Skip to content

chore(deps): update dependency hugo to v0.162.0#2143

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/hugo-0.x
May 28, 2026
Merged

chore(deps): update dependency hugo to v0.162.0#2143
renovate[bot] merged 1 commit into
mainfrom
renovate/hugo-0.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 26, 2026

This PR contains the following updates:

Package Update Change
hugo minor 0.161.10.162.0

Release Notes

gohugoio/hugo (hugo)

v0.162.0

Compare Source

The notable new feature in this release is support for AVIF images (both encoder and decoder). There's a demo site set up that demonstrates the difference between HDR AVIF and SDR JPEG images. Note that that demo is only really interesting if viewed on an HDR capable screen (e.g. Apple Retina).

Security fixes

There are some notable security fixes in this release.

Security fixes in Go

This release upgrades from Go 1.26.1 to 126.3, which brings a set of security fixes. Some relevant for Hugo are:

  • XSS in html/template (CVE-2026-39826 & CVE-2026-39823): Two separate vulnerabilities where escaper bypasses in html/template could lead to Cross-Site Scripting (XSS).
  • html/template: Fixes an issue where JS template literal contexts were incorrectly tracked across template branches, which could lead to improper content escaping.
Security fixes and hardening in Hugo

The following changes either fix a concrete issue or reduce the default attack surface of hugo builds.

  • Disallow text/html content files by default (e41a064). A new security.allowContent policy gates which content media types may be used for pages under /content. text/html is denied by default; sites that rely on hand-authored or adapter-emitted HTML content can opt back in with security.allowContent = ['.*'].
  • Re-check security.http.urls on every redirect hop in resources.GetRemote (86fbb0f).
  • Reject symlinked entries in resources.Get (f8b5fa0).

We will update this section later with links to CVEs where applicable.

All changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label May 26, 2026
@renovate renovate Bot enabled auto-merge (squash) May 26, 2026 14:49
@renovate renovate Bot force-pushed the renovate/hugo-0.x branch from a3f0452 to 6517c30 Compare May 26, 2026 15:34
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 26, 2026

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: mise.lock

mise ERROR error parsing config file: /tmp/renovate/repos/github/prometheus/client_java/mise.toml
mise ERROR Config files in /tmp/renovate/repos/github/prometheus/client_java/mise.toml are not trusted.
Trust them with `mise trust`. See https://mise.en.dev/cli/trust.html for more information.
mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information

Command failed: mise lock hugo
mise ERROR error parsing config file: /tmp/renovate/repos/github/prometheus/client_java/mise.toml
mise ERROR Config files in /tmp/renovate/repos/github/prometheus/client_java/mise.toml are not trusted.
Trust them with `mise trust`. See https://mise.en.dev/cli/trust.html for more information.
mise ERROR Run with --verbose or MISE_VERBOSE=1 for more information

@renovate renovate Bot force-pushed the renovate/hugo-0.x branch 4 times, most recently from 40b0469 to 6ad01e3 Compare May 28, 2026 12:25
@renovate renovate Bot force-pushed the renovate/hugo-0.x branch from 6ad01e3 to bf66e54 Compare May 28, 2026 12:27
@renovate renovate Bot merged commit 41860c3 into main May 28, 2026
13 checks passed
@renovate renovate Bot deleted the renovate/hugo-0.x branch May 28, 2026 12:38
jaydeluca pushed a commit that referenced this pull request Jun 4, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [hugo](https://redirect.github.com/gohugoio/hugo) | minor | `0.161.1`
→ `0.162.0` |

---

### Release Notes

<details>
<summary>gohugoio/hugo (hugo)</summary>

###
[`v0.162.0`](https://redirect.github.com/gohugoio/hugo/releases/tag/v0.162.0)

[Compare
Source](https://redirect.github.com/gohugoio/hugo/compare/v0.161.1...v0.162.0)

The notable new feature in this release is support for [AVIF
images](https://gohugo.io/configuration/imaging/#avif-images) (both
encoder and decoder). There's a [demo
site](https://redirect.github.com/bep/hdrsdr.com) set up that
demonstrates the difference between HDR AVIF and SDR JPEG images. Note
that that demo is only really interesting if viewed on an HDR capable
screen (e.g. Apple Retina).

##### Security fixes

There are some notable security fixes in this release.

##### Security fixes in Go

This release upgrades from Go 1.26.1 to 126.3, which brings a set of
security fixes. Some relevant for Hugo are:

- XSS in html/template (CVE-2026-39826 & CVE-2026-39823): Two separate
vulnerabilities where escaper bypasses in html/template could lead to
Cross-Site Scripting (XSS).
- html/template: Fixes an issue where JS template literal contexts were
incorrectly tracked across template branches, which could lead to
improper content escaping.

##### Security fixes and hardening in Hugo

The following changes either fix a concrete issue or reduce the default
attack surface of `hugo` builds.

- **Disallow `text/html` content files by default**
([e41a064](https://redirect.github.com/gohugoio/hugo/commit/e41a06447d)).
A new `security.allowContent` policy gates which content media types may
be used for pages under `/content`. `text/html` is denied by default;
sites that rely on hand-authored or adapter-emitted HTML content can opt
back in with `security.allowContent = ['.*']`.
- **Re-check `security.http.urls` on every redirect hop in
`resources.GetRemote`**
([86fbb0f](https://redirect.github.com/gohugoio/hugo/commit/86fbb0f7a8)).
- **Reject symlinked entries in `resources.Get`**
([f8b5fa0](https://redirect.github.com/gohugoio/hugo/commit/f8b5fa09a6)).

**We will update this section later with links to CVEs where
applicable.**

##### All changes

- hugolib: Fix Page.GitInfo for modules with go.mod in a repo
subdirectory
[`df54219`](https://redirect.github.com/gohugoio/hugo/commit/df542191)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14942](https://redirect.github.com/gohugoio/hugo/issues/14942)
- Fix typo in CONTRIBUTING.md
[`4bc7cae`](https://redirect.github.com/gohugoio/hugo/commit/4bc7caea)
[@&#8203;bep](https://redirect.github.com/bep)
- resources: Fix the :counter placeholder
[`5d51b82`](https://redirect.github.com/gohugoio/hugo/commit/5d51b82a)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14921](https://redirect.github.com/gohugoio/hugo/issues/14921)
- commands: Fix import from Jekyll
[`81d7762`](https://redirect.github.com/gohugoio/hugo/commit/81d77620)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14795](https://redirect.github.com/gohugoio/hugo/issues/14795)
[#&#8203;14906](https://redirect.github.com/gohugoio/hugo/issues/14906)
- Fix prevention of direct symlink reads in resources.Get
[`f8b5fa0`](https://redirect.github.com/gohugoio/hugo/commit/f8b5fa09)
[@&#8203;bep](https://redirect.github.com/bep)
- commands: Fix github-dark chromastyles
[`88d838a`](https://redirect.github.com/gohugoio/hugo/commit/88d838a9)
[@&#8203;xndvaz](https://redirect.github.com/xndvaz)
[#&#8203;14831](https://redirect.github.com/gohugoio/hugo/issues/14831)
- Disallow HTML content by default
[`e41a064`](https://redirect.github.com/gohugoio/hugo/commit/e41a0644)
[@&#8203;bep](https://redirect.github.com/bep)
- Add image processing support for AVIF
[`90d9f81`](https://redirect.github.com/gohugoio/hugo/commit/90d9f812)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;7837](https://redirect.github.com/gohugoio/hugo/issues/7837)
- config: Preserve intentionally empty maps
[`80e6084`](https://redirect.github.com/gohugoio/hugo/commit/80e60847)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14944](https://redirect.github.com/gohugoio/hugo/issues/14944)
- hugolib: Merge existing hugo\_stats.json when renderSegments is set
[`aeb9a5c`](https://redirect.github.com/gohugoio/hugo/commit/aeb9a5cc)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14939](https://redirect.github.com/gohugoio/hugo/issues/14939)
- all: Replace RWMutex struct caches with ConcurrentMap
[`c4bbc28`](https://redirect.github.com/gohugoio/hugo/commit/c4bbc280)
[@&#8203;bep](https://redirect.github.com/bep)
- tpl/tplimpl: Consolidate and improve embedded template integration
tests
[`d8c7021`](https://redirect.github.com/gohugoio/hugo/commit/d8c70218)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14932](https://redirect.github.com/gohugoio/hugo/issues/14932)
- parser: Drop empty sub maps from hugo config output
[`ee4f1ac`](https://redirect.github.com/gohugoio/hugo/commit/ee4f1acd)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14855](https://redirect.github.com/gohugoio/hugo/issues/14855)
- markup/highlight: Allow overriding type and code via options
[`b613365`](https://redirect.github.com/gohugoio/hugo/commit/b6133657)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;11872](https://redirect.github.com/gohugoio/hugo/issues/11872)
- Update AI assistance disclosure requirements
[`d2c821b`](https://redirect.github.com/gohugoio/hugo/commit/d2c821b5)
[@&#8203;bep](https://redirect.github.com/bep)
- hugolib: Use AllTranslated in IsTranslated
[`4ed7600`](https://redirect.github.com/gohugoio/hugo/commit/4ed7600f)
[@&#8203;bep](https://redirect.github.com/bep)
- tpl: Simplify sitemap template
[`cbe4339`](https://redirect.github.com/gohugoio/hugo/commit/cbe4339a)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14912](https://redirect.github.com/gohugoio/hugo/issues/14912)
- tpl: Use AllTranslations in sitemap template
[`6475d30`](https://redirect.github.com/gohugoio/hugo/commit/6475d308)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14912](https://redirect.github.com/gohugoio/hugo/issues/14912)
[#&#8203;14917](https://redirect.github.com/gohugoio/hugo/issues/14917)
- tpl/collections: Make dict return nil when no values are provided
[`67aede4`](https://redirect.github.com/gohugoio/hugo/commit/67aede43)
[@&#8203;bep](https://redirect.github.com/bep)
- Sync Go template package to 1.26.3
[`87f194b`](https://redirect.github.com/gohugoio/hugo/commit/87f194b2)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14897](https://redirect.github.com/gohugoio/hugo/issues/14897)
- Upgrade to Go 1.26.3
[`d81e3c2`](https://redirect.github.com/gohugoio/hugo/commit/d81e3c29)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14897](https://redirect.github.com/gohugoio/hugo/issues/14897)
- ci: Check embedded template formatting with gotmplfmt
[`7c65a4d`](https://redirect.github.com/gohugoio/hugo/commit/7c65a4db)
[@&#8203;bep](https://redirect.github.com/bep)
- tpl: Run gotmplfmt -w .
[`d31a927`](https://redirect.github.com/gohugoio/hugo/commit/d31a9275)
[@&#8203;bep](https://redirect.github.com/bep)
- markup/goldmark/codeblocks: Always split Chroma options into .Options
[`c36608c`](https://redirect.github.com/gohugoio/hugo/commit/c36608c5)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14909](https://redirect.github.com/gohugoio/hugo/issues/14909)
- hugolib: Allow empty params front matter
[`2f361a8`](https://redirect.github.com/gohugoio/hugo/commit/2f361a8e)
[@&#8203;xndvaz](https://redirect.github.com/xndvaz)
[#&#8203;14886](https://redirect.github.com/gohugoio/hugo/issues/14886)
- common/hmaps: Merge slice-valued module config into site config
[`5559263`](https://redirect.github.com/gohugoio/hugo/commit/55592633)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;13869](https://redirect.github.com/gohugoio/hugo/issues/13869)
- tpl: Use GetMatch for both local and global image resources
[`656fc04`](https://redirect.github.com/gohugoio/hugo/commit/656fc040)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14062](https://redirect.github.com/gohugoio/hugo/issues/14062)
- Revert "markup/tableofcontents: Skip empty TOC levels"
[`a20cb5b`](https://redirect.github.com/gohugoio/hugo/commit/a20cb5b1)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14898](https://redirect.github.com/gohugoio/hugo/issues/14898)
- tpl/templates: Reject Defer inside partialCached
[`4d775cb`](https://redirect.github.com/gohugoio/hugo/commit/4d775cbe)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;13492](https://redirect.github.com/gohugoio/hugo/issues/13492)
- common/hexec: Make NODE\_PATH a fallback for ESM bare imports
[`ae7bf74`](https://redirect.github.com/gohugoio/hugo/commit/ae7bf74b)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;13987](https://redirect.github.com/gohugoio/hugo/issues/13987)
- config: Allow repeating the root key in /config files
[`ba5d812`](https://redirect.github.com/gohugoio/hugo/commit/ba5d8126)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;12899](https://redirect.github.com/gohugoio/hugo/issues/12899)
[#&#8203;14882](https://redirect.github.com/gohugoio/hugo/issues/14882)
- Revise test naming guidelines in AGENTS.md
[`be4a0df`](https://redirect.github.com/gohugoio/hugo/commit/be4a0df3)
[@&#8203;bep](https://redirect.github.com/bep)
- Update AGENTS.md
[`e4cf565`](https://redirect.github.com/gohugoio/hugo/commit/e4cf565c)
[@&#8203;bep](https://redirect.github.com/bep)
- js: Return error for missing batch imports
[`9e64953`](https://redirect.github.com/gohugoio/hugo/commit/9e649533)
[@&#8203;xndvaz](https://redirect.github.com/xndvaz)
[#&#8203;13737](https://redirect.github.com/gohugoio/hugo/issues/13737)
- resources/images: Keep smart crop target size
[`f0cfc28`](https://redirect.github.com/gohugoio/hugo/commit/f0cfc28c)
[@&#8203;xndvaz](https://redirect.github.com/xndvaz)
[#&#8203;13688](https://redirect.github.com/gohugoio/hugo/issues/13688)
- testing: Use synctest where relevant
[`16e854a`](https://redirect.github.com/gohugoio/hugo/commit/16e854a4)
[@&#8203;bep](https://redirect.github.com/bep)
- security: Validate redirects against security.http.urls
[`86fbb0f`](https://redirect.github.com/gohugoio/hugo/commit/86fbb0f7)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14871](https://redirect.github.com/gohugoio/hugo/issues/14871)
- markup/tableofcontents: Skip empty TOC levels
[`7d4af7a`](https://redirect.github.com/gohugoio/hugo/commit/7d4af7a1)
[@&#8203;xndvaz](https://redirect.github.com/xndvaz)
[#&#8203;7128](https://redirect.github.com/gohugoio/hugo/issues/7128)
- Fall back to hugo.buildDate in hugo.BuildDate() in non-vcs builds
[`28147cb`](https://redirect.github.com/gohugoio/hugo/commit/28147cb0)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14862](https://redirect.github.com/gohugoio/hugo/issues/14862)
- css: Make css.Build's file-loader URLs absolute to web context root
[`e51e761`](https://redirect.github.com/gohugoio/hugo/commit/e51e761d)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14849](https://redirect.github.com/gohugoio/hugo/issues/14849)
- hugolib: Don't warn about lang/kind/path coming from cascade.params
[`7011239`](https://redirect.github.com/gohugoio/hugo/commit/70112392)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14848](https://redirect.github.com/gohugoio/hugo/issues/14848)
- markup/goldmark: Unwrap inner HTML for plain code blocks
[`694906f`](https://redirect.github.com/gohugoio/hugo/commit/694906f6)
[@&#8203;cyphercodes](https://redirect.github.com/cyphercodes)
[#&#8203;14820](https://redirect.github.com/gohugoio/hugo/issues/14820)
- tpl/tplimpl: Extend page image lookup to include global resources
[`d27b9c0`](https://redirect.github.com/gohugoio/hugo/commit/d27b9c06)
[@&#8203;ogulcanaydogan](https://redirect.github.com/ogulcanaydogan)
[#&#8203;14062](https://redirect.github.com/gohugoio/hugo/issues/14062)
- security: Allow hostnames starting with digits in default http.urls
[`62cef36`](https://redirect.github.com/gohugoio/hugo/commit/62cef367)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14837](https://redirect.github.com/gohugoio/hugo/issues/14837)
- commands: Improve description of command flags
[`ff22c62`](https://redirect.github.com/gohugoio/hugo/commit/ff22c62a)
[@&#8203;jmooring](https://redirect.github.com/jmooring)
[#&#8203;14817](https://redirect.github.com/gohugoio/hugo/issues/14817)
- build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0
[`4f444c8`](https://redirect.github.com/gohugoio/hugo/commit/4f444c81)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/image from 0.40.0 to 0.41.0
[`fe6c726`](https://redirect.github.com/gohugoio/hugo/commit/fe6c7265)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump github.com/getkin/kin-openapi from 0.137.0 to
0.138.0
[`6a2a038`](https://redirect.github.com/gohugoio/hugo/commit/6a2a0380)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump github.com/JohannesKaufmann/html-to-markdown/v2
[`cf1de59`](https://redirect.github.com/gohugoio/hugo/commit/cf1de598)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/image from 0.39.0 to 0.40.0
[`97f990c`](https://redirect.github.com/gohugoio/hugo/commit/97f990cc)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump golang.org/x/tools from 0.44.0 to 0.45.0
[`b99634e`](https://redirect.github.com/gohugoio/hugo/commit/b99634e2)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3
[`fdd977e`](https://redirect.github.com/gohugoio/hugo/commit/fdd977e9)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.0 to 2.3.1
[`123018d`](https://redirect.github.com/gohugoio/hugo/commit/123018de)
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot]
- deps: Upgrade to Chroma v2.24.1
[`b88fa8c`](https://redirect.github.com/gohugoio/hugo/commit/b88fa8cc)
[@&#8203;bep](https://redirect.github.com/bep)
[#&#8203;14839](https://redirect.github.com/gohugoio/hugo/issues/14839)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE5NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Jay DeLuca <jaydeluca4@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant