Skip to content

deps: bump astral-sh/uv from 0.12.19 to 0.12.24 - #389

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/astral-sh/uv-0.12.24
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/astral-sh/uv-0.12.24

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Warning

Cooldown could not be applied because no publication date was available from the registry.

Bumps astral-sh/uv from 0.12.19 to 0.12.24.

Release notes

Sourced from astral-sh/uv's releases.

0.12.24

Release Notes

Released on 2026-10-08.

Enhancements

  • Remove orphaned temporary build environments with uv cache prune (#22171)
  • Accept PEP 508 marker operators directly before grouped expressions (#22309)
  • Reject malformed requirements-file options instead of partially parsing or ignoring them (#22317)
  • Show underlying filesystem and registry errors when managed Python uninstallation fails (#22362)
  • Identify the invalid source URL in Python mirror errors (#22364)

Preview features

  • Display preferred advisory IDs in uv audit reports, prioritizing PYSEC, GHSA, then CVE identifiers (#22292)

Configuration

  • Support custom installation mirrors for GraalPy (#22269)
  • Support custom installation mirrors for Pyodide (#22271)
  • Allow UV_NO_CACHE=false to override no-cache = true in configuration (#22324)
  • Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#22144)

Performance

  • Speed up later commands after creating an environment by warming its interpreter cache (#21304)
  • Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#22246)
  • Enforce resource limits when parsing package indexes and --find-links pages with astral-html (#22203)
  • Reduce standalone uv-build executable size by 7.5% by omitting unused Zstandard support (#22242)
  • Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#22144)
  • Reduce Python download error formatting code size by sharing its formatter (#22141)

Bug fixes

  • Verify supplied hashes even when hash presence is disabled with --no-require-hashes or require-hashes = false (#22369)
  • Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#22360)
  • Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#22237)
  • Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#22234)
  • Give explicit uv publish --trusted-publishing values precedence over configuration (#22279)
  • Allow UV_OFFLINE=false to override offline = true in configuration (#22283)
  • Allow UV_SYSTEM_CERTS=false to override system-certs = true in configuration (#22291)
  • Allow uv auth login over IPv6 loopback addresses (#22306)
  • Resolve GitHub dependencies whose Git references contain # or % characters (#22281)
  • Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#22322)
  • Preserve JSON output from uv version and uv self version with a single --quiet flag (#22280)
  • Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#22284)
  • Restore wheel incompatibility hints when WHEEL metadata contains multiple expanded Tag: rows (#22235)
  • Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#22302)
  • Prevent workspace-cache assertion failures after modifying a project at the workspace root (#22236)

... (truncated)

Changelog

Sourced from astral-sh/uv's changelog.

0.12.24

Released on 2026-10-08.

Enhancements

  • Remove orphaned temporary build environments with uv cache prune (#22171)
  • Accept PEP 508 marker operators directly before grouped expressions (#22309)
  • Reject malformed requirements-file options instead of partially parsing or ignoring them (#22317)
  • Show underlying filesystem and registry errors when managed Python uninstallation fails (#22362)
  • Identify the invalid source URL in Python mirror errors (#22364)

Preview features

  • Display preferred advisory IDs in uv audit reports, prioritizing PYSEC, GHSA, then CVE identifiers (#22292)

Configuration

  • Support custom installation mirrors for GraalPy (#22269)
  • Support custom installation mirrors for Pyodide (#22271)
  • Allow UV_NO_CACHE=false to override no-cache = true in configuration (#22324)
  • Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#22144)

Performance

  • Speed up later commands after creating an environment by warming its interpreter cache (#21304)
  • Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#22246)
  • Enforce resource limits when parsing package indexes and --find-links pages with astral-html (#22203)
  • Reduce standalone uv-build executable size by 7.5% by omitting unused Zstandard support (#22242)
  • Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#22144)
  • Reduce Python download error formatting code size by sharing its formatter (#22141)

Bug fixes

  • Verify supplied hashes even when hash presence is disabled with --no-require-hashes or require-hashes = false (#22369)
  • Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#22360)
  • Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#22237)
  • Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#22234)
  • Give explicit uv publish --trusted-publishing values precedence over configuration (#22279)
  • Allow UV_OFFLINE=false to override offline = true in configuration (#22283)
  • Allow UV_SYSTEM_CERTS=false to override system-certs = true in configuration (#22291)
  • Allow uv auth login over IPv6 loopback addresses (#22306)
  • Resolve GitHub dependencies whose Git references contain # or % characters (#22281)
  • Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#22322)
  • Preserve JSON output from uv version and uv self version with a single --quiet flag (#22280)
  • Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#22284)
  • Restore wheel incompatibility hints when WHEEL metadata contains multiple expanded Tag: rows (#22235)
  • Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#22302)
  • Prevent workspace-cache assertion failures after modifying a project at the workspace root (#22236)
  • Hide the ignored --keyring-provider option from uv auth help (#19520)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.12.19 to 0.12.24.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.19...0.12.24)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.12.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants