Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump hexo-theme-redefine from 2.6.4 to 2.7.1 #32

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 5, 2024

Bumps hexo-theme-redefine from 2.6.4 to 2.7.1.

Release notes

Sourced from hexo-theme-redefine's releases.

v2.7.1

releasev270

更新日志

更改项

  • 修复:行内代码样式问题 #428 #429

更新方法:

  • NPM: npm install hexo-theme-redefine@latest
  • Git: cd themes/redefine && git pull

详见:Redefine 文档 #更新

新版本刚发布后,部分CDN 同步需要时间,如需使用,请等待几小时后,生成站点查看日志以确定 CDN 是否可用。 推荐使用 npmmirror CDN,由阿里云官方提供,访问速度极快(国内与海外)。

本版本主要为 bug 修复,不需要迁移配置文件


关于 BootCDN 以及 Staticfile CDN 投毒

Staticfile 以及 Bootcdn 由于存在 CDN 投毒的安全风险,已经不再安全。因此,Redefine 主题的新版本 (2.7.0+) 已切换到 Cloudflare 的 CDNJS 作为 Twikoo 和 Gitalk 的脚本源,并且移除这两者的支持。

如需进一步了解相关内容,请访问 【BootCDN/Staticfile投毒分析】供应链投毒后,我们的选择还剩下哪些?(来源:吾爱破解论坛)。

请及时更新主题版本到 2.7.0 即以上,并避免使用 bootCDN 和 staticfileCDN。 感谢您的理解与支持。


Release Notes

Changes

New Features (configuration file migration required)

  • None.

Update Instructions

  • NPM: npm install hexo-theme-redefine@latest
  • Git: cd themes/redefine && git pull

Configuration file migration is required to use new features. Users should check the update documentation for details.

The npmmirror CDN is recommended for fast access speeds both domestically and internationally.

... (truncated)

Commits
  • e189999 Merge pull request #430 from EvanNotFound/dev
  • 1a22cc9 chore: bump version to 2.7.1
  • 18e7746 style: improve inline code styling and color variables #428 #429
  • 0187cf4 Merge pull request #426 from EvanNotFound/dev
  • 0a1c561 chore: bump version to 2.7.0
  • 2143135 chore: bump version to 2.7.0
  • e3f73d3 refactor: Convert atom-one-light theme to Stylus variables
  • 2f78b39 feat: implement configurable code block highlight themes #380
  • 76a35c1 feat: Add configurable excerpt length for home page articles #414
  • a041a3d feat: Add custom title font option for navbar and sidebar #398
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hexo-theme-redefine](https://github.com/EvanNotFound/hexo-theme-redefine) from 2.6.4 to 2.7.1.
- [Release notes](https://github.com/EvanNotFound/hexo-theme-redefine/releases)
- [Commits](EvanNotFound/hexo-theme-redefine@v2.6.4...v2.7.1)

---
updated-dependencies:
- dependency-name: hexo-theme-redefine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants