Skip to content

fix(deps): update dependency hexo to v6 [security]

CC康纳百川请求将renovate/npm-hexo-vulnerability合并到master

Created by: renovate[bot]

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
hexo (source) 5.4.0 -> 6.0.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-25987

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.


Release Notes

hexojs/hexo

v6.0.0

Compare Source

Breaking Changes

Security

Please see more detail: Announcement: About CVE-2021-25987

New features

Performance

Fixes

Refactor

Docs

Dependencies

New Contributors

Full Changelog: https://github.com/hexojs/hexo/compare/5.4.0...6.0.0

v5.4.2

Compare Source

Fixes

Full Changelog: https://github.com/hexojs/hexo/compare/5.4.1...5.4.2

v5.4.1

Compare Source

Fixes

Full Changelog: https://github.com/hexojs/hexo/compare/5.4.0...5.4.1


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

合并请求报告