Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 4, 2025

This PR contains the following updates:

Package Change Age Confidence
hexo (source) 6.3.0 -> 7.2.0 age confidence

GitHub Vulnerability Alerts

CVE-2023-39584

Hexo up to v7.1.1 was discovered to contain an arbitrary file read vulnerability.


Release Notes

hexojs/hexo (hexo)

v7.2.0

Compare Source

New Features

Improved type definitions

Fixes

Refactor

Test

CI/CD

Docs

Dependencies

New Contributors

Full Changelog: hexojs/hexo@v7.1.1...v7.2.0

v7.1.1

Compare Source

Fixes

Misc

  • chore: use prepublishOnly instead of prepublish and run npm install in prepublishOnly script by @​yoshinorin in #​5399

Full Changelog: hexojs/hexo@v7.1.0...v7.1.1

v7.1.0

Compare Source

Notable Changes

New Features

Fixes

CI/CD

Dependencies

New Contributors

Full Changelog: hexojs/hexo@v7.0.0...v7.1.0

v7.0.0

Compare Source

Migration Guide

built-in tags

WARNING
Some of the built-in tags have been dropped (gist, youtube, jsfiddle, and vimeo). If you use those tags in your existing blog posts, you can install hexo-tag-embed to continue using them with Hexo v7.0.0.

Note
No need to install it if you are not using (or will not use) gist, youtube, jsfiddle, vimeo tags in your post or page.

$ npm i hexo-tag-embed
Syntax highlighting

WARNING
Syntax highlighting is refactored and controlled by the following settings. See Syntax Highlighting for more details.

syntax_highlighter: highlight.js # highlight.js | prismjs | <empty>

Breaking Changes

Notable Changes

New Features

Fixes

Performance

Refactor

CI/CD

Dependencies

Test

Misc

New Contributors

Full Changelog


Appendix: Changes between v7.0.0(RC2) and v7.0.0

Breaking Changes

New Feature

Performance

Fixes

CI/CD

Dependencies

Misc

Full Changelog

hexojs/hexo@v7.0.0-rc2...v7.0.0


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Sep 4, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: packages/demo/package-lock.json
npm warn Unknown env config "store". This will stop working in the next major version of npm.
npm error code EUNSUPPORTEDPROTOCOL
npm error Unsupported URL Type "workspace:": workspace:^
npm error A complete log of this run can be found in: /runner/cache/others/npm/_logs/2025-12-03T19_09_17_177Z-debug-0.log

@netlify
Copy link

netlify bot commented Sep 4, 2025

Deploy Preview for nexmoe-demo canceled.

Name Link
🔨 Latest commit c48bf1c
🔍 Latest deploy log https://app.netlify.com/projects/nexmoe-demo/deploys/69308aec1fe5e30008d65353

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Sep 4, 2025

Deploying hexo-theme-nexmoe with  Cloudflare Pages  Cloudflare Pages

Latest commit: c48bf1c
Status: ✅  Deploy successful!
Preview URL: https://8cacc091.hexo-theme-nexmoe-9ad.pages.dev
Branch Preview URL: https://renovate-npm-hexo-vulnerabil.hexo-theme-nexmoe-9ad.pages.dev

View logs

@renovate renovate bot changed the title fix(deps): update dependency hexo to v7 [security] chore(deps): update dependency hexo to v7 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-hexo-vulnerability branch from 1873edc to e33843f Compare October 21, 2025 16:11
@renovate renovate bot force-pushed the renovate/npm-hexo-vulnerability branch from e33843f to e95b308 Compare November 10, 2025 15:11
@renovate renovate bot force-pushed the renovate/npm-hexo-vulnerability branch from e95b308 to 8ccd578 Compare November 18, 2025 09:53
@renovate renovate bot force-pushed the renovate/npm-hexo-vulnerability branch from 8ccd578 to c48bf1c Compare December 3, 2025 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants