upvote
To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE
reply
I have full control over the inputs for hugo and the output is pure static HTML. It's better if there are no CVEs but I really don't sweat these. My Hugo template runs 100% pure CSS and no JS.
reply