Repository navigation
[Snyk] Upgrade hexo from 4.0.0 to 4.2.0 - #14
Merged
MichaelKohler merged 1 commit intoMar 16, 2020
Merged
Conversation
Snyk has created this PR to upgrade hexo from 4.0.0 to 4.2.0. See this package in NPM: https://www.npmjs.com/package/hexo See this project in Snyk: https://app.snyk.io/org/michaelkohler-eeo/project/a7d76bb4-a4ae-41bc-b632-f9d9846d11ac?utm_source=github&utm_medium=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade hexo from 4.0.0 to 4.2.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.Release notes
Package name: hexo
-
4.2.0 - 2019-12-22
- Caching is disabled by default in hexo-server [#3963]
- It's disabled so that any changes (particularly to the theme's layout) can be previewed in real-time.
- If you use hexo-server in production environment to serve your website, it can be enabled by,
- Add
- Example usage:
- Merges similar theme configs in main config and theme's config [#3967]
- For example:
- Plus,
- Fixes some caching issue [#3985]
- Open Graph now applies all
-
- Lodash
- However, we plan to completely drop it in the coming Hexo 5.0.0
- This project page includes all the relevant pull requests which you may find useful
-
- This means Hexo no longer includes cheerio as part of its production dependencies (it's still a development dependency)
- This also means the following initialization methods no longer work,
- To use cheerio,
-
4.1.1 - 2019-12-12
- Add
- Use the following config to remove the trailing ".html" from permalink variables
- Example:
- Set default locales (in "language_TERRITORY" format) for
- Previously
- With this fix, if the language is "en",
- "node_modules/" and ".git/" folders in themes/ are now always ignored [#3918]
- Further reduces lodash usage [#3880]
-
4.1.0 - 2019-12-09
- Requires Node 8.10 or above [#3778]
- Node 8 is going to be deprecated in less than a month, we strongly urge to upgrade to Node 10 or newer
- Not all locales are supported (e.g.
- Dash (e.g. "en-GB") must be used for multilingual support, dash is automatically transformed to underscore (e.g. "en_GB") in
- Verify the corresponding file exists in the
- Support adding hour and minute to post permalink [#3629]
- Example usage:
- Results in
- Insert
- Enable
- Affects
- Requires supported browsers to benefit from this feature
- Unsupported browsers would simply ignore the attribute, thus it is safe to use and always enabled
- Example usage:
- Insert the following snippet (if EJS is used) inside
- would output
- Hexo 3.9.0+ inserts the tag automatically; to get the performance benefit (of the
- Support custom attributes in
- Example usage:
- Support
- Enabled by default, enabling
- Configure in
- This option also can be passed to
- Retain blank lines in a codeblock attached in blockquote [#3770]
- Replaced deprecated
- Replaced deprecated
- meta_generator tag should be inserted into
- No longer clear database
- Completely ignore files/folders specified in
- If you're using Webpack or related tools in your theme, the
- A temporary workaround is to configure Hexo to ignore that folder,
- The workaround will no longer be necessary in future version
- jsfiddle, vimeo and youtube tag plugins now use https only [#3806]
- Prevent unnecessary insertion of front-matter when using alias in Hexo CLI [#3830]
- Applies
- Add FOSSA license analyzer for open-source software license compliance [#3779]
- Run benchmark in CI to catch regression [#3776]
- Further reduces lodash usage [#3786], [#3788], [#3790], [#3785], [#3809], [#3791], [#3810], [#3826], [#3867], [#3845]
- Remove unnecessary file at the end of unit test [#3792]
- Add funding source to npm [#3851]
- Update bump strip-ansi from 5.2.0 to 6.0.0 [#3852]
- Update chalk from 2.4.2 to 3.0.0 [#3853]
-
4.0.0 - 2019-10-16
- chore: drop Node 6 #3598
- fix post_link, asset_link when title contains unescaped html charaters #3704
- Affects
- If you want to retain unescaped characters, set
- fix: encode permalink by default #3708
- If you currently use
- Use
- Use
- Drop
- If you want to use the variables in decoded form,
- Use
- This change does not apply to
- fix(paginator): add
- Theme devs, if you customize
-
- Support
-
- Refer to micromatch docs for advanced globbing
-
- Add
-
- If you experience "Out of memory" issue, try lowering the value in
-
- If you prefer not to use file modification time in the
-
-
- Use the following config to remove the trailing
- Does not apply to
- Should be compatible with existing canonical-related plugins, recommend plugin and theme devs to test
-
- use this helper
-
- added
- perf(meta_generator): drop cheerio #3671
- perf(open_graph): drop cheerio and use regex #3680
- perf(external_link): drop cheerio and use regex #3685
- perf(cache): enforce caching across modes #3756
- fix: set english as default #3654
- Use filename when title is not specified in the front-matter #3672
- fix: ignore categories / tags with zero posts #3624
- fix(open_graph): remove index.html from url #3661
- fix(open_graph): remove duplicate twitter card tags #3668
- fix(helpers, tag plugins): encode url by default #3710
- Refer to #3708 for guide on decoding.
- fix(open_graph): percent-encode url, not html escape #3686
- fix: Allow backtick code block in "blockquote" tag plugin #2321
- fix: Correct processing of backtick code block on blockquote #3765
- fix: prevent inserting extra new line character into the end of backtick code block #3768
- chore(deps): update tildify requirement from ^1.2.0 to ^2.0.0 #3541
- chore(deps): update strip-indent requirement from ^2.0.0 to ^3.0.0 #3534
- chore(deps-dev): update husky requirement from ^1.1.3 to ^3.0.0 #3608
- chore(deps-dev): update eslint requirement from ^5.9.0 to ^6.0.1 #3606
- chore(deps-dev): update lint-staged requirement from ^8.1.0 to ^9.1.0 #3615
- chore: update to hexo-util@1.0.1 and hexo-renderer-marked@2.0.0 #3646
- chore(deps): update hexo-i18n requirement from ^0.2.1 to ^1.0.0 #3698
- chore(deps): update hexo-fs requirement from ^1.0.0 to ^2.0.0 #3699
- chore(deps): update hexo-front-matter requirement from ^0.2.3 to ^1.0.0 #3700
- chore(deps): update hexo-log requirement from ^0.2.0 to ^1.0.0 #3730
- chore(deps): update warehouse requirement from ^2.2.0 to ^3.0.0 #3736
- chore(deps): bump hexo-cli from 2.0.0 to 3.0.0 #3743
from hexo GitHub release notesFeatures
min_depth:option totoc()helper [#3997]Fixes
themevariable should have,pretty_urlsoptions toog:urltag [#3983]Refactor
No longer uses lodash [#3969], [#3987], [#3753]
_is still available as a global variable, usually utilized in theme layout.Completely drops cheerio [#3850], [#3677]
Feature
trailing_html:topretty_urls:option to remove ".html" from url [#3917]https://yoursite.com/page/about.html->https://yoursite.com/page/aboutFixes
og:localeOpen Graph tag [#3921]og:localewas inserted only iflanguage:is configured in "language-TERRITORY" formatog:localewill default to "en_US". Refer to the pull request for the full list.meta_generator()helper should output the correct Hexo version [#3925]permalink_defaults:option should be parsed, not replaced [#3926]Refactor
Breaking change
og:localeOpen Graph tag won't be inserted iflanguage:(in config, front-matter of post/page oropen_graph()helper) is not inlanguage-TERRITORYformat [#3808]enis invaliden-GBis validen-AUis not valid), see official listog:localelanguages/folder of installed theme before changing thelanguage:configFeatures
https://yoursite.com/2019/12/09/23/59/a-post/article:published_time[#3674]article:author[#3805] Open Graph tagslazyloadin iframe-related tag plugins [#3798]iframe,jsfiddle,vimeo,youtubetag pluginsmeta_generatorhelper to insert metadata element tag [#3782]<head>element of your theme layout,<meta name="generator" content="Hexo 4.1.0">meta_generatorhelper),meta_generator:option should be disabled,js()[#3681] andcss()[#3690] helperswrap:option to enable/disable wrapping backtick codeblock in<table>element [#3827]line_numberalso enables ithighlight:codeblock()tag plugin [#3848]{% codeblock lang:js wrap:false %} const foo = (bar) => { return bar; }; {% endcodeblock %}Fixes
og_updated_timeOpen Graph tag witharticle:modified_time[#3674]keywordsOpen Graph tag witharticle:tag[#3805]<head>that spans multiple lines [#3778]db.jsonwhen runninghexo neworhexo --help[#3793]ignore:option [#3797]node_modulesfolder could cause some issuesexternal_linkfilter should not process data URLs (e.g.mailto:&javascript:) [#3812] and<article>element [#3895]-pis alias of--path-sis alias of--slug-ris alias of--replaceinclude:andexclude:options to post's asset folder [#3882]ignore:option should work for files, in addition to folders [#3878]Housekeeping
Breaking change
asset_link,post_linktag pluginsfalseto the final argument{% asset_link 'filename 'title' 'false' %}encodeURI(post.permalink)(includingpermalinkof page, tag & category variables), there are three options:encodeURI(decodeURI(post.permalink))for backward-compatibility with hexo v3.9 (and older)encodeURL()function provided by hexo-util, it is backward-compatibleencodeURI()function, this breaks backward-compatibilitydecodeURI(post.permalink)decodeURL()of hexo-util can decode punycoded domain.this.urlvariable.escapeoption for compatibility with hexo-util@1.3.0 #3728prev_text/next_textwith html (e.g. to insert icons), you need to setescape: falsein the parameter.Feature
feat(filter): use existing excerpt if possible #3612
excerpt:in front-matterswitch minimatch to micromatch #3538
feat: add option to disable meta generator tag #3653
meta_generator: falseto config to disablefeat(generator): allow limit parallel generation #3665
hexo g --concurrency <number>Option to use date instead of file mtime for updated date #3235
post.updatedvariable, setuse_date_for_updated: truein configfeat(list_tags): add Schema "keywords" and Microdata "tag" #3678
feat(permalink_variable): add pretty_urls option to remove index.html from url #3691
index.htmlfrompermalinkvariablesthis.urlvariable (see #3661).feat: add
full_url_forhelper #3701full_url_for(page.path)instead ofconfig.url + page.pathfix: external_link should use after_render #3675
fieldandexcludeoptions, see #3675 for guide.Performance
Fix
Dependency
Commit messages
Package name: hexo
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs