ci(deps): update gohugoio/hugo action to v0.129.0 #52
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.118.2->v0.129.0Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.129.0Compare Source
This release brings a rewrite of the logic around browser refreshes when running
hugo server. We have seen some situations where asset changes (e.g. image/CSS/JS) has not been refreshed reliably in all browsers, even with the developer console open and the cache disabled. We suspect this comes from a recent browser bug (typically: Works fine in Safari, does not refresh in Chrome). The strategy we've been using when a change triggers multiple changes (e.g. both HTML and CSS) is to do one "browser force refresh", which in LiveReload ends up as awindow.location.reload(). With this release we:livereload.Start the server with:
And you should see how Hugo handles browser updates when you change content/templates etc.
A related tip; start the server with
Hugo will navigate to the content file you're changing and log it in the console.
Also new in this release a new xxHash hashing function that is much faster than any of the other hashing functions in Hugo, especially for larger inputs.
Note
We have upgraded the integration with Git used to load GitInfo to be part of Hugo's Security Policy. We have added
gitto the default whitelist, but if you have a custom security policy, you may have to update that.Bug fixes
cc2d19e@bep #12648251a23e@bep #12625Improvements
4d8bfa7@bepf0ed91c@bep #12655094f746@bep #12643fb8909d@bep #126430ee2610@PeskyPotato #10905644d554@bep #12635Dependency Updates
7be0377@bep #8627439f07e@bepce5a2ce@bep0f42d97@bepv0.128.2Compare Source
What's Changed
8cf96f2@bep #12638v0.128.1Compare Source
What's Changed
7b6dafc@bep #12438a95fe50@CyrusYip932ab4c@jmooringv0.128.0Compare Source
This release brings TailwindCSS v4 (alpha) support. For more info about the TailwindCSS 4 integration, see this repo. Also notable is the new templates.Defer template func and the dramatically improved performance of
$page.GetTermsfor bigger sites.Bug fixes
c880faa@bep #126218731d88@bep #12617ad6d91c@bep #126007ee36b3@razonyangImprovements
e1317dd@bep #12618 #12620eddcd2b@bep #1261816e4662@bep6cd0784@bep #8086 #125891c85830@bep #12486d5542ed@depp #12607478a910@bep #126108efc75b@jmooring #1259757165d4@jmooring9c3143c@bep #125729f22bc4@bepcba2de6@jmooring #125789c4e14e@bep #125721cdd3d0@bep #12575Dependency Updates
79da24a@jmooringb187c06@jmooring8cf94ae@jmooring #12580b57306d@bep #12575Build Setup
1687a9a@bep #12378Documentation
3b72446@bepb46d101@bepv0.127.0Compare Source
This release brings proper HTTP caching and live reloading of remote resources fetched with resources.GetRemote, especially useful when used with content adapters.
Note that this isn't enabled out of the box, so if you need this, you need to add some configuration. The demo below is configured as:
hugodemo__v0127.mp4
What's Changed
447108f@bep #12502 #118912b05a50@bep #12502 #12570v0.126.3Compare Source
917199a@bep #12561c8dac67@jmooring #125130068f03@razonyang0221ddb@bep #12556v0.126.2Compare Source
Bug fixes
1464091@bep #12538519f41d@bep #12544b893a09@jmooring #12514Improvements
2c88e45@bepeaa42a8@bep #12530245928a@bep #125077f30617@jmooring #12525931e096@jmooring #12520548dc21@jmooring #125196b00661@bep #12511v0.126.1Compare Source
What's Changed
39cf906@bep #124971aacfce@bep #12493v0.126.0Compare Source
This release brings, drum roll, a long-awaited Hugo feature that has had many names. At one point we named it pages from data. You can read all about it in the documentation where it's titled Content Adapters.
Also worth mentioning are the new Extras Goldmark Extensions, which allows you to enable Markdown syntax for inserted text, mark text, subscript and superscript. A big thanks to @bowman2001 for the implementation.
Improvements
74ab839@jmooring #1243392290aa@jmooring #124326dbbe6d@jmooring #12490e2d66e3@bep #12427 #12485 #6310 #507455dea41@jmooring #1247987ab7f7@jmooring #124806dfeb9f@jmooring #12468ca9a77e@jmooringDependency Updates
ee26e69@dependabot[bot]6e83d00@dependabot[bot]Documentation
2661402@bepBuild Setup
d02f062@bep #12451 #6290v0.125.7Compare Source
Note that this release is only relevant if you use Hugo's
openapi3.Unmarshaltemplate function.What's Changed
3c6260f@bepv0.125.6Compare Source
What's Changed
bb59a7e@bep #12395 #12456503d209@bep #1245868e9532@dependabot[bot]9cd7db6@bepc892e75@bepv0.125.5Compare Source
What's Changed
7be7f89@bep #12449c8e400b@bep #123849dd6870@bep #12436v0.125.4Compare Source
What Changed
7203a95@bep #12296fb51b69@jmooring #12418fe84cc2@Habbiebabcb33@bep #122886b86797@bep #12415fb08439@dependabot[bot]v0.125.3Compare Source
This release fixes a security issue reported by @ejona86 (see #12411) that could allow XSS injection from Markdown content files if one of the internal link or image render hook templates added in Hugo 0.123.0 are enabled. You typically control and trust the content files, but according to Hugo's security model, we state that "template and configuration authors (you) are trusted, but the data you send in is not."
509ab08@bep15a4b9b@bep10a8448@jmooring #12396722c486@ejona86f40f50e@bep #12407v0.125.2Compare Source
What's Changed
06d2489@bep #12399004b694@bepda6112f@jmooring #12393faf9fed@bep11aa893@jmooring #12387v0.125.1Compare Source
What's Changed
0c188fd@bep #12383bbc6888@bep #12381v0.125.0Compare Source
Some of the notable new features in this release:
.RenderShortcodein a shortcode, typically used to resolve links and page resources relative to an includedPage.Luminanceto$image.Color, allowing for sorting by relative luminance.e197c7b@bep #10450This release is built with Go 1.22.2 (#12351) which comes with a fix for security issue CVE-2023-45288. We don't see how that could be exploited in Hugo, but we do appreciate that people want a clean security report.
Bug fixes
fa60a2f@bep #123626049ba9@jmooring #123699323376@bepbf0b140@grimreaper17765a7@coliff2664052@curegit488b21d@bep #12306983b8d5@bep #1232038e05bd@bep #1230927414d4@availhangImprovements
e197c7b@bep #10450df11327@bep #123568e50ccf@bepbfc3122@bep00ae8e8@bepe423e56@bep09eb822@jmooring #12359a6e8439@jmooring #1231638f68cd@bepa67650b@scop2a060b3@bep #1235192de862@bep7907935@testwill02d5ec1@dependabot[bot]4500b0e@sorenisanerd #4926 #8232 #123427bf1abf@jmooring8a0ea12@jmooring #3694 #9213 #10520 #10575 #105766f07e59@seiyab2da4ec5@jmooring #8296 #8698 #8991 #9818 #9866 #106476624979@jmooring #123306738a3e@jmooring #653 #122822f7df4b@jmooring #11867f0a26cf@jmooring #3918 #1169274ce5dc@jmooring #757054a8f0c@jmooring #10412 #12310ebfca61@jmooring #11802 #10093e191774@jmooring #12297Dependency Updates
fe63de3@dependabot[bot]a18e2bc@dependabot[bot]97df6be@dependabot[bot]e9b8bec@dependabot[bot]888cc1e@dependabot[bot]060cce0@dependabot[bot]5608ba1@dependabot[bot]2fedca6@dependabot[bot]07873b7@dependabot[bot]Documentation
df9f2fb@bep74e9129@bep #12375c837f36@jmooring #12291v0.124.1Compare Source
What's Changed
758a876@bep #1212919937a2@bep #12165c1ea22a@anthonyfok0750a9e@bep #12275v0.124.0Compare Source
The new feature in this release is a new segments configuration section and a new
--renderSegmentsflag/config key. This release also updates to Go 1.22.1 that fixes a security issue in the template package that Hugo uses (CVE-2023-45289, see golang/go#65697). We don't see how this could be exploited in Hugo, but we appreciate that Hugo users want to have a clean security report.Bug fixes
f1d7559@bep #122633935faa@jmooring #1226678178d0@coliff68d92ef@bep #12261b40f3c7@bep #1225407b2e53@bep #122309ca1de0@bep #121959668759@bep #122369e9b1f1@bep #12214Improvements
1f1c62e@bep #10106558f74f@bepd4d49e0@jmooring #1222857206e7@bep #1225048a0fea@jmooring #12244 #12245dc6a292@jmooring #122324f92f94@jmooring #12224f038a51@jmooringDependency Updates
ba03114@bepb1f8676@dependabot[bot]b4bff61@dependabot[bot]d2cebee@dependabot[bot]be914ff@myitcv #11862e626750@dependabot[bot]Documentation
76ef3f4@bep0ccb6cd@bepBuild Setup
d24ffdd@jmooring #12219v0.123.8Compare Source
ada3fce@deininga4b1747@bep #121904d5e173@bep #121904271b6b@bep #121980567a3e@bep #12193134e7d1@lyind #7169 #11783 #120221f48b71@razonyang05e23bd@jmooring #122067afac3f@bep #12188632ad74@jmooring #12203v0.123.7Compare Source
What's Changed
2b2f2b7@bep #121750d6e593@bep #121787023cf0@bep #121829dfa9e7@bep #121833f217fd@jmooring #12177v0.123.6Compare Source
What's Changed
fce8d82@bep #121724a502f7@bep #12133be1dbba@bep #12132v0.123.5Compare Source
What's Changed
6a8b25e@bep #12169a322282@bep #121416bc0d74@bep [#12163](https://redirect.githubConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.