Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update all non-major dependencies to v0.140.2 in .github/workflows/test.yml #242

Merged
merged 1 commit into from
Dec 31, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 31, 2024

This PR contains the following updates:

Package Type Update Change OpenSSF
gohugoio/hugo patch 0.140.1 -> 0.140.2 OpenSSF Scorecard
hugo-extended dependencies patch 0.140.1 -> 0.140.2 OpenSSF Scorecard

Release Notes

gohugoio/hugo (gohugoio/hugo)

v0.140.2

Compare Source

The timing of this release comes from the security fix in golang.org/x/net's html.Parse function. This is used in two places in Hugo:

  1. Extracting table of contents from Asciidoctor rendered output.
  2. Collecting HTML classes etc. when build stats is enabled

It's a little bit of a stretch to see how this could be exploited in Hugo, but we understand that many wants a clean security report. See this issue for details.

What's Changed

jakejarvis/hugo-extended (hugo-extended)

v0.140.2

Compare Source


Configuration

📅 Schedule: Branch creation - "* 0-3 * * *" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

Deploying website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9f38d7b
Status:⚡️  Build in progress...

View logs

@renovate renovate bot added dependencies Pull requests that update a dependency file github-releases patch labels Dec 31, 2024
@renovate renovate bot enabled auto-merge (squash) December 31, 2024 01:38
@renovate renovate bot merged commit 890795c into main Dec 31, 2024
1 of 2 checks passed
@renovate renovate bot deleted the renovate/all-minor-patch branch December 31, 2024 01:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file github-releases patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants