fix(deps): update dependency hexo to v7 [security]#99
Open
renovate[bot] wants to merge 1 commit intobackupfrom
Open
fix(deps): update dependency hexo to v7 [security]#99renovate[bot] wants to merge 1 commit intobackupfrom
renovate[bot] wants to merge 1 commit intobackupfrom
Conversation
657c7dc to
af6867a
Compare
95c4d5c to
af6867a
Compare
af6867a to
0688a96
Compare
0688a96 to
7be2eda
Compare
7be2eda to
ae38c4a
Compare
ae38c4a to
5b78e1e
Compare
5b78e1e to
c59b9d8
Compare
c59b9d8 to
9823354
Compare
9823354 to
4ef3447
Compare
4ef3447 to
0e952fa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^5.4.0→^7.0.0GitHub Vulnerability Alerts
CVE-2021-25987
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
CVE-2023-39584
Hexo up to v7.1.1 was discovered to contain an arbitrary file read vulnerability.
Release Notes
hexojs/hexo (hexo)
v7.2.0Compare Source
New Features
Improved type definitions
Fixes
Refactor
Test
CI/CD
Docs
Dependencies
@types/nodeversion by @uiolee in #5411New Contributors
Full Changelog: hexojs/hexo@v7.1.1...v7.2.0
v7.1.1Compare Source
Fixes
Misc
prepublishOnlyinstead ofprepublishand runnpm installinprepublishOnlyscript by @yoshinorin in #5399Full Changelog: hexojs/hexo@v7.1.0...v7.1.1
v7.1.0Compare Source
Notable Changes
New Features
Fixes
numbertostringexplicitly by @yoshinorin in #5342CI/CD
Dependencies
New Contributors
Full Changelog: hexojs/hexo@v7.0.0...v7.1.0
v7.0.0Compare Source
Migration Guide
built-in tags
Syntax highlighting
Breaking Changes
Migration Guidsection.gisttag by @yoshinorin in #5067youtubetag by @yoshinorin in #5064jsfiddletag by @yoshinorin in #5066vimeotag by @yoshinorin in #5065external_linkboolean type by @yoshinorin in #5063use_date_for_updatedoption forupdated_optionby @yoshinorin in #5062link(#5253) by @stevenjoezhang in #5253Notable Changes
New Features
Fixes
Performance
Refactor
WHATWG URL APIinstead ofurl.resolveby @yoshinorin in #5136CI/CD
Dependencies
hexo-logfrom3.2.0to4.0.1by @yoshinorin in #5096Test
Misc
otherissue template (#5248) by @yoshinorin in #5248git-exec-and-restage(#5281) by @uiolee in #5281New Contributors
Full Changelog
Appendix: Changes between v7.0.0(RC2) and v7.0.0
Breaking Changes
link(#5253) by @stevenjoezhang in #5253New Feature
Performance
Fixes
CI/CD
Dependencies
Misc
otherissue template (#5248) by @yoshinorin in #5248git-exec-and-restage(#5281) by @uiolee in #5281Full Changelog
hexojs/hexo@v7.0.0-rc2...v7.0.0
v6.3.0Compare Source
New Features
view rawby @stevenjoezhang in #4996language_attroption (hexojs/hexo-util#278) by @renbaoshuo in #5017is_home_first_page()helper by @renbaoshuo in #5006Improvements
Fixes
db.jsonfile path in debug logging on Windows by @stevenjoezhang in #4994Refactors
Test
CI/CD
release-drafterby @yoshinorin in #5044Dependencies
Misc
New Contributors
Full Changelog: hexojs/hexo@6.2.0...6.3.0
v6.2.0Compare Source
Fixes
Refactors
Dependencies
Miscs
Your theme _config.ymlsection by @yoshinorin in #4931New Contributors
Full Changelog: hexojs/hexo@6.1.0...6.2.0
v6.1.0Compare Source
New Features
Fixes
post_asset_folderis set, restrict renderable files to default file extension by @kristofzerbe in #4781Tests
Dependencies
Misc
How to testsection by @stevenjoezhang in #4576New Contributors
Full Changelog: hexojs/hexo@6.0.0...6.1.0
v6.0.0Compare Source
Breaking Changes
Security
Please see more detail: Announcement: About CVE-2021-25987
New features
og:imageandtwitter:image@KentarouTakeda [#4748]Performance
Fixes
Refactor
Array.flat()@curbengh [#4806]Docs
Dependencies
New Contributors
Full Changelog: hexojs/hexo@5.4.0...6.0.0
v5.4.2Compare Source
Fixes
js-yamlfromv4.xtov3.14.xby @yoshinorin in #4932Full Changelog: hexojs/hexo@5.4.1...5.4.2
v5.4.1Compare Source
Fixes
Full Changelog: hexojs/hexo@5.4.0...5.4.1
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.