github gohugoio/hugo v0.167.0

3 hours ago

This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.

Relative partial references. A partial name starting with ./ or ../ is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g. {{ partial "./item.html" . }} from within layouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #15373 and the documentation.

Slugs for section, taxonomy and term pages. The slug front matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g. content/help/_index.es.md with slug: ayuda gives /es/ayuda/, /es/ayuda/avanzado/ etc. See #14352.

Other notable improvements include the new build.cleanDestinationDir config with keepFiles/keepDirs Glob patterns (#14937, docs), hugo now builds without a config file (#15393), exact numeric comparisons in eq, where, in and the set functions (#15322, #15358), and automatic summaries that no longer end inside an open list or blockquote (#14044).

Security

This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.

  • Sass imports not found in Hugo's file systems were resolved by the Sass compiler itself, which follows symlinks and knows nothing about the project root. A theme could import a file outside the project and get its content into the published CSS. These imports are now resolved by Hugo and checked against the same security.allowRead roots as the Node.js tools and js.Build. 41040cc (thanks to @Hama1cco)
  • Likewise, imports not found in /assets were resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it. 2aa51f3 (thanks to @Hama1cco)
  • A symlinked directory in a theme at the parent of a nested mount could expose files outside the module. 2fe9bab
  • Explicit heading IDs (e.g. ## Foo {id="..."}) were written unescaped into the table of contents href, allowing attribute breakout. 671fbf2

Note

  • The default baseURL is now https://example.org/ (it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, set baseURL explicitly. bc68654 @bep #14625 #15384
  • The root cleanDestinationDir config key is deprecated in favour of build.cleanDestinationDir.enable. The --cleanDestinationDir flag maps to the new key. Note that .git files in the publish dir are now kept by default. 9086193 @bep #14937
  • eq now compares numeric values the same way as lt, le etc., so e.g. eq 1 1.0 is now true. Also, in, intersect, union, uniq, symdiff, complement and where's in/not in now compare numbers exactly rather than via float64, and no longer require the Go types to match. 4d628bb 366377b @bep #15322 #15358
  • A user table render hook is now preferred over the embedded one. 140d936 @jmooring #15389
  • Automatic summaries are expanded past summaryLength when needed so they don't end inside an open container element. This may change the summary for some pages. d692a24 @bep #14044

Bug fixes

Improvements

Dependency Updates

Documentation

Build Setup

Don't miss a new hugo release

NewReleases is sending notifications on new releases.