mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: bump github.com/gohugoio/hugo from 0.161.1 to 0.162.0 (#25698)
Bumps [github.com/gohugoio/hugo](https://github.com/gohugoio/hugo) from 0.161.1 to 0.162.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/gohugoio/hugo/releases">github.com/gohugoio/hugo's releases</a>.</em></p> <blockquote> <h2>v0.162.0</h2> <p>The notable new feature in this release is support for <a href="https://gohugo.io/configuration/imaging/#avif-images">AVIF images</a> (both encoder and decoder). There's a <a href="https://github.com/bep/hdrsdr.com">demo site</a> set up that demonstrates the difference between HDR AVIF and SDR JPEG images. Note that that demo is only really interesting if viewed on an HDR capable screen (e.g. Apple Retina).</p> <h2>Security fixes</h2> <p>There are some notable security fixes in this release.</p> <h3>Security fixes in Go</h3> <p>This release upgrades from Go 1.26.1 to 126.3, which brings a set of security fixes. Some relevant for Hugo are:</p> <ul> <li>XSS in html/template (CVE-2026-39826 & CVE-2026-39823): Two separate vulnerabilities where escaper bypasses in html/template could lead to Cross-Site Scripting (XSS).</li> <li>html/template: Fixes an issue where JS template literal contexts were incorrectly tracked across template branches, which could lead to improper content escaping.</li> </ul> <h3>Security fixes and hardening in Hugo</h3> <p>The following changes either fix a concrete issue or reduce the default attack surface of <code>hugo</code> builds.</p> <ul> <li><strong>Disallow <code>text/html</code> content files by default</strong> (<a href="https://github.com/gohugoio/hugo/commit/e41a06447d">e41a064</a>). A new <code>security.allowContent</code> policy gates which content media types may be used for pages under <code>/content</code>. <code>text/html</code> is denied by default; sites that rely on hand-authored or adapter-emitted HTML content can opt back in with <code>security.allowContent = ['.*']</code>.</li> <li><strong>Re-check <code>security.http.urls</code> on every redirect hop in <code>resources.GetRemote</code></strong> (<a href="https://github.com/gohugoio/hugo/commit/86fbb0f7a8">86fbb0f</a>).</li> <li><strong>Reject symlinked entries in <code>resources.Get</code></strong> (<a href="https://github.com/gohugoio/hugo/commit/f8b5fa09a6">f8b5fa0</a>).</li> </ul> <p><strong>We will update this section later with links to CVEs where applicable.</strong></p> <h2>All changes</h2> <ul> <li>hugolib: Fix Page.GitInfo for modules with go.mod in a repo subdirectory df542191 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14942">#14942</a></li> <li>Fix typo in CONTRIBUTING.md 4bc7caea <a href="https://github.com/bep"><code>@bep</code></a></li> <li>resources: Fix the :counter placeholder 5d51b82a <a href="https://github.com/jmooring"><code>@jmooring</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14921">#14921</a></li> <li>commands: Fix import from Jekyll 81d77620 <a href="https://github.com/jmooring"><code>@jmooring</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14795">#14795</a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14906">#14906</a></li> <li>Fix prevention of direct symlink reads in resources.Get f8b5fa09 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>commands: Fix github-dark chromastyles 88d838a9 <a href="https://github.com/xndvaz"><code>@xndvaz</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14831">#14831</a></li> <li>Disallow HTML content by default e41a0644 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>Add image processing support for AVIF 90d9f812 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/7837">#7837</a></li> <li>config: Preserve intentionally empty maps 80e60847 <a href="https://github.com/jmooring"><code>@jmooring</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14944">#14944</a></li> <li>hugolib: Merge existing hugo_stats.json when renderSegments is set aeb9a5cc <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14939">#14939</a></li> <li>all: Replace RWMutex struct caches with ConcurrentMap c4bbc280 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>tpl/tplimpl: Consolidate and improve embedded template integration tests d8c70218 <a href="https://github.com/jmooring"><code>@jmooring</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14932">#14932</a></li> <li>parser: Drop empty sub maps from hugo config output ee4f1acd <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14855">#14855</a></li> <li>markup/highlight: Allow overriding type and code via options b6133657 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/11872">#11872</a></li> <li>Update AI assistance disclosure requirements d2c821b5 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>hugolib: Use AllTranslated in IsTranslated 4ed7600f <a href="https://github.com/bep"><code>@bep</code></a></li> <li>tpl: Simplify sitemap template cbe4339a <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14912">#14912</a></li> <li>tpl: Use AllTranslations in sitemap template 6475d308 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14912">#14912</a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14917">#14917</a></li> <li>tpl/collections: Make dict return nil when no values are provided 67aede43 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>Sync Go template package to 1.26.3 87f194b2 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14897">#14897</a></li> <li>Upgrade to Go 1.26.3 d81e3c29 <a href="https://github.com/bep"><code>@bep</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14897">#14897</a></li> <li>ci: Check embedded template formatting with gotmplfmt 7c65a4db <a href="https://github.com/bep"><code>@bep</code></a></li> <li>tpl: Run gotmplfmt -w . d31a9275 <a href="https://github.com/bep"><code>@bep</code></a></li> <li>markup/goldmark/codeblocks: Always split Chroma options into .Options c36608c5 <a href="https://github.com/jmooring"><code>@jmooring</code></a> <a href="https://redirect.github.com/gohugoio/hugo/issues/14909">#14909</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/gohugoio/hugo/commit/076dfe13d0f789e3d9586b192f8f7f3329c26990"><code>076dfe1</code></a> releaser: Bump versions for release of 0.162.0</li> <li><a href="https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1"><code>e41a064</code></a> Disallow HTML content by default</li> <li><a href="https://github.com/gohugoio/hugo/commit/90d9f812b2cafc79ca125a829936dec9654aec64"><code>90d9f81</code></a> Add image processing support for AVIF</li> <li><a href="https://github.com/gohugoio/hugo/commit/80e60847fb5d12f6a54fae782cb643a1772c38b6"><code>80e6084</code></a> config: Preserve intentionally empty maps</li> <li><a href="https://github.com/gohugoio/hugo/commit/df5421918a987cedaba42a050b0e4dde9c88ba3f"><code>df54219</code></a> hugolib: Fix Page.GitInfo for modules with go.mod in a repo subdirectory</li> <li><a href="https://github.com/gohugoio/hugo/commit/aeb9a5cc02fad527220d6a40b1450661c6a56503"><code>aeb9a5c</code></a> hugolib: Merge existing hugo_stats.json when renderSegments is set</li> <li><a href="https://github.com/gohugoio/hugo/commit/c4bbc2805c7092deafabae01e71ff2dda37bd877"><code>c4bbc28</code></a> all: Replace RWMutex struct caches with ConcurrentMap</li> <li><a href="https://github.com/gohugoio/hugo/commit/d8c70218b7385125d807784534af5e5491bc30df"><code>d8c7021</code></a> tpl/tplimpl: Consolidate and improve embedded template integration tests</li> <li><a href="https://github.com/gohugoio/hugo/commit/ee4f1acd93b417078715693fb22ce1fd2bab2684"><code>ee4f1ac</code></a> parser: Drop empty sub maps from hugo config output</li> <li><a href="https://github.com/gohugoio/hugo/commit/b6133657e006290375e587bfb6566469a14911af"><code>b613365</code></a> markup/highlight: Allow overriding type and code via options</li> <li>Additional commits viewable in <a href="https://github.com/gohugoio/hugo/compare/v0.161.1...v0.162.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
@@ -162,7 +162,7 @@ require (
|
||||
github.com/go-logr/logr v1.4.3
|
||||
github.com/go-playground/validator/v10 v10.30.0
|
||||
github.com/gofrs/flock v0.13.0
|
||||
github.com/gohugoio/hugo v0.161.1
|
||||
github.com/gohugoio/hugo v0.162.0
|
||||
github.com/golang-jwt/jwt/v4 v4.5.2
|
||||
github.com/golang-migrate/migrate/v4 v4.19.0
|
||||
github.com/gomarkdown/markdown v0.0.0-20260411013819-759bbc3e3207
|
||||
@@ -231,10 +231,10 @@ require (
|
||||
golang.org/x/crypto v0.51.0
|
||||
golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f
|
||||
golang.org/x/mod v0.36.0
|
||||
golang.org/x/net v0.54.0
|
||||
golang.org/x/net v0.55.0
|
||||
golang.org/x/oauth2 v0.36.0
|
||||
golang.org/x/sync v0.20.0
|
||||
golang.org/x/sys v0.44.0
|
||||
golang.org/x/sys v0.45.0
|
||||
golang.org/x/term v0.43.0
|
||||
golang.org/x/text v0.37.0
|
||||
golang.org/x/tools v0.45.0
|
||||
@@ -278,7 +278,7 @@ require (
|
||||
github.com/agext/levenshtein v1.2.3 // indirect
|
||||
github.com/agnivade/levenshtein v1.2.1 // indirect
|
||||
github.com/akutz/memconn v0.1.0 // indirect
|
||||
github.com/alecthomas/chroma/v2 v2.23.1 // indirect
|
||||
github.com/alecthomas/chroma/v2 v2.24.1 // indirect
|
||||
github.com/alexbrainman/sspi v0.0.0-20210105120005-909beea2cc74 // indirect
|
||||
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
|
||||
github.com/apparentlymart/go-cidr v1.1.0 // indirect
|
||||
@@ -304,7 +304,7 @@ require (
|
||||
github.com/beorn7/perks v1.0.1 // indirect
|
||||
github.com/bep/godartsass/v2 v2.5.0 // indirect
|
||||
github.com/bep/golibsass v1.2.0 // indirect
|
||||
github.com/bmatcuk/doublestar/v4 v4.9.1 // indirect
|
||||
github.com/bmatcuk/doublestar/v4 v4.10.0 // indirect
|
||||
github.com/charmbracelet/x/ansi v0.11.6 // indirect
|
||||
github.com/charmbracelet/x/term v0.2.2 // indirect
|
||||
github.com/chromedp/sysutil v1.1.0 // indirect
|
||||
@@ -313,7 +313,7 @@ require (
|
||||
github.com/cloudflare/circl v1.6.3 // indirect
|
||||
github.com/containerd/continuity v0.4.5 // indirect
|
||||
github.com/coreos/go-iptables v0.6.0 // indirect
|
||||
github.com/dlclark/regexp2 v1.11.5 // indirect
|
||||
github.com/dlclark/regexp2 v1.12.0 // indirect
|
||||
github.com/docker/cli v29.2.0+incompatible // indirect
|
||||
github.com/docker/go-connections v0.6.0 // indirect
|
||||
github.com/docker/go-units v0.5.0 // indirect
|
||||
@@ -379,7 +379,7 @@ require (
|
||||
github.com/kr/fs v0.1.0 // indirect
|
||||
github.com/kylelemons/godebug v1.1.0 // indirect
|
||||
github.com/leodido/go-urn v1.4.0 // indirect
|
||||
github.com/lucasb-eyer/go-colorful v1.3.0 // indirect
|
||||
github.com/lucasb-eyer/go-colorful v1.4.0 // indirect
|
||||
github.com/lufia/plan9stats v0.0.0-20250317134145-8bc96cf8fc35 // indirect
|
||||
github.com/mailru/easyjson v0.9.1 // indirect
|
||||
github.com/mattn/go-colorable v0.1.14 // indirect
|
||||
@@ -409,7 +409,7 @@ require (
|
||||
github.com/opencontainers/image-spec v1.1.1 // indirect
|
||||
github.com/opencontainers/runc v1.2.8 // indirect
|
||||
github.com/outcaste-io/ristretto v0.2.3 // indirect
|
||||
github.com/pelletier/go-toml/v2 v2.3.0 // indirect
|
||||
github.com/pelletier/go-toml/v2 v2.3.1 // indirect
|
||||
github.com/philhofer/fwd v1.1.3-0.20240916144458-20a13a1f6b7c // indirect
|
||||
github.com/pierrec/lz4/v4 v4.1.18 // indirect
|
||||
github.com/pion/transport/v2 v2.2.10 // indirect
|
||||
|
||||
Reference in New Issue
Block a user