-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Update dependency gohugoio/hugo from v0.152.1 to v0.152.2 (.github/workflows/validate_docs_build.yml) #13665
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…rkflows/validate_docs_build.yml)
|
This pull request uses an unusual Hugo version ("0.152.2") in the CI workflow which appears to be non-existent or unstable, risking build failures and pipeline instability; consider pinning to a known stable Hugo release.
Use of Potentially Unstable or Non-Existent Dependency Version in
|
| Vulnerability | Use of Potentially Unstable or Non-Existent Dependency Version |
|---|---|
| Description | The CI/CD pipeline is configured to use Hugo version '0.152.2'. This version number is highly unusual for a stable Hugo release, which typically follows a '0.XX.X' pattern with much lower patch numbers. Searches for this specific version using vulnerability lookup tools and general release information yielded no results, indicating it is likely a non-existent, pre-release, or otherwise unstable version not intended for production use. While no specific CVEs were found for this version (likely because it's not a recognized stable release), its use introduces significant risk of build failures and instability in the CI/CD pipeline. |
django-DefectDojo/.github/workflows/gh-pages.yml
Lines 18 to 21 in 5e59c34
| hugo-version: '0.152.2' # renovate: datasource=github-releases depName=gohugoio/hugo | |
| extended: true | |
| - name: Setup Node |
All finding details can be found in the DryRun Security Dashboard.
|
I'm going to let @paulOsinski have the first approval on this one. |
|
All good! |
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
0.152.1->0.152.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.152.2Compare Source
In
v0.152.0we tightened the source validation for file mounts. We always said that project mounts can mount with absolute file/directorynames, modules/themes are restricted to relative. Inv0.152.0we narrowed module/themes mounts to be local, which made the setup in the bug report listed below fail:One part of this is security. But the construct above is usually very odd (the project uses files in a theme/module, not the other way around) and not very portable. But the example above demonstrates a valid exception, that we now have added support for in a portable way. The above example now works as it did before
v0.152.0, but going forward you can also write:We now have the
node_modulesas a special case: For themes/modules we first check if the mounted source exists locally, if not we try relative to the project root.What's Changed
1c8c21e@jmooring #14086809ebe0@bep #1408908a0679@jordelverConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.