Update dependency gohugoio/hugo to v0.167.0 - #300
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/gohugoio-hugo-0.x
branch
from
October 1, 2026 17:15
05c7be0 to
aa59328
Compare
renovate
Bot
force-pushed
the
renovate/gohugoio-hugo-0.x
branch
from
October 1, 2026 21:48
aa59328 to
5223948
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.163.3→v0.167.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.167.0Compare Source
This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.
Relative partial references. A partial name starting with
./or../is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g.{{ partial "./item.html" . }}from withinlayouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #15373 and the documentation.Slugs for section, taxonomy and term pages. The
slugfront matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g.content/help/_index.es.mdwithslug: ayudagives/es/ayuda/,/es/ayuda/avanzado/etc. See #14352.Other notable improvements include the new
build.cleanDestinationDirconfig withkeepFiles/keepDirsGlob patterns (#14937, docs),hugonow builds without a config file (#15393), exact numeric comparisons ineq,where,inand the set functions (#15322, #15358), and automatic summaries that no longer end inside an open list or blockquote (#14044).Security
This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.
security.allowReadroots as the Node.js tools andjs.Build.41040cc(thanks to @Hama1cco)/assetswere resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it.2aa51f3(thanks to @Hama1cco)2fe9bab## Foo {id="..."}) were written unescaped into the table of contentshref, allowing attribute breakout.671fbf2Note
baseURLis nowhttps://example.org/(it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, setbaseURLexplicitly.bc68654@bep #14625 #15384cleanDestinationDirconfig key is deprecated in favour ofbuild.cleanDestinationDir.enable. The--cleanDestinationDirflag maps to the new key. Note that.gitfiles in the publish dir are now kept by default.9086193@bep #14937eqnow compares numeric values the same way aslt,leetc., so e.g.eq 1 1.0is nowtrue. Also,in,intersect,union,uniq,symdiff,complementandwhere'sin/not innow compare numbers exactly rather than viafloat64, and no longer require the Go types to match.4d628bb366377b@bep #15322 #15358140d936@jmooring #15389summaryLengthwhen needed so they don't end inside an open container element. This may change the summary for some pages.d692a24@bep #14044Bug fixes
fdbba5a@jmooring2782bfd@flyn-org5edd05b@bep #11266 #153691d87ee5@bepffbcdba@hktitof #15323a374b86@bep #15330Improvements
f6606f1@bep41040cc@bep2aa51f3@bepc7f9999@bep #15393dd16df1@jakezwang #11131140d936@jmooring #1538983ab799@bep5d43ab7@bep #14352806a62e@bep #153858bac4de@bepbd1588b@bep #153739086193@bep #14937a74b753@bep #843307b9fba@jmooring #843309fa49b@bep2fe9bab@bep671fbf2@bep25f2856@bep #15367cb6a707@bep #15355 #15361366377b@bep #15358 #1535910bb97b@bep51cd9e6@bepec578f0@jmooring #153555698de9@bepd692a24@bep #14044 #149273be817e@bep4d628bb@bep #15322 #15347aaacd12@jmooring #15332881c0ec@bepDependency Updates
1567bde@dependabot[bot]9e4059c@dependabot[bot]8e3bbe6@dependabot[bot]753c5fc@dependabot[bot]facde8a@dependabot[bot]c7e1a8e@dependabot[bot]ec57bb7@dependabot[bot] #15324Documentation
7a46cd2@mikoxyzBuild Setup
34d8cdb@bepv0.166.0Compare Source
This release is mostly about hardening and bug fixes, but there are some notable changes:
.Rendernow takes an optional context argument:{{ .Render "view" $ctx }}, mirroring thepartialAPI. This makes it possible to pass e.g. a dict to a content view. See #15077.returnkeyword in templates has been reimplemented. It now works in any template (not just partials) and can be used anywhere, e.g. insideiforrangeblocks. See #15212.resources.Publishtemplate function andIndexOfmethod onPages.relatedconfig: newtokenizeoption for index values, and index creation is faster.Note
8d88b8b@bep #15267d19e0a4@bep #12536 #12543 #15266ec52e63@bep #15254c05c012@bepe6abb9c@bep6a2a955@bep #15301 #15302efd2456@bep #15273938c820@bep8405b80@bep #1521239507d5@ipince #4092 #3577 #5571 #4090Glob patterns
The glob library used for e.g. module mounts (
includeFiles,excludeFiles),cascadetargets,segments,deploymentmatchers andnoVendorhas been upgraded to v1.0.0. This is a complete rewrite of the matching engine that fixes a long list of correctness bugs, but it also means that some patterns may behave differently:{, an empty[]class) now fail with a syntax error instead of being silently accepted.**matches any sequence of characters including separators, but it is not the**/"globstar" of shells:**/xrequires the literal/and does not matchx, anda/**/bdoes not matcha/b. Use{**/,}xif you need both.\is the escape character, so a literal backslash must be written as\\.If a pattern that used to match no longer does (or vice versa), it was most likely relying on a bug in the old engine.
Security
text/orgcontent is now denied by default, as Org mode's export blocks and@@html:...@@snippets pass raw HTML through unescaped, making it the same XSS sink astext/html. Sites with Org content can opt back in viasecurity.allowContent.resources.GetRemoteetc.) now validate the resolved address at dial time and reject loopback, private, link-local, CGNAT and similar ranges. This only applies under the defaultsecurity.http.urlsallowlist; if you have customized it, you have opted into your own hosts and the check stands down. Proxies fromHTTP_PROXY/HTTPS_PROXYhide the destination address from this check and are now ignored unless you setsecurity.http.proxyFromEnvironment = true.security.node.permissions.allowRead.themes/mytheme/assets -> /somewhere/else) are now dropped. This closes a gap in thethemes/confinement; absolute mountsourcevalues are still allowed.Other
{{ return <value> }}outside a partial is now an error; it was previously silently ignored.slugwhose title contains a/(e.g.Watch/listen to this) now gets a single URL segment (.../watch-listen-to-this/) instead of a nested one (.../watch/listen-to-this/). Taxonomy and term pages are not affected.KaTeX
When upgrading to Hugo v0.166.0, sites using
transform.ToMathwith theoutputoption set tohtmlorhtmlAndMathmlmust update the KaTeX stylesheet referenced in their template(s) to version 0.18.4 or higher. Using older CSS versions like 0.16.21 will cause certain mathematical or chemical expressions to render incorrectly.Example update:
See these examples:
Bug fixes
ae07063@youdie0065130d00@youdie0067785668@bep #12536 #12543efe5cbc@jmooring #152617b5199f@bep87260e4@jmooring #1522349dceb1@bep #152075e70992@jmooring #15206Improvements
857120b@bep #15307938c820@bep3b2d3b8@bep9c2527f@bepa36bd27@bep24d5e42@bep9e7c978@bep #125436b5b7d8@bep #1254362e24b7@bep #12536 #12543f61346e@bep850f11c@jmooring #7515 #1519939507d5@ipince #4092 #3577 #5571 #409090fe506@jmooring #1525349835f8@Soundcreates #15234d6e6f9e@bep #15247e4dc48c@bep #15247bcde806@bep #15077df4ac34@bep #15245166d3ee@Soundcreates #15237a25af7f@Shiwang0-0 #15027723579f@bep85ad5e4@bepe31ff54@bep #152288405b80@bep #15212bf05832@Shiwang0-0 #13589a05736c@bep #15208423e9ce@jmooring #15271 #15280Dependency Updates
3fbfd27@dependabot[bot]393de58@dependabot[bot]870f746@dependabot[bot]6152e22@dependabot[bot]5b6e7c2@dependabot[bot]dc03bb2@dependabot[bot]701dd33@dependabot[bot]b4062c8@dependabot[bot]cdd1627@dependabot[bot]efd2456@bep #15273d462968@dependabot[bot]fd5f7c6@dependabot[bot]6b33517@dependabot[bot]5f0d88b@dependabot[bot]9171dae@dependabot[bot]d1ee825@dependabot[bot]v0.165.0Compare Source
The two main new things is the new
css.ChromaStylestemplate func and the newimportContextoption demonstrated below.The
importContextis relevant forcss.Build,js.Build,css.Sass, andcss.PostCSS. and it allows you to make resources (e.g. built fromresources.FromString) resolvable in e.g. CSS@importstatements.Note
8a55df7@bep #15178 #15171Bug fixes
f772998@bep #151892ffaf1f@bepa808f6e@bep #151746bf1524@bep #15130f961093@jmooring #15121984358f@jmooring #15114Improvements
995a215@bep #15189 #15189f88f0a9@bep #1516952c9bd7@bep44da086@bep #1517333d1f2c@bep #1516764da6d7@bep #1516170db201@bep #151038a468df@bep615e45d@bep #15112a243a61@Soundcreates7d90277@bep861ede6@bep #15101f228c87@bep7df45f6@bep89b8c32@jmooring #15116Dependency Updates
0bb337b@dependabot[bot]03dc917@dependabot[bot]c829b73@dependabot[bot]94f3908@dependabot[bot]75fcc75@dependabot[bot]b5fa03d@dependabot[bot]9da472d@dependabot[bot]635532a@dependabot[bot]9c71f60@dependabot[bot]420527f@dependabot[bot]7fe786e@dependabot[bot]03b244f@dependabot[bot]9611813@dependabot[bot]e35b7f0@dependabot[bot]0796fa7@dependabot[bot]1b701b7@dependabot[bot]a32d70b@dependabot[bot]948cfb9@dependabot[bot]8930802@dependabot[bot]Documentation
dd3f273@bep #15190d1f191c@jmooringv0.164.0Compare Source
Notable new features in this release are:
Notes
29ed932@bep #15086Changes
5a5f4a5@bepd83ce27@bep #15056c6acc24@bep #534929ed932@bep #15086671897a@bejaratommy #11794499794d@sjh9714 #1507865c8217@bepdfb35dc@bep #15072a5ec542@bep #15068 #15060e46d37a@jmooring #15057fe06735@jmooring #15052128fb17@jmooring #15062Dependency Updates
921db7b@dependabot[bot]786ce71@dependabot[bot]5ad2846@dependabot[bot]36ad9f5@dependabot[bot]7c0a0bc@dependabot[bot]a879ebf@dependabot[bot]332d5ec@dependabot[bot]212cc11@dependabot[bot]884439b@bep #15033790a8aa@bep #15017Configuration
📅 Schedule: (UTC)
* * 1 */3 *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.