Bump astral-sh/setup-uv from 8.3.2 to 9.0.0#64
Conversation
a5edce8 to
196c540
Compare
There was a problem hiding this comment.
IcebergAutoReview
Verdict: approve
The major upgrade is correctly scoped to four setup-uv references, retains immutable full-SHA pinning, and matches v9.0.0. The documented breaking cache-default change does not affect correctness; current CI exercises cached lint/test jobs and the same uv build path used for releases.
Findings
- No blocking findings.
Validation
- Inspected complete main...HEAD diff and commit ancestry.
- Verified only .github/workflows/ci.yml and release.yml changed, replacing v8.3.2 with v9.0.0.
- Ran git diff --check; no whitespace errors.
- Confirmed setup-uv remains pinned to the immutable 40-character v9.0.0 commit SHA.
- Relied on the supplied fully green current-head GitHub CI as the broad validation baseline.
Residual risks / optional notes
- With v9, cache pruning defaults to false, so the two cache-enabled CI jobs may consume more GitHub Actions cache storage. This is the documented intentional breaking change and is operational rather than correctness-blocking.
Automated review by Codex 196c54062f14 using IcebergAutoReview.
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@11f9893...c771a70) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
196c540 to
ac1d56e
Compare
There was a problem hiding this comment.
IcebergAutoReview
Verdict: approve
The new head is a clean rebase onto main after actions/checkout v7.0.1 landed. The effective PR delta remains limited to four setup-uv references, all pinned to the documented immutable v9.0.0 SHA. No prior blockers existed, and the rebase introduces no regression.
Findings
- No blocking findings.
Validation
- Inspected 196c540..HEAD; the only changes are the already-merged actions/checkout v7.0.1 updates from main.
- Reconstructed ancestry and confirmed HEAD is based directly on current main; main...HEAD contains only the four intended setup-uv upgrades.
- Compared the old and rebased PR commits with git range-diff and inspected affected workflow context.
- Ran git diff --check for both the follow-up delta and effective PR delta; no whitespace errors.
- Confirmed every setup-uv reference uses the full 40-character v9.0.0 commit SHA c771a70e6277c0a99b617c7a806ffedaca235ff9.
- Relied on the supplied fully green current-head GitHub CI for broad validation.
Residual risks / optional notes
- setup-uv v9 disables cache pruning by default, so cache-enabled jobs may consume more GitHub Actions cache storage. This documented operational change does not affect correctness.
Automated review by Codex ac1d56efa839 using IcebergAutoReview.
Bumps astral-sh/setup-uv from 8.3.2 to 9.0.0.
Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
c771a70chore(deps): roll up Dependabot updates (#970)2f537cachore: update known checksums for 0.11.30 (#968)2269552Speed up version client by partial response reads (#807)47a7f4fChangeprune-cachedefault tofalse(#967)71966efchore(deps): roll up Dependabot updates (#962)f12b1f0fix: fall back to distribution ID when os-release has no version field (#961)ecd24ddchore: update known checksums for 0.11.29 (#960)6a19136docs: update version references to v8.3.2 (#949)