Skip to content

chore(deps): update dependency hugo-extended to v0.167.0 - #2131

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/hugo-extended-0.x
Sep 30, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/hugo-extended-0.x

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
hugo-extended tools minor 0.166.0 → 0.167.0

Release Notes

gohugoio/hugo (hugo-extended)

v0.167.0

Compare Source

This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.

Relative partial references. A partial name starting with ./ or ../ is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g. {{ partial "./item.html" . }} from within layouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #​15373 and the documentation.

Slugs for section, taxonomy and term pages. The slug front matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g. content/help/_index.es.md with slug: ayuda gives /es/ayuda/, /es/ayuda/avanzado/ etc. See #​14352.

Other notable improvements include the new build.cleanDestinationDir config with keepFiles/keepDirs Glob patterns (#​14937, docs), hugo now builds without a config file (#​15393), exact numeric comparisons in eq, where, in and the set functions (#​15322, #​15358), and automatic summaries that no longer end inside an open list or blockquote (#​14044).

Security

This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.

  • Sass imports not found in Hugo's file systems were resolved by the Sass compiler itself, which follows symlinks and knows nothing about the project root. A theme could import a file outside the project and get its content into the published CSS. These imports are now resolved by Hugo and checked against the same security.allowRead roots as the Node.js tools and js.Build. 41040cc (thanks to @​Hama1cco)
  • Likewise, imports not found in /assets were resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it. 2aa51f3 (thanks to @​Hama1cco)
  • A symlinked directory in a theme at the parent of a nested mount could expose files outside the module. 2fe9bab
  • Explicit heading IDs (e.g. ## Foo {id="..."}) were written unescaped into the table of contents href, allowing attribute breakout. 671fbf2

Note

  • The default baseURL is now https://example.org/ (it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, set baseURL explicitly. bc68654 @​bep #​14625 #​15384
  • The root cleanDestinationDir config key is deprecated in favour of build.cleanDestinationDir.enable. The --cleanDestinationDir flag maps to the new key. Note that .git files in the publish dir are now kept by default. 9086193 @​bep #​14937
  • eq now compares numeric values the same way as lt, le etc., so e.g. eq 1 1.0 is now true. Also, in, intersect, union, uniq, symdiff, complement and where's in/not in now compare numbers exactly rather than via float64, and no longer require the Go types to match. 4d628bb 366377b @​bep #​15322 #​15358
  • A user table render hook is now preferred over the embedded one. 140d936 @​jmooring #​15389
  • Automatic summaries are expanded past summaryLength when needed so they don't end inside an open container element. This may change the summary for some pages. d692a24 @​bep #​14044

Bug fixes

Improvements

Dependency Updates

Documentation

Build Setup


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovatebot label Sep 29, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 29, 2026 16:03
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Rendered manifest diff — this PR vs main (desired state)

No changes to the rendered desired state. ✅

@renovate
renovate Bot force-pushed the renovate/hugo-extended-0.x branch 2 times, most recently from 903b9ec to ce12e6a Compare September 30, 2026 05:49
@renovate
renovate Bot force-pushed the renovate/hugo-extended-0.x branch from ce12e6a to 94046ce Compare September 30, 2026 05:59
@renovate
renovate Bot merged commit 299408d into main Sep 30, 2026
13 checks passed
@renovate
renovate Bot deleted the renovate/hugo-extended-0.x branch September 30, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants