chore(deps): update dependency gohugoio/hugo to v0.152.2 in .github/workflows/test.yml #245
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.151.0->0.152.2Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.152.2Compare Source
In
v0.152.0we tightened the source validation for file mounts. We always said that project mounts can mount with absolute file/directorynames, modules/themes are restricted to relative. Inv0.152.0we narrowed module/themes mounts to be local, which made the setup in the bug report listed below fail:One part of this is security. But the construct above is usually very odd (the project uses files in a theme/module, not the other way around) and not very portable. But the example above demonstrates a valid exception, that we now have added support for in a portable way. The above example now works as it did before
v0.152.0, but going forward you can also write:We now have the
node_modulesas a special case: For themes/modules we first check if the mounted source exists locally, if not we try relative to the project root.What's Changed
1c8c21e@jmooring #14086809ebe0@bep #1408908a0679@jordelverv0.152.1Compare Source
These fixes are are all related to the YAML library upgrade in v0.152.0.
e08278d@bep #14079df4f80d@bep #14081d4c7888@bep #1407929e2c2f@bep #140780579afc@bep #14074v0.152.0Compare Source
The big new thing and the motivation behind this release is the upgrade to a more modern YAML library in @goccy 's github.com/goccy/go-yaml. It's been a surprisingly long and winding road to get here. Note that this upgrade comes with some minor breaking changes, most notably that the old YAML 1.1 spec listed a set of strings that, when unquoted, were treated as boolean
trueorfalse. So if you're using any of the values in the table below as booleans, you need to adjust your YAML, but I suspect that fixing this very surprising behavior will fix more issues than it introduces. A big new thing with this new YAML library is the support for YAML anchors and aliases which helps to reduce duplication in e.g. your configuration. There are some examples in Hugo's release build configuration and in the Hugo's CI release setup.yes,Yes,YES,y,Y,on,On,ONtrue(bool)yes,Yes,YES,y,Y,on,On,ON(string)no,No,NO,n,N,off,Off,OFFfalse(bool)no,No,NO,n,N,off,Off,OFF(string)Note
a3d9548@bep #8822 #13043 #14053Improvements
a130770@bep #140729425b93@bep #14072bd50c9c@bep #14067a8e0ca9@bep #14069559a029@jmooring #140615bad0d5@bep #14061Dependency Updates
184b10e@bep9e344bb@dependabot[bot]Build Setup
d51adca@bepv0.151.2Compare Source
What's Changed
989454a@bep #140541e91e46@bep #14054v0.151.1Compare Source
This release is mostly motivated by some upstream security fixes:
net/htmlpackage also has one security patchI, @bep, have inspected the above issues, and none of them seem to be relevant for Hugo, but we understand that many want to have a clean security report.
Bug fixes
88aea56@oishikazuo #14039a133393@bepImprovements
e2fb0b0@bep29cf874@imomaliev1b4dd43@jmooring #140464414ef7@bep9197deb@bepDependency Updates
f4c1157@dependabot[bot]54075ac@dependabot[bot]8b52303@dependabot[bot]3d45d30@dependabot[bot]095157c@dependabot[bot]Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.