hugo/issues/14937)
- `eq` now compares numeric values the same way as `lt`, `le` etc., so
e.g. `eq 1 1.0` is now `true`. Also, `in`, `intersect`, `union`, `uniq`,
`symdiff`, `complement` and `where`'s `in`/`not in` now compare numbers
exactly rather than via `float64`, and no longer require the Go types to
match.
[`4d628bb`](https://redirect.github.com/gohugoio/hugo/commit/4d628bbd)
[`366377b`](https://redirect.github.com/gohugoio/hugo/commit/366377b6)
[@​bep](https://redirect.github.com/bep)
[#​15322](https://redirect.github.com/gohugoio/hugo/issues/15322)
[#​15358](https://redirect.github.com/gohugoio/hugo/issues/15358)
- A user table render hook is now preferred over the embedded one.
[`140d936`](https://redirect.github.com/gohugoio/hugo/commit/140d9362)
[@​jmooring](https://redirect.github.com/jmooring)
[#​15389](https://redirect.github.com/gohugoio/hugo/issues/15389)
- Automatic summaries are expanded past `summaryLength` when needed so
they don't end inside an open container element. This may change the
summary for some pages.
[`d692a24`](https://redirect.github.com/gohugoio/hugo/commit/d692a243)
[@​bep](https://redirect.github.com/bep)
[#​14044](https://redirect.github.com/gohugoio/hugo/issues/14044)
#### Bug fixes
- hugolib: Fix failing integration test
[`fdbba5a`](https://redirect.github.com/gohugoio/hugo/commit/fdbba5a6)
[@​jmooring](https://redirect.github.com/jmooring)
- Fix build with Go 1.26 on Fedora 44 Beta
[`2782bfd`](https://redirect.github.com/gohugoio/hugo/commit/2782bfd3)
[@​flyn-org](https://redirect.github.com/flyn-org)
- Fix smartcrop with rotation
([#​15371](https://redirect.github.com/gohugoio/hugo/issues/15371))
[`5edd05b`](https://redirect.github.com/gohugoio/hugo/commit/5edd05bb)
[@​bep](https://redirect.github.com/bep)
[#​11266](https://redirect.github.com/gohugoio/hugo/issues/11266)
[#​15369](https://redirect.github.com/gohugoio/hugo/issues/15369)
- ci: Fix broken magefile
[`1d87ee5`](https://redirect.github.com/gohugoio/hugo/commit/1d87ee5b)
[@​bep](https://redirect.github.com/bep)
- tpl/collections: Fix union of slices with different numeric element
types
[`ffbcdba`](https://redirect.github.com/gohugoio/hugo/commit/ffbcdba9)
[@​hktitof](https://redirect.github.com/hktitof)
[#​15323](https://redirect.github.com/gohugoio/hugo/issues/15323)
- Fix stale page content when several files in the same dir change in
one batch
[`a374b86`](https://redirect.github.com/gohugoio/hugo/commit/a374b865)
[@​bep](https://redirect.github.com/bep)
[#​15330](https://redirect.github.com/gohugoio/hugo/issues/15330)
#### Improvements
- Update .gitignore
[`f6606f1`](https://redirect.github.com/gohugoio/hugo/commit/f6606f1f)
[@​bep](https://redirect.github.com/bep)
- tocss: Confine Sass import fallbacks to the allowed read paths
[`41040cc`](https://redirect.github.com/gohugoio/hugo/commit/41040cc7)
[@​bep](https://redirect.github.com/bep)
- js: Confine ESBuild's fallback resolver to the allowed read paths
[`2aa51f3`](https://redirect.github.com/gohugoio/hugo/commit/2aa51f34)
[@​bep](https://redirect.github.com/bep)
- commands: Allow building without a config file
[`c7f9999`](https://redirect.github.com/gohugoio/hugo/commit/c7f99993)
[@​bep](https://redirect.github.com/bep)
[#​15393](https://redirect.github.com/gohugoio/hugo/issues/15393)
- collections: Preserve slice type when appending an empty slice
[`dd16df1`](https://redirect.github.com/gohugoio/hugo/commit/dd16df14)
[@​jakezwang](https://redirect.github.com/jakezwang)
[#​11131](https://redirect.github.com/gohugoio/hugo/issues/11131)
- tpl/tplimpl: Prefer user table render hook over embedded
[`140d936`](https://redirect.github.com/gohugoio/hugo/commit/140d9362)
[@​jmooring](https://redirect.github.com/jmooring)
[#​15389](https://redirect.github.com/gohugoio/hugo/issues/15389)
- Avoid allocating in SitesMatrix.MatchSiteVector
[`83ab799`](https://redirect.github.com/gohugoio/hugo/commit/83ab7999)
[@​bep](https://redirect.github.com/bep)
- Add slug support for section, taxonomy and term pages
[`5d43ab7`](https://redirect.github.com/gohugoio/hugo/commit/5d43ab70)
[@​bep](https://redirect.github.com/bep)
[#​14352](https://redirect.github.com/gohugoio/hugo/issues/14352)
- tpl: Avoid reflect.Value.Call for common signatures
[`806a62e`](https://redirect.github.com/gohugoio/hugo/commit/806a62e8)
[@​bep](https://redirect.github.com/bep)
[#​15385](https://redirect.github.com/gohugoio/hugo/issues/15385)
- ci: Disable vet when running tests
[`8bac4de`](https://redirect.github.com/gohugoio/hugo/commit/8bac4de7)
[@​bep](https://redirect.github.com/bep)
- tpl/partials: Support relative partial paths from within partials
([#​15376](https://redirect.github.com/gohugoio/hugo/issues/15376))
[`bd1588b`](https://redirect.github.com/gohugoio/hugo/commit/bd1588bd)
[@​bep](https://redirect.github.com/bep)
[#​15373](https://redirect.github.com/gohugoio/hugo/issues/15373)
- config: Add build.cleanDestinationDir config
[`9086193`](https://redirect.github.com/gohugoio/hugo/commit/90861931)
[@​bep](https://redirect.github.com/bep)
[#​14937](https://redirect.github.com/gohugoio/hugo/issues/14937)
- commands: Make
testscripts/commands/hugo\_\_clean\_destination\_dir.txt portable
[`a74b753`](https://redirect.github.com/gohugoio/hugo/commit/a74b7539)
[@​bep](https://redirect.github.com/bep)
[#​8433](https://redirect.github.com/gohugoio/hugo/issues/8433)
- commands: Handle missing staticDir in cleanDestinationDir
[`07b9fba`](https://redirect.github.com/gohugoio/hugo/commit/07b9fba1)
[@​jmooring](https://redirect.github.com/jmooring)
[#​8433](https://redirect.github.com/gohugoio/hugo/issues/8433)
- hugofs: Cache symlink checks
[`09fa49b`](https://redirect.github.com/gohugoio/hugo/commit/09fa49be)
[@​bep](https://redirect.github.com/bep)
- hugofs: Drop symlinks in virtual ancestor dirs of nested mounts
[`2fe9bab`](https://redirect.github.com/gohugoio/hugo/commit/2fe9bab7)
[@​bep](https://redirect.github.com/bep)
- markup/tableofcontents: Escape heading IDs in ToC HTML
[`671fbf2`](https://redirect.github.com/gohugoio/hugo/commit/671fbf2c)
[@​bep](https://redirect.github.com/bep)
- hugofs: Allow symlinked mount roots in the main project
[`25f2856`](https://redirect.github.com/gohugoio/hugo/commit/25f2856a)
[@​bep](https://redirect.github.com/bep)
[#​15367](https://redirect.github.com/gohugoio/hugo/issues/15367)
- Expand and consolidate BOM trimming
[`cb6a707`](https://redirect.github.com/gohugoio/hugo/commit/cb6a7072)
[@​bep](https://redirect.github.com/bep)
[#​15355](https://redirect.github.com/gohugoio/hugo/issues/15355)
[#​15361](https://redirect.github.com/gohugoio/hugo/issues/15361)
- tpl/collections: Compare numbers exactly in set operations and where
[`366377b`](https://redirect.github.com/gohugoio/hugo/commit/366377b6)
[@​bep](https://redirect.github.com/bep)
[#​15358](https://redirect.github.com/gohugoio/hugo/issues/15358)
[#​15359](https://redirect.github.com/gohugoio/hugo/issues/15359)
- ci: Skip vet on Windows
[`10bb97b`](https://redirect.github.com/gohugoio/hugo/commit/10bb97ba)
[@​bep](https://redirect.github.com/bep)
- Revert "parser/metadecoders: Strip BOM from data prior to
unmarshalling"
[`51cd9e6`](https://redirect.github.com/gohugoio/hugo/commit/51cd9e6c)
[@​bep](https://redirect.github.com/bep)
- parser/metadecoders: Strip BOM from data prior to unmarshalling
[`ec578f0`](https://redirect.github.com/gohugoio/hugo/commit/ec578f0c)
[@​jmooring](https://redirect.github.com/jmooring)
[#​15355](https://redirect.github.com/gohugoio/hugo/issues/15355)
- tpl: Reformat templates with new formatter version
[`5698de9`](https://redirect.github.com/gohugoio/hugo/commit/5698de94)
[@​bep](https://redirect.github.com/bep)
- resources/page: Balance container tags in automatic summaries
[`d692a24`](https://redirect.github.com/gohugoio/hugo/commit/d692a243)
[@​bep](https://redirect.github.com/bep)
[#​14044](https://redirect.github.com/gohugoio/hugo/issues/14044)
[#​14927](https://redirect.github.com/gohugoio/hugo/issues/14927)
- config/security: Add an integration test
[`3be817e`](https://redirect.github.com/gohugoio/hugo/commit/3be817ed)
[@​bep](https://redirect.github.com/bep)
- tpl/compare: Consolidate numeric comparisions
[`4d628bb`](https://redirect.github.com/gohugoio/hugo/commit/4d628bbd)
[@​bep](https://redirect.github.com/bep)
[#​15322](https://redirect.github.com/gohugoio/hugo/issues/15322)
[#​15347](https://redirect.github.com/gohugoio/hugo/issues/15347)
- tpl/strings: Add a strings.FirstLower function
[`aaacd12`](https://redirect.github.com/gohugoio/hugo/commit/aaacd12c)
[@​jmooring](https://redirect.github.com/jmooring)
[#​15332](https://redirect.github.com/gohugoio/hugo/issues/15332)
- Update brevity guideline in AGENTS.md
[`881c0ec`](https://redirect.github.com/gohugoio/hugo/commit/881c0ec7)
[@​bep](https://redirect.github.com/bep)
#### Dependency Updates
- build(deps): bump github.com/olekukonko/tablewriter from 1.1.4 to
1.1.5
[`1567bde`](https://redirect.github.com/gohugoio/hugo/commit/1567bdef)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump github.com/dustin/go-humanize from 1.0.1 to 1.1.0
[`9e4059c`](https://redirect.github.com/gohugoio/hugo/commit/9e4059cf)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/tools from 0.49.0 to 0.50.0
[`8e3bbe6`](https://redirect.github.com/gohugoio/hugo/commit/8e3bbe67)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/image from 0.45.0 to 0.46.0
[`753c5fc`](https://redirect.github.com/gohugoio/hugo/commit/753c5fc1)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/text from 0.41.0 to 0.42.0
[`facde8a`](https://redirect.github.com/gohugoio/hugo/commit/facde8aa)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.45.0
[`c7e1a8e`](https://redirect.github.com/gohugoio/hugo/commit/c7e1a8e6)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
- deps: Bump github.com/bep/imagemeta from 1.0.0 to 1.0.1
([#​15338](https://redirect.github.com/gohugoio/hugo/issues/15338))
[`ec57bb7`](https://redirect.github.com/gohugoio/hugo/commit/ec57bb7d)
[@​dependabot](https://redirect.github.com/dependabot)\[bot]
[#​15324](https://redirect.github.com/gohugoio/hugo/issues/15324)
#### Documentation
- readme: Bump minimum Go version
[`7a46cd2`](https://redirect.github.com/gohugoio/hugo/commit/7a46cd2b)
[@​mikoxyz](https://redirect.github.com/mikoxyz)
#### Build Setup
- Update release image to Go 1.27.1
([#​15342](https://redirect.github.com/gohugoio/hugo/issues/15342))
[`34d8cdb`](https://redirect.github.com/gohugoio/hugo/commit/34d8cdb1)
[@​bep](https://redirect.github.com/bep)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent cce26b8 commit e40562e
2 files changed
Lines changed: 23 additions & 23 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
0 commit comments