Release notes
*Sourced from [jekyll's releases](https://github.com/jekyll/jekyll/releases).*
> ## v3.8.4
>
> ## Bug Fixes
>
> * security: fix include bypass of EntryFilter#filter symlink check ([#7228](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7228))
Changelog
*Sourced from [jekyll's changelog](https://github.com/jekyll/jekyll/blob/master/History.markdown).*
> ## HEAD
>
> * Textile is only supported through a converter plugin ([#7003](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7003))
> * Add info how to deploy using pre-push git hook ([#7179](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7179))
>
> ### Documentation
>
> * Release post for v3.8.0 ([#6849](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6849))
> * Add Installation Instructions for Ubuntu ([#6925](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6925))
> * add liquid tag jekyll-flickr ([#6946](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6946))
> * Add 4.0 development post ([#6934](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6934))
> * Updated copy - fixed casing of SaaS on resources page. ([#6949](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6949))
> * WIP: Do not advise users to install Jekyll outside of Bundler ([#6927](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6927))
> * Don't prompt for sudo when installing with Ubuntu WSL ([#6781](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6781))
> * Fix typo ([#6969](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6969))
> * Add version number for group_by_exp doc ([#6956](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6956))
> * Update Windows install docs ([#6926](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6926))
> * Remove documentation for using Redcarpet ([#6990](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6990))
> * Updated nginx configuration for custom-404-page documentation ([#6994](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6994))
> * List all static files variables ([#7002](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7002))
> * Document that _drafts need to be contained within the custom collection directory ([#6985](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6985))
> * proposed change for passive voice. ([#7005](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7005))
> * added the CAT plugin to the plugin list ([#7011](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7011))
> * Updated to supported version ([#7031](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7031))
> * Clarify definition of 'draft' ([#7037](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7037))
> * Listed the jekyll-target-blank plugin in plugins list. ([#7046](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7046))
> * Typo ([#7058](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7058))
> * Add Hints for some Improved Travis Config in Doc ([#7049](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7049))
> * Added plugin json-get. ([#7086](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7086))
> * Update travis-ci.md to point out "this is an example Gemfile" ([#7089](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7089))
> * Adding `jekyll-info` plugin ([#7091](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7091))
> * GitHub enables you to use themes from other repos ([#7112](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7112))
> * Updates to CODE OF CONDUCT (v1.4.0) ([#7105](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7105))
> * Instructions to view theme’s files under Linux ([#7095](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7095))
> * add jekyll-xml-source ([#7114](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7114))
> * Add the jekyll-firstimage filter plugin ([#7127](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7127))
> * Use a real theme in the example ([#7125](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7125))
> * Update docs about post creation ([#7138](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7138))
> * Add DEV Community's Jekyll tag to community page ([#7139](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7139))
> * Initialize upgrading doc for v4.0 ([#7140](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7140))
> * Add version badge for date filters with ordinal ([#7162](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7162))
> * Add closing tags for <a> ([#7163](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7163))
> * Add TSV to list of supported _data files. ([#7168](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7168))
> * Corrected sample usage of postfiles ([#7181](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7181))
> * Add missing html end tag for code example in section 'For loops' ([#7199](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7199))
> * Resolve "Unable to locate package ruby2.4" error ([#7196](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7196))
> * installation instructions for Fedora ([#7198](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7198))
> * New docs ([#7205](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7205))
> * Correct stylesheet url in tutorial step 7 ([#7210](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7210))
> * Add some minor improvements to image loading in Showcase page ([#7214](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7214))
> ... (truncated)
Commits
- [`cc52cac`](https://github.com/jekyll/jekyll/commit/cc52cac81a9d8c78c01040a75c8122076cf2135f) Release :gem: 3.8.4
- [`91abe9f`](https://github.com/jekyll/jekyll/commit/91abe9f7419c4cc6e7730e5d185cc020164d4da6) Release :gem: 3.8.4
- [`d9a2758`](https://github.com/jekyll/jekyll/commit/d9a2758ff698c4efd244f5ce0d8bed49bc81ce92) 3.8.x: security: fix `include` bypass of `EntryFilter#filter` symlink check (...
- See full diff in [compare view](https://github.com/jekyll/jekyll/compare/v3.8.3...v3.8.4)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Finally, you can contact us by mentioning @dependabot.
Bumps jekyll from 3.8.3 to 3.8.4.
Release notes
*Sourced from [jekyll's releases](https://github.com/jekyll/jekyll/releases).* > ## v3.8.4 > > ## Bug Fixes > > * security: fix include bypass of EntryFilter#filter symlink check ([#7228](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7228))Changelog
*Sourced from [jekyll's changelog](https://github.com/jekyll/jekyll/blob/master/History.markdown).* > ## HEAD > > * Textile is only supported through a converter plugin ([#7003](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7003)) > * Add info how to deploy using pre-push git hook ([#7179](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7179)) > > ### Documentation > > * Release post for v3.8.0 ([#6849](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6849)) > * Add Installation Instructions for Ubuntu ([#6925](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6925)) > * add liquid tag jekyll-flickr ([#6946](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6946)) > * Add 4.0 development post ([#6934](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6934)) > * Updated copy - fixed casing of SaaS on resources page. ([#6949](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6949)) > * WIP: Do not advise users to install Jekyll outside of Bundler ([#6927](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6927)) > * Don't prompt for sudo when installing with Ubuntu WSL ([#6781](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6781)) > * Fix typo ([#6969](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6969)) > * Add version number for group_by_exp doc ([#6956](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6956)) > * Update Windows install docs ([#6926](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6926)) > * Remove documentation for using Redcarpet ([#6990](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6990)) > * Updated nginx configuration for custom-404-page documentation ([#6994](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6994)) > * List all static files variables ([#7002](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7002)) > * Document that _drafts need to be contained within the custom collection directory ([#6985](https://github-redirect.dependabot.com/jekyll/jekyll/issues/6985)) > * proposed change for passive voice. ([#7005](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7005)) > * added the CAT plugin to the plugin list ([#7011](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7011)) > * Updated to supported version ([#7031](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7031)) > * Clarify definition of 'draft' ([#7037](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7037)) > * Listed the jekyll-target-blank plugin in plugins list. ([#7046](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7046)) > * Typo ([#7058](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7058)) > * Add Hints for some Improved Travis Config in Doc ([#7049](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7049)) > * Added plugin json-get. ([#7086](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7086)) > * Update travis-ci.md to point out "this is an example Gemfile" ([#7089](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7089)) > * Adding `jekyll-info` plugin ([#7091](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7091)) > * GitHub enables you to use themes from other repos ([#7112](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7112)) > * Updates to CODE OF CONDUCT (v1.4.0) ([#7105](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7105)) > * Instructions to view theme’s files under Linux ([#7095](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7095)) > * add jekyll-xml-source ([#7114](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7114)) > * Add the jekyll-firstimage filter plugin ([#7127](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7127)) > * Use a real theme in the example ([#7125](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7125)) > * Update docs about post creation ([#7138](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7138)) > * Add DEV Community's Jekyll tag to community page ([#7139](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7139)) > * Initialize upgrading doc for v4.0 ([#7140](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7140)) > * Add version badge for date filters with ordinal ([#7162](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7162)) > * Add closing tags for <a> ([#7163](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7163)) > * Add TSV to list of supported _data files. ([#7168](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7168)) > * Corrected sample usage of postfiles ([#7181](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7181)) > * Add missing html end tag for code example in section 'For loops' ([#7199](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7199)) > * Resolve "Unable to locate package ruby2.4" error ([#7196](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7196)) > * installation instructions for Fedora ([#7198](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7198)) > * New docs ([#7205](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7205)) > * Correct stylesheet url in tutorial step 7 ([#7210](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7210)) > * Add some minor improvements to image loading in Showcase page ([#7214](https://github-redirect.dependabot.com/jekyll/jekyll/issues/7214)) > ... (truncated)Commits
- [`cc52cac`](https://github.com/jekyll/jekyll/commit/cc52cac81a9d8c78c01040a75c8122076cf2135f) Release :gem: 3.8.4 - [`91abe9f`](https://github.com/jekyll/jekyll/commit/91abe9f7419c4cc6e7730e5d185cc020164d4da6) Release :gem: 3.8.4 - [`d9a2758`](https://github.com/jekyll/jekyll/commit/d9a2758ff698c4efd244f5ce0d8bed49bc81ce92) 3.8.x: security: fix `include` bypass of `EntryFilter#filter` symlink check (... - See full diff in [compare view](https://github.com/jekyll/jekyll/compare/v3.8.3...v3.8.4)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.