---
title: "Release v0.161.1 · gohugoio/hugo"
url: https://daily.dev/posts/release-v0-161-1-gohugoio-hugo-lmnqiguqq
source_url: https://github.com/gohugoio/hugo/releases/tag/v0.161.1
type: article
source: "Hugo"
published: 2026-04-29T17:47:02.135Z
updated: 2026-04-29T17:47:23.382Z
tags: ["security", "golang"]
reading_time: 1
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Release v0.161.1 · gohugoio/hugo

**[Hugo](https://daily.dev/sources/hugo)** · 1 min read · 0 upvotes · 0 comments

## Summary

Hugo v0.161.1 is a patch release with four changes: resources.GetRemote now honors the Retry-After HTTP header during retries, the warpc module migrates to the parson.c JSON library, a new AllowChildProcess option is added to security.node.permissions config, and the default HTTP URL security rule for '@' denial is narrowed to apply only to userinfo rather than the full URL.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.com/gohugoio/hugo/releases/tag/v0.161.1>

## Similar posts on daily.dev

- [Release v0.161.0 · gohugoio/hugo](https://daily.dev/posts/release-v0-161-0-gohugoio-hugo-8gacipf2u) · Hugo · 0 upvotes · 0 comments
- [Release v0.163.1 · gohugoio/hugo](https://daily.dev/posts/release-v0-163-1-gohugoio-hugo-8arc16a1i) · Hugo · 0 upvotes · 0 comments
- [Release v0.162.0 · gohugoio/hugo](https://daily.dev/posts/release-v0-162-0-gohugoio-hugo-egkcuot9a) · Hugo · 18 upvotes · 1 comments
- [Release v0.165.0 · gohugoio/hugo](https://daily.dev/posts/release-v0-165-0-gohugoio-hugo-4zn1e82fe) · Hugo · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#golang](https://daily.dev/tags/golang)

[View this post on daily.dev](https://daily.dev/posts/release-v0-161-1-gohugoio-hugo-lmnqiguqq)
