Skip to content

Minor Enhancement - 2.14: Bump the jekyll group in /docs with 4 updates - #14

Merged
Lycogrypho merged 1 commit into
mainfrom
dependabot/bundler/docs/jekyll-7fb58019c1
Oct 6, 2026
Merged

Lycogrypho merged 1 commit into
mainfrom
dependabot/bundler/docs/jekyll-7fb58019c1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the jekyll group in /docs with 4 updates: jekyll-remote-theme, jekyll-relative-links, jekyll-seo-tag and jekyll-include-cache.

Updates jekyll-remote-theme from 0.5.2 to 0.6.2

Release notes

Sourced from jekyll-remote-theme's releases.

v0.6.2

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#155)

v0.6.1

Security

  • Reject local theme paths when the site is built in safe mode, so a site's _config.yml can't read files from outside the site on the build host (GHSA-3343-386p-v26g)

v0.6.0

Security

  • Cap the download size while streaming, so chunked responses without a Content-Length header are limited too (#152)
  • Reject zip entries that inflate past their declared size, and cap the total extracted size at 2 GB (#152)

Fixes

  • Honor NO_PROXY/no_proxy, and use HTTPS_PROXY for the @latest release lookup as well as the download (#152)
  • Stop registering a new at_exit handler and theme temp directory on every jekyll serve rebuild (#152)

Changes

  • Add a 10-second open timeout and a 60-second read timeout to GitHub requests (#152)

Dependencies

  • Declare required_ruby_version >= 3.0 (#145)

Infrastructure

Changelog

Sourced from jekyll-remote-theme's changelog.

0.6.2

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#155)

0.6.1

Security

  • Reject local theme paths when the site is built in safe mode, so a site's _config.yml can't read files from outside the site on the build host (GHSA-3343-386p-v26g)

0.6.0

Security

  • Cap the download size while streaming, so chunked responses without a Content-Length header are limited too (#152)
  • Reject zip entries that inflate past their declared size, and cap the total extracted size at 2 GB (#152)

Fixes

  • Honor NO_PROXY/no_proxy, and use HTTPS_PROXY for the @latest release lookup as well as the download (#152)
  • Stop registering a new at_exit handler and theme temp directory on every jekyll serve rebuild (#152)

Changes

  • Add a 10-second open timeout and a 60-second read timeout to GitHub requests (#152)

Dependencies

  • Declare required_ruby_version >= 3.0 (#145)

Infrastructure

Commits
  • 8bcedd8 Merge pull request #156 from benbalter/release/v0.6.2
  • 6db3eca Merge pull request #157 from benbalter/chore/inherit-issue-forms
  • bbb65a3 Use default issue forms and retire request-info
  • f7bb0bc Release 0.6.2
  • 5825e61 Merge pull request #155 from benbalter/docs/discoverability
  • 6aa7d15 Improve RubyGems and GitHub discoverability
  • 1900f20 Merge pull request #154 from benbalter/fix-local-path
  • 14f9e03 Return no theme paths when a local theme is rejected
  • 42646c5 Release 0.6.1
  • bef0912 Reject local theme paths in safe mode
  • Additional commits viewable in compare view

Updates jekyll-relative-links from 0.8.0 to 0.9.1

Release notes

Sourced from jekyll-relative-links's releases.

v0.9.1

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#127)

v0.9.0

Bug fixes

  • Apply the site's baseurl to links rewritten in includes, fixing project pages served from /repo/ (#125)
  • Resolve links to pages added during jekyll serve rebuilds (#125)
  • The rellinks filter now rewrites links whose href isn't the first attribute (#125)

Performance

  • Resolve link targets through one per-site index instead of scanning every page for each link (#125)

Removed

  • The internal JekyllRelativeLinks::Context class, and process_link, which was unintentionally exposed as a Liquid filter (#125)

Dependencies

  • Declare required_ruby_version >= 3.0 (#117)

Infrastructure

  • Bump github/codeql-action (#118, #122)
Changelog

Sourced from jekyll-relative-links's changelog.

0.9.1

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#127)

0.9.0

Bug fixes

  • Apply the site's baseurl to links rewritten in includes, fixing project pages served from /repo/ (#125)
  • Resolve links to pages added during jekyll serve rebuilds (#125)
  • The rellinks filter now rewrites links whose href isn't the first attribute (#125)

Performance

  • Resolve link targets through one per-site index instead of scanning every page for each link (#125)

Removed

  • The internal JekyllRelativeLinks::Context class, and process_link, which was unintentionally exposed as a Liquid filter (#125)

Dependencies

  • Declare required_ruby_version >= 3.0 (#117)

Infrastructure

  • Bump github/codeql-action (#118, #122)
Commits
  • 21c876f Release v0.9.1 (#128)
  • 95358b6 Use default issue forms and retire request-info (#129)
  • 0f31696 Improve RubyGems and GitHub discoverability (#127)
  • 3877478 Release v0.9.0 (#126)
  • d7d1d39 Apply baseurl in hooks, share one link resolver (#125)
  • 18ea456 Remove dependabot.yml (migrated to Renovate)
  • 89a8b0d Switch to :instant Renovate preset (platformAutomerge)
  • dc55e65 Onboard Renovate via shared preset
  • ac3f227 Bump github/codeql-action from 4.37.4 to 4.37.8 (#122)
  • 5dcf899 Bump github/codeql-action from 4.37.3 to 4.37.4 (#118)
  • Additional commits viewable in compare view

Updates jekyll-seo-tag from 2.9.0 to 2.9.1

Release notes

Sourced from jekyll-seo-tag's releases.

v2.9.1

Security

  • Escape all metadata attribute outputs, and make the JSON-LD block safe inside its script tag (GHSA-572m-7cg5-6j5r)
Changelog

Sourced from jekyll-seo-tag's changelog.

2.9.1 / 2026-09-29

Security

  • Escape all metadata attribute outputs, and make the JSON-LD block safe inside its script tag (GHSA-572m-7cg5-6j5r)
Commits

Updates jekyll-include-cache from 0.2.2 to 0.3.1

Release notes

Sourced from jekyll-include-cache's releases.

v0.3.1

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#46)

v0.3.0

Bug fixes

  • Name the Jekyll 4 cache JekyllIncludeCache instead of Module, and clear the digest cache on each rebuild so jekyll serve no longer grows without bound (#43)

Performance

  • Keep rendered includes in memory instead of writing each one to .jekyll-cache and wiping it before every render. Rebuilds were about 27% faster in a 1,000-page benchmark with identical output (#43)

Dependencies

  • Declare required_ruby_version >= 3.0 (#32)

Infrastructure

Changelog

Sourced from jekyll-include-cache's changelog.

0.3.1

Maintenance release: no runtime behavior changes.

Documentation

  • Add a gemspec description and RubyGems metadata (homepage, source code, bug tracker, and changelog links), and lead the README with the same one-line description (#46)

0.3.0

Bug fixes

  • Name the Jekyll 4 cache JekyllIncludeCache instead of Module, and clear the digest cache on each rebuild so jekyll serve no longer grows without bound (#43)

Performance

  • Keep rendered includes in memory instead of writing each one to .jekyll-cache and wiping it before every render. Rebuilds were about 27% faster in a 1,000-page benchmark with identical output (#43)

Dependencies

  • Declare required_ruby_version >= 3.0 (#32)

Infrastructure

Commits
  • 0351fda Release v0.3.1 (#47)
  • cee5485 Use default issue forms and retire request-info (#48)
  • 5bbb40d Improve RubyGems and GitHub discoverability (#46)
  • 951fa0d Release v0.3.0 (#45)
  • 245e525 Fix cache namespace and rebuild leak; keep include cache in memory (#43)
  • d05de44 chore(deps): update github/codeql-action action to v4.38.1 (#44)
  • 27a852e chore(deps): update github/codeql-action action to v4.38.0 (#42)
  • 0eabf4e chore(deps): update github/codeql-action action to v4.37.9 (#41)
  • 50703d8 Remove dependabot.yml (migrated to Renovate)
  • 1fd734d Switch to :instant Renovate preset (platformAutomerge)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the jekyll group in /docs with 4 updates: [jekyll-remote-theme](https://github.com/benbalter/jekyll-remote-theme), [jekyll-relative-links](https://github.com/benbalter/jekyll-relative-links), [jekyll-seo-tag](https://github.com/jekyll/jekyll-seo-tag) and [jekyll-include-cache](https://github.com/benbalter/jekyll-include-cache).


Updates `jekyll-remote-theme` from 0.5.2 to 0.6.2
- [Release notes](https://github.com/benbalter/jekyll-remote-theme/releases)
- [Changelog](https://github.com/benbalter/jekyll-remote-theme/blob/master/HISTORY.md)
- [Commits](benbalter/jekyll-remote-theme@v0.5.2...v0.6.2)

Updates `jekyll-relative-links` from 0.8.0 to 0.9.1
- [Release notes](https://github.com/benbalter/jekyll-relative-links/releases)
- [Changelog](https://github.com/benbalter/jekyll-relative-links/blob/main/CHANGELOG.md)
- [Commits](benbalter/jekyll-relative-links@v0.8.0...v0.9.1)

Updates `jekyll-seo-tag` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/jekyll/jekyll-seo-tag/releases)
- [Changelog](https://github.com/jekyll/jekyll-seo-tag/blob/master/History.markdown)
- [Commits](jekyll/jekyll-seo-tag@v2.9.0...v2.9.1)

Updates `jekyll-include-cache` from 0.2.2 to 0.3.1
- [Release notes](https://github.com/benbalter/jekyll-include-cache/releases)
- [Changelog](https://github.com/benbalter/jekyll-include-cache/blob/main/CHANGELOG.md)
- [Commits](benbalter/jekyll-include-cache@v0.2.2...v0.3.1)

---
updated-dependencies:
- dependency-name: jekyll-remote-theme
  dependency-version: 0.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: jekyll
- dependency-name: jekyll-relative-links
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: jekyll
- dependency-name: jekyll-seo-tag
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: jekyll
- dependency-name: jekyll-include-cache
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: jekyll
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies documentation Improvements or additions to documentation labels Oct 5, 2026
@Lycogrypho
Lycogrypho merged commit ada363d into main Oct 6, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/bundler/docs/jekyll-7fb58019c1 branch October 6, 2026 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant