Skip to content

ci: bump uv from 0.12.5 to 0.12.20 in /.github - #4

Merged
kingletas merged 1 commit into
mainfrom
dependabot/pip/dot-github/uv-0.12.19
Oct 2, 2026
Merged

kingletas merged 1 commit into
mainfrom
dependabot/pip/dot-github/uv-0.12.19

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps uv from 0.12.5 to 0.12.20.

Release notes

Sourced from uv's releases.

0.12.20

Release Notes

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

Install uv 0.12.20

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | sh

Install prebuilt binaries via powershell script

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.20

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

0.12.19

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 1, 2026
Bumps [uv](https://github.com/astral-sh/uv) from 0.12.5 to 0.12.20.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.5...0.12.20)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title ci: bump uv from 0.12.5 to 0.12.19 in /.github ci: bump uv from 0.12.5 to 0.12.20 in /.github Oct 2, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/dot-github/uv-0.12.19 branch from 4edd473 to 899a7b6 Compare October 2, 2026 12:08
@kingletas
kingletas merged commit c2d5d42 into main Oct 2, 2026
5 checks passed
@kingletas
kingletas deleted the dependabot/pip/dot-github/uv-0.12.19 branch October 2, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant