Conversation
…rkflows/validate_docs_build.yml)
|
This pull request uses an unusual Hugo version ("0.152.2") in the CI workflow which appears to be non-existent or unstable, risking build failures and pipeline instability; consider pinning to a known stable Hugo release.
Use of Potentially Unstable or Non-Existent Dependency Version in
|
| Vulnerability | Use of Potentially Unstable or Non-Existent Dependency Version |
|---|---|
| Description | The CI/CD pipeline is configured to use Hugo version '0.152.2'. This version number is highly unusual for a stable Hugo release, which typically follows a '0.XX.X' pattern with much lower patch numbers. Searches for this specific version using vulnerability lookup tools and general release information yielded no results, indicating it is likely a non-existent, pre-release, or otherwise unstable version not intended for production use. While no specific CVEs were found for this version (likely because it's not a recognized stable release), its use introduces significant risk of build failures and instability in the CI/CD pipeline. |
django-DefectDojo/.github/workflows/gh-pages.yml
Lines 18 to 21 in 5e59c34
All finding details can be found in the DryRun Security Dashboard.
Contributor
|
I'm going to let @paulOsinski have the first approval on this one. |
Maffooch
approved these changes
Nov 10, 2025
Contributor
|
All good! |
paulOsinski
approved these changes
Nov 12, 2025
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Maffooch
pushed a commit
to valentijnscholten/django-DefectDojo
that referenced
this pull request
Feb 16, 2026
…rkflows/validate_docs_build.yml) (DefectDojo#13665) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Paul Osinski <42211303+paulOsinski@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.152.1->0.152.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
gohugoio/hugo (gohugoio/hugo)
v0.152.2Compare Source
In
v0.152.0we tightened the source validation for file mounts. We always said that project mounts can mount with absolute file/directorynames, modules/themes are restricted to relative. Inv0.152.0we narrowed module/themes mounts to be local, which made the setup in the bug report listed below fail:One part of this is security. But the construct above is usually very odd (the project uses files in a theme/module, not the other way around) and not very portable. But the example above demonstrates a valid exception, that we now have added support for in a portable way. The above example now works as it did before
v0.152.0, but going forward you can also write:We now have the
node_modulesas a special case: For themes/modules we first check if the mounted source exists locally, if not we try relative to the project root.What's Changed
1c8c21e@jmooring #14086809ebe0@bep #1408908a0679@jordelverConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.