Repository navigation
chore(deps): update dependency astral-sh/uv to v0.13.0 - #54
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 3, 2026 21:11
daee770 to
885f9e4
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 5, 2026 01:07
885f9e4 to
60be32f
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 5, 2026 21:09
60be32f to
3bae168
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 10, 2026 13:52
3bae168 to
be83a8f
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 10, 2026 21:59
be83a8f to
03cf8f0
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 16, 2026 13:10
03cf8f0 to
917237e
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 17, 2026 23:52
917237e to
2afc170
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 24, 2026 08:34
2afc170 to
65422ae
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
February 25, 2026 02:09
65422ae to
ea83269
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
2 times, most recently
from
March 3, 2026 22:09
8f214bb to
eb21677
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
March 7, 2026 00:34
eb21677 to
1bb7131
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
March 13, 2026 20:39
1bb7131 to
9d2b76a
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
March 17, 2026 01:14
9d2b76a to
6bd4094
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
March 20, 2026 01:10
6bd4094 to
d664428
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
2 times, most recently
from
April 16, 2026 08:51
f194f02 to
a20ef84
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
April 27, 2026 15:32
a20ef84 to
63b4b33
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 5, 2026 09:02
63b4b33 to
c959be0
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 5, 2026 22:28
c959be0 to
bba0da6
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 6, 2026 21:06
bba0da6 to
ba7a9f1
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 9, 2026 01:57
ba7a9f1 to
22b7c80
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 11, 2026 05:52
22b7c80 to
9f40193
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 12, 2026 21:56
9f40193 to
7233a98
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 18, 2026 21:09
7233a98 to
cdbe385
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 22, 2026 01:01
cdbe385 to
45b987c
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
May 29, 2026 00:16
45b987c to
a7a556f
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
June 1, 2026 20:41
a7a556f to
198851e
Compare
renovate
Bot
force-pushed
the
renovate/astral-sh-uv-0.x
branch
from
June 4, 2026 00:03
198851e to
b4606b7
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.26→0.13.0Release Notes
astral-sh/uv (astral-sh/uv)
v0.13.0Compare Source
Released on 2026-10-09.
uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.
We expect most users to be able to upgrade without making changes.
While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. uv may download or rebuild dependencies after upgrading, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.
There are no breaking changes to the configuration of the uv build backend. If your
[build-system]table includes an upper bound onuv_build, update it to allowuv_build0.13, e.g.,uv_build>=0.13.0,<0.14.Breaking changes
Use Python 3.15 as the default stable version
The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running
uv python install.uv continues to use compatible Python installations that are already present. For example,
uv venvcan still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such asuv venvanduvx pythoncan now download Python 3.15.You can opt out of this behavior by requesting Python 3.14 explicitly, e.g.,
uv venv --python 3.14. For projects, useuv python pin 3.14to record the version in.python-version.Honor
--require-hashesin included constraints files (#22275)Previously, uv ignored
--require-hashesin constraints files included with-cfrom a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the
--require-hashesdirective from the included constraints file if hash checking is not intended.Prefer native Python on Windows ARM64 (#22100)
Previously, ARM64 builds of uv preferred emulated
x86_64Python installations because native wheel support was limited. Now, uv prefers native ARM64 (aarch64) interpreters across Python versions.This follows similar changes in CPython, the official Windows Python install manager, and GitHub's actions/setup-python.
When a native interpreter is unavailable, uv continues to fall back to
x86_64, then 32-bitx86.You can opt out of this behavior by setting
UV_PYTHON_ARCH=x86_64or requesting an explicit architecture, e.g.,cpython-3.14-windows-x86_64. If you are usingsetup-uv, you can setpython-arch: x86_64instead.Reject editable requirements in included constraints files (#22282)
Previously, uv silently ignored editable (
-e) requirements in constraints files included with-cfrom a requirements file. Now, uv rejects these requirements with an error, matching pip's behavior.You cannot opt out of this behavior. Move editable requirements to a requirements file passed with
-r, or pass them directly with--editable, instead of including them in a constraints file.Omit the distutils startup patch on Python 3.10 and later (#22096)
Previously, uv installed
_virtualenv.pyand_virtualenv.pthinto every new virtual environment to prevent distutils configuration from changing installation paths. Now, likevirtualenv21.6.0, uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.
This stabilizes the
no-distutils-patchpreview feature.Treat requirement-file option values as single paths (#22290)
Previously, uv split values passed to
--constraint,--override,--exclude, and--build-constrainton spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace
-c "a.txt b.txt"with-c a.txt -c b.txt.Space-separated lists in
UV_CONSTRAINT,UV_OVERRIDE,UV_EXCLUDE, andUV_BUILD_CONSTRAINTremain supported.Use
tar-codecfor tar archives by default (#22094)Previously, uv used
astral-tokio-tarto extract tar archives, build source distributions withuv_build, and read their metadata foruv publish. Now, uv usestar-codec, which applies stricter validation when reading archives.uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by
uv_buildcan also have different archive bytes and hashes.You can opt out of this behavior by setting
UV_LEGACY_TAR_BACKEND=1.This stabilizes the
tar-codecpreview feature.Reject
uv build --clearoutput directories that contain a build source(#22276)
Previously,
uv build --clearcould delete a project or input source distribution when theoutput directory contained the source. Now, uv rejects these output directories, including
equivalent paths reached through symlinks, before clearing any build output.
Select an output directory that does not contain any build sources, or omit
--clear.Python
Preview features
--require-build-hashes(#21411)Performance
Bug fixes
v0.12.24Compare Source
Release Notes
Released on 2026-10-08.
Enhancements
uv cache prune(#22171)Preview features
uv auditreports, prioritizing PYSEC, GHSA, then CVE identifiers (#22292)Configuration
UV_NO_CACHE=falseto overrideno-cache = truein configuration (#22324)Performance
--find-linkspages withastral-html(#22203)uv-buildexecutable size by 7.5% by omitting unused Zstandard support (#22242)Bug fixes
--no-require-hashesorrequire-hashes = false(#22369)uv publish --trusted-publishingvalues precedence over configuration (#22279)UV_OFFLINE=falseto overrideoffline = truein configuration (#22283)UV_SYSTEM_CERTS=falseto overridesystem-certs = truein configuration (#22291)uv auth loginover IPv6 loopback addresses (#22306)#or%characters (#22281)uv versionanduv self versionwith a single--quietflag (#22280)WHEELmetadata contains multiple expandedTag:rows (#22235)--keyring-provideroption fromuv authhelp (#19520)uv toolrequirements (#22320)Documentation
required-environmentsdocumentation (#22238)Install uv 0.12.24
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"Download uv 0.12.24
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
v0.12.23Compare Source
Release Notes
Released on 2026-10-03.
Python
Preview features
uv.lockwithout a workspace manifest usinguv sync --frozenwithfrozen-lockfile(#22018)uv.lockwithout a workspace manifest usinguv export --frozenwithfrozen-lockfile(#22007)uv.lockwithout a workspace manifest usinguv tree --frozenwithfrozen-lockfile(#22016)uv.lockwithout a workspace manifest usinguv workspace metadata --frozenwithfrozen-lockfile(#22017, #22018)Bug fixes
win_amd64wheels instead of building from source (#22099)Install uv 0.12.23
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"Download uv 0.12.23
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
v0.12.22Compare Source
Release Notes
Released on 2026-10-01.
Python
Enhancements
--offlineoption fromuv publishhelp (#22124)Preview features
--no-default-groupsinuv audit(#22090)uv auditoruv tool auditruns offline and hide the unsupported option from help (#22114)Configuration
UV_PYTHON_ARCHto select an interpreter architecture independently of its Python version (#22098)Performance
Bug fixes
Other changes
Install uv 0.12.22
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.22/uv-installer.ps1 | iex"Download uv 0.12.22
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
v0.12.21Compare Source
Release Notes
Released on 2026-09-29.
Python
Enhancements
[manifest]tables from lockfiles that contain only manifest subtables (#22070)Preview features
uv.lock, including those involving pre-releases, with theresolution-inputspreview feature (#22004, #22068)Bug fixes
uv python pin --rmfrom removing a global.python-versionsfile without--global(#21992)Install uv 0.12.21
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"Download uv 0.12.21
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
v0.12.20Compare Source
Release Notes
Released on 2026-09-28.
Enhancements
Preview features
lockfile-normalizationpreview feature (#21951)pylock.toml(#22003)pylock.tomlfiles relative to the output file (#22042)tool-install-locksrequirements resolve to the same package (#22000)lock-without-metadatalockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)uv workspace metadataanduv tree --format jsonoutput (#22050)Configuration
XDG_CONFIG_DIRSafter empty entries (#21987)Performance
Bug fixes
--require-hashesand--verify-hashes(#21996)--no-build(#21988)--all-packages, including--no-install-projectand--no-emit-project(#21994)pyproject.tomlifuv upgradefails or is interrupted (#21983)--show-settings(#21989)uv python listanduv python upgradeinstead of panicking (#22033)/install(#22036)Install uv 0.12.20
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.ps1 | iex"Download uv 0.12.20