<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh" -->

---
title: Hugo Updates: Versions 0.151.1 and 0.151.2 Address...
description: Hugo versions 0.151.1 through 0.152.2 bring critical security patches via Go 1.25.3 upgrade, transition to goccy/go-yaml library with YAML 1.1 support, fixes...
canonical: https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hugo Updates: Versions 0.151.1 and 0.151.2 Address Security and Functionality Enhancements | daily.dev
og:description: Hugo versions 0.151.1 through 0.152.2 bring critical security patches via Go 1.25.3 upgrade, transition to goccy/go-yaml library with YAML 1.1 support, fixes...
og:url: https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh
og:image: https://api.daily.dev/og/posts/NglMSafMH.png
og:image:alt: Hugo Updates: Versions 0.151.1 and 0.151.2 Address Security and Functionality Enhancements
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hugo Updates: Versions 0.151.1 and 0.151.2 Address Security and Functionality Enhancements

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Hugo versions 0.151.1 through 0.152.2 bring critical security patches via Go 1.25.3 upgrade, transition to goccy/go-yaml library with YAML 1.1 support, fixes for CJK character handling and shortcode nesting, and resolution of file mount configuration issues with node_modules directories. The YAML library change affects how unquoted strings are interpreted and adds support for anchors and aliases.

## Content

The recent releases of Hugo have introduced several improvements, crucial fixes, and updates to enhance the tool's security, functionality, and compatibility.

### v0.151.1

Hugo v0.151.1 tackled upstream security vulnerabilities by upgrading to Go 1.25.3, incorporating 10 vital security fixes, and patching the net/html package. This update also addressed Chinese, Japanese, and Korean (CJK) character handling in string truncation, fixed shortcode error handling issues, and included optimizations for memory allocation and markup rendering. Furthermore, multiple dependencies such as esbuild and golang.org packages were updated to enhance performance and security.

### v0.152.0

In Hugo v0.152.0, a significant upgrade was made to the YAML processing library, transitioning to goccy/go-yaml. This change aligns with YAML 1.1 specifications, altering how unquoted strings like 'yes', 'no', 'on', 'off' are treated, now interpreted as strings instead of booleans. Additionally, support for YAML anchors and aliases was added to minimize configuration duplication. Other enhancements included refining config handling, module mounts, and internationalization (i18n) error message outputs.

### v0.151.2

The v0.151.2 release addressed a specific regression concerning shortcode nesting. Previous issues with nested shortcodes sharing identical names were resolved, ensuring proper parsing and usage in content creation. A new test case was also added to verify the fix and improve parser robustness.

### v0.152.1

Version 0.152.1 focused on resolving five bugs that were introduced with the new YAML library in v0.152.0. These included numeric type conversions in templates, issues with uint64 handling in 'where' clauses and sorting, compatibility problems of YAML integers with Go's integer types, and eliminating nil map errors arising from empty YAML configuration files.

### v0.152.2

The v0.152.2 release resolved a regression from v0.152.0 affecting file mount configurations with relative paths. This update added specialized handling for `node_modules` directories, allowing them to be mounted effectively whether they are in the local theme/module directory or at the project root. This ensures the seamless integration of dependencies like Bootstrap while maintaining necessary security measures.

These updates collectively strengthen Hugo's functionality, security posture, and user experience, providing a more robust and efficient static site generation tool.

---

Tags: [#security](https://daily.dev/tags/security), [#golang](https://daily.dev/tags/golang)

[View this post on daily.dev](https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hugo Updates: Versions 0.151.1 and 0.151.2 Address Security and Functionality Enhancements","url":"https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh"},"datePublished":"2025-10-16T22:01:16.429Z","dateModified":"2025-10-24T16:12:12.953Z","description":"Hugo versions 0.151.1 through 0.152.2 bring critical security patches via Go 1.25.3 upgrade, transition to goccy/go-yaml library with YAML 1.1 support, fixes...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d9757bb549374763655347e7540b4f7?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8d9757bb549374763655347e7540b4f7?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hugo-updates-versions-0-151-1-and-0-151-2-address-security-and-functionality-enhancements-nglmsafmh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,golang","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Hugo Updates: Versions 0.151.1 and 0.151.2 Address Security and Functionality Enhancements"}]}
```

