Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
YouTube Security Videosheise & c't: So funktioniert die neue Überwachungstechnik in Bädern(30.09.2026 um 16:00 Uhr)
••••
YouTube Security VideosMicrosoft Developer: AI Isn't Accountable. You Are.(30.09.2026 um 16:00 Uhr)
•
Windows Tipps & SecurityWie viel Datenvolumen braucht mobiles Arbeiten wirklich?(30.09.2026 um 15:43 Uhr)
•
Videos & KonferenzenWBS LEGAL: 25 Minuten kopfüber in 15 Metern Höhe! 🎢😱(30.09.2026 um 16:00 Uhr)
•••
Sicherheitslücken (CVE)USN-8852-1: OpenVPN vulnerabilities(30.09.2026 um 13:53 Uhr)
•
YouTube Security Videosheise & c't: So funktioniert die neue Überwachungstechnik in Bädern(30.09.2026 um 16:00 Uhr)
••••
YouTube Security VideosMicrosoft Developer: AI Isn't Accountable. You Are.(30.09.2026 um 16:00 Uhr)
•
Windows Tipps & SecurityWie viel Datenvolumen braucht mobiles Arbeiten wirklich?(30.09.2026 um 15:43 Uhr)
•
Videos & KonferenzenWBS LEGAL: 25 Minuten kopfüber in 15 Metern Höhe! 🎢😱(30.09.2026 um 16:00 Uhr)
•••
Sicherheitslücken (CVE)USN-8852-1: OpenVPN vulnerabilities(30.09.2026 um 13:53 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

GitHub Release: gohugoio/hugo v0.167.0 (28.09.2026)

Release v0.167.0 von gohugoio/hugo auf GitHub: This release brings relative partial references, slug support for branch pages, and a handful of security…

0
↗ Quelle (GitHub · gohugoio/hugo)
Reagiere als Erste:r — dein Feedback zählt!
gohugoio/hugov0.167.028.09.2026@bep

This release brings relative partial references, slug support for branch pages, and a handful of security hardening fixes.


Relative partial references. A partial name starting with ./ or ../ is now resolved relative to the directory of the calling partial. This makes it much easier to write self-contained, movable partial trees, e.g. {{ partial "./item.html" . }} from within layouts/_partials/card/list.html. Relative paths are only allowed from within partials, and paths resolving outside the partials directory is an error. See #15373 and the documentation.


Slugs for section, taxonomy and term pages. The slug front matter now works for branch pages, not just regular pages, and it cascades to descendants. This is particularly useful in multilingual sites, where e.g. content/help/_index.es.md with slug: ayuda gives /es/ayuda/, /es/ayuda/avanzado/ etc. See #14352.


Other notable improvements include the new build.cleanDestinationDir config with keepFiles/keepDirs Glob patterns (#14937, docs), hugo now builds without a config file (#15393), exact numeric comparisons in eq, where, in and the set functions (#15322, #15358), and automatic summaries that no longer end inside an open list or blockquote (#14044).


Security


This release contains several hardening fixes. None of them are known to be exploited, but if you build sites with untrusted themes or modules, you should upgrade.



  • Sass imports not found in Hugo's file systems were resolved by the Sass compiler itself, which follows symlinks and knows nothing about the project root. A theme could import a file outside the project and get its content into the published CSS. These imports are now resolved by Hugo and checked against the same security.allowRead roots as the Node.js tools and js.Build. 41040cc (thanks to @Hama1cco)

  • Likewise, imports not found in /assets were resolved and read by ESBuild itself. The resolved path is now checked against the allowed read paths before ESBuild loads it. 2aa51f3 (thanks to @Hama1cco)

  • A symlinked directory in a theme at the parent of a nested mount could expose files outside the module. 2fe9bab

  • Explicit heading IDs (e.g. ## Foo {id="..."}) were written unescaped into the table of contents href, allowing attribute breakout. 671fbf2


Note



  • The default baseURL is now https://example.org/ (it was empty). Hugo has always required a valid URL to work properly, so this mostly affects new and test sites, but if you relied on the empty default for relative URLs, set baseURL explicitly. bc68654 @bep #14625 #15384

  • The root cleanDestinationDir config key is deprecated in favour of build.cleanDestinationDir.enable. The --cleanDestinationDir flag maps to the new key. Note that .git files in the publish dir are now kept by default. 9086193 @bep #14937

  • eq now compares numeric values the same way as lt, le etc., so e.g. eq 1 1.0 is now true. Also, in, intersect, union, uniq, symdiff, complement and where's in/not in now compare numbers exactly rather than via float64, and no longer require the Go types to match. 4d628bb 366377b @bep #15322 #15358

  • A user table render hook is now preferred over the embedded one. 140d936 @jmooring #15389

  • Automatic summaries are expanded past summaryLength when needed so they don't end inside an open container element. This may change the summary for some pages. d692a24 @bep #14044


Bug fixes



Improvements



Dependency Updates



Documentation



Build Setup


Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-82307 | Improper neutralization of special elements used in an SQL command ('SQL…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag