Commit Graph

8859 Commits

Author SHA1 Message Date
Charlie Marsh c5977cc4ae Use structured source data for version IDs (#18840)
## Summary

Right now, two direct URLs with different hash fragments are considered
different versions based on `VersionId`. This PR changes the internal
representation to match our parsed URL structure. E.g., these should be
considered the same "version" if specified as direct URLs:

```text
https://files.pythonhosted.org/packages/36/55/ad4de788d84a630656ece71059665e01ca793c04294c463fd84132f40fe6/anyio-4.0.0-py3-none-any.whl#sha256=cfdb2b588b9fc25ede96d8db56ed50848b0b649dca3dd1df0b11f683bb9e0b5f

https://files.pythonhosted.org/packages/36/55/ad4de788d84a630656ece71059665e01ca793c04294c463fd84132f40fe6/anyio-4.0.0-py3-none-any.whl#sha512=f30761c1e8725b49c498273b90dba4b05c0fd157811994c806183062cb6647e773364ce45f0e1ff0b10e32fe6d0232ea5ad39476ccf37109d6b49603a09c11c2
```
2026-04-07 12:07:29 -04:00
Zanie Blue 5108919f03 Add support for --upgrade-group (#18266)
Closes https://github.com/astral-sh/uv/issues/13705

Note this only affects top-level group members, not transitive
dependencies of them.
2026-04-07 11:05:38 -05:00
Charlie Marsh 191e5f5bf4 Store relative timestamps in tool receipts (#18901)
## Summary

Tool receipts were only storing the absolute timestamp, not the relative
span. So upgrades, `--outdated`, etc., were operating off the fixed
cutoff. We now follow the approach used in the lockfile, whereby we
store the cutoff and the relative span, and use that to recompute
offsets.
2026-04-07 10:32:04 -05:00
Charlie Marsh 27dc5627d0 Add AGENTS.md (#18902)
## Summary

Like Ruff, we now use `AGENTS.md` and tell Claude to look at that for
any Claude users.
2026-04-07 10:44:14 -04:00
Charlie Marsh bca76afb9c Respect --exclude-newer in uv tool list --outdated (#18861)
## Summary

Closes https://github.com/astral-sh/uv/issues/18819.
2026-04-07 09:44:27 -04:00
Zanie Blue 2cf99b91ec Recompute relative exclude-newer values during uv tree --outdated (#18899)
See https://github.com/astral-sh/uv/issues/18708#issuecomment-4129893195

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-07 08:34:17 -05:00
Zanie Blue de7b3de062 Clarify that --exclude-newer compares artifact upload times (#18830)
Co-authored-by: Claude <noreply@anthropic.com>
2026-04-07 08:15:38 -05:00
renovate[bot] 968c3a5161 Update Rust crate env_logger to v0.11.10 (#18873)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [env_logger](https://redirect.github.com/rust-cli/env_logger) |
dev-dependencies | patch | `0.11.9` → `0.11.10` |

---

### Release Notes

<details>
<summary>rust-cli/env_logger (env_logger)</summary>

###
[`v0.11.10`](https://redirect.github.com/rust-cli/env_logger/blob/HEAD/CHANGELOG.md#01110---2026-03-23)

[Compare
Source](https://redirect.github.com/rust-cli/env_logger/compare/v0.11.9...v0.11.10)

##### Internal

- Update dependencies

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/uv).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ1cGRhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImJ1aWxkOnNraXAtZG9ja2VyIiwiYnVpbGQ6c2tpcC1yZWxlYXNlIiwiaW50ZXJuYWwiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-04-07 07:59:48 -05:00
Zanie Blue bb2667ca9b Error on --locked and --frozen when script lockfile is missing (#18832)
However, we do not error when these are set as environment variables for
backwards compatibility and general safety since those variables could
only be intended for project use.

Closes https://github.com/astral-sh/uv/issues/18826

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-07 07:33:29 -05:00
renovate[bot] 24b3e37dba Update cgr.dev/chainguard/python:latest-dev Docker digest to f475abd (#18863)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| cgr.dev/chainguard/python | container | digest | `7f42e64` → `f475abd`
|

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/uv).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ1cGRhdGVkSW5WZXIiOiI0My4xMDIuMTEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImJ1aWxkOnNraXAtZG9ja2VyIiwiYnVpbGQ6c2tpcC1yZWxlYXNlIiwiaW50ZXJuYWwiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-04-07 07:15:45 -05:00
Ben Beasley 4695d6a05b Gate a few new tests on the test-pypi feature (#18897)
<!--
Thank you for contributing to uv! To help us out with reviewing, please
consider the following:

- Does this pull request include a summary of the change? (See below.)
- Does this pull request include a descriptive title?
- Does this pull request include references to any relevant issues?
-->

## Summary

Makes it easier to run integration tests in offline environments by
gating six new tests on the `test-pypi` feature. All of these tests fail
in offline environments when they try to make HTTPS requests to PyPI.

## Test Plan

<!-- How was it tested? -->
Applied as a patch to Fedora’s [`uv`
package](https://src.fedoraproject.org/rpms/uv); built and ran
integration tests in an offline environment.
2026-04-07 11:29:19 +00:00
Charlie Marsh 0da0cd8b43 Fix uv export extra resolution for workspace member and conflicting extras (#18888)
`uv export` was resolving extra markers too early... We now preserve raw
edge markers, track child extras activated by each edge, and resolve
both using the active path context.

Closes https://github.com/astral-sh/uv/issues/18887.
2026-04-06 16:06:58 -04:00
Charlie Marsh 8b0e9e5fb9 Include conflicts defined in virtual workspace root (#18886)
## Summary

Closes https://github.com/astral-sh/uv/issues/18879.
2026-04-06 14:09:57 -04:00
Charlie Marsh d1db4ef72f Add some additional tests for comment removals (#18874)
Related to https://github.com/astral-sh/uv/issues/9856 and
https://github.com/astral-sh/uv/issues/13966.
2026-04-06 03:02:00 +00:00
renovate[bot] 16a1a5dc5c Update Rust crate wmi to v0.18.4 (#18866) 2026-04-06 02:42:30 +00:00
renovate[bot] f57c9de87a Update Rust crate uuid to v1.23.0 (#18871) 2026-04-06 02:38:14 +00:00
renovate[bot] f0fb08c319 Update Rust crate insta to v1.47.1 (#18868) 2026-04-05 22:27:46 -04:00
renovate[bot] 80876c8d96 Update Rust to v1.94.1 (#18867) 2026-04-06 02:27:16 +00:00
renovate[bot] 75745b9d54 Update Rust crate rustc-hash to v2.1.2 (#18865) 2026-04-06 02:24:34 +00:00
renovate[bot] 08b1f4d07f Update dependency astral-sh/uv to v0.11.3 (#18864) 2026-04-05 22:23:36 -04:00
Charlie Marsh 60786a5127 Track newly-activated extras when determining conflicts (#18852)
## Summary

When evaluating a dependency like `member[cpu]`, we now treat `cpu` as
active for that dependency’s own conflict marker check.

Closes https://github.com/astral-sh/uv/issues/14645.
2026-04-05 03:34:58 +00:00
Charlie Marsh 7f7c36a3bc Sort by comparator to break specifier ties (#18850)
## Summary

We were writing `<=1.4.4,>=1.4.4` to the lockfile, and rejecting the
input dependencies (`>= 1.4.4, <= 1.4.4`).

Closes https://github.com/astral-sh/uv/issues/17639.
2026-04-04 22:37:45 -04:00
Charlie Marsh 796ceb2790 Avoid panics in environment finding via cycle detection (#18828)
## Summary

We had no cycle handling here. I guess I naively thought the PubGrub
graph... wouldn't contain cycles? Not sure why I would think that
though!

Closes https://github.com/astral-sh/uv/issues/16930.
2026-04-02 18:02:41 -04:00
Zanie Blue 657182761d Bump actions using Node 20 (#18817)
The node version is deprecated and is going to be dropped in June 2026
2026-04-02 09:09:33 -05:00
Zanie Blue 85c7e234b5 Add a comment explaining the release-gate workflow (#18816) 2026-04-02 08:16:49 -05:00
Zanie Blue 3b19c24740 Run trampoline consistency checks after utility script changes (#18814)
Otherwise changes, e.g., https://github.com/astral-sh/uv/pull/18811, may
not cause the checks to run!
2026-04-01 21:33:14 +00:00
Zanie Blue 45da18ac31 Fix deployment flag in Docker builds on release (#18812) 2026-04-01 16:16:10 -05:00
Zanie Blue 4573247603 Temporarily disable the trampoline reproducibility check (#18806) 2026-04-01 21:07:57 +00:00
Zanie Blue 464a33ca82 Bump version to 0.11.3 (#18805) 2026-04-01 15:52:54 -05:00
Rex Ledesma 08577895ae docs: add explicit example for opting package out of --exclude-newer (#18803)
<!--
Thank you for contributing to uv! To help us out with reviewing, please
consider the following:

- Does this pull request include a summary of the change? (See below.)
- Does this pull request include a descriptive title?
- Does this pull request include references to any relevant issues?
-->

## Summary

Add the explicit configuration for opting out a package out of
`--exclude-newer`. The docs mention this from
https://github.com/astral-sh/uv/pull/16854, but the actual
pyproject.toml configuration was missing. I found it from
https://github.com/astral-sh/uv/issues/12449#issuecomment-4170155721,
but this should be in the docs.

## Test Plan

uv run --only-group docs mkdocs serve -f mkdocs.yml

---------

Co-authored-by: Zanie Blue <contact@zanie.dev>
2026-04-01 20:40:20 +00:00
renovate[bot] 9191802665 Update cgr.dev/chainguard/python:latest-dev Docker digest to 7f42e64 (#18759)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| cgr.dev/chainguard/python | container | digest | `197dc1b` → `7f42e64`
|

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/uv).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My45NC4xIiwidXBkYXRlZEluVmVyIjoiNDMuMTAwLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImJ1aWxkOnNraXAtZG9ja2VyIiwiYnVpbGQ6c2tpcC1yZWxlYXNlIiwiaW50ZXJuYWwiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-04-01 15:32:05 -05:00
Volodymyr Borodaykevych 6289299517 fix: bump rustls-webpki 0.103.9 -> 0.103.10 (GHSA-pwjx-qhcg-rvj4) (#18785)
Patch Cargo.lock to upgrade rustls-webpki from 0.103.9 to 0.103.10,
addressing the security advisory GHSA-pwjx-qhcg-rvj4.

<!--
Thank you for contributing to uv! To help us out with reviewing, please
consider the following:

- Does this pull request include a summary of the change? (See below.)
- Does this pull request include a descriptive title?
- Does this pull request include references to any relevant issues?
-->

## Summary

<!-- What's the purpose of the change? What does it do, and why? -->

```
bin/uv (rustbinary)

Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 0, CRITICAL: 0)

┌───────────────┬─────────────────────┬──────────┬────────┬───────────────────┬───────────────────────────┬───────────────────────────────────────────────────────────┐
│    Library    │    Vulnerability    │ Severity │ Status │ Installed Version │       Fixed Version       │                           Title                           │
├───────────────┼─────────────────────┼──────────┼────────┼───────────────────┼───────────────────────────┼───────────────────────────────────────────────────────────┤
│ rustls-webpki │ GHSA-pwjx-qhcg-rvj4 │ MEDIUM   │ fixed  │ 0.103.9           │ 0.103.10, 0.104.0-alpha.5 │ webpki: CRLs not considered authoritative by Distribution │
│               │                     │          │        │                   │                           │ Point due to faulty matching...                           │
│               │                     │          │        │                   │                           │ https://github.com/advisories/GHSA-pwjx-qhcg-rvj4         │
└───────────────┴─────────────────────┴──────────┴────────┴───────────────────┴───────────────────────────┴───────────────────────────────────────────────────────────┘
```

## Test Plan

<!-- How was it tested? -->
2026-04-01 15:31:24 -05:00
konsti 5f6da0aaee Use Python 3.14 for CI cache check (#18796)
By updating to a newer Python version, we get a newer homeassistant
version. This change also pins the mac job to the same Python version as
the Linux job.
2026-04-01 15:29:47 -05:00
Zanie Blue 6b1ebc33dc Add a "release-gate" step to the release workflow (#18804)
The way this works is

1. `release-gate` is an environment which requires approval from another
person in the organization
2. Once approved, the release can continue
3. GitHub then requires approval for every subsequent job, which we use
the `release` environment for
4. We do not require team members to approve on the `release`
environment because we run _many_ child jobs during releases
5. The `release` environment uses a deployment protection rule which
queries a GitHub App we manage
6. The GitHub App checks if the `release-gate` job was successful in the
same workflow and approves or denies accordingly

The GitHub App's source is at
https://github.com/open-security-tools/ost-environment-gate and includes
another explanation of what's going on in this process.

We don't make the release-gate block everything, so builds can start at
least while we wait for the release-gate to be approved.
2026-04-01 15:23:37 -05:00
Martin Jansche 8fe68cf52d Support debug CPython ABI tags in environment compatibility (#18739)
## Summary

This PR fixes a problem in `uv pip install`, which currently refuses to
install debug wheels in virtual environments with debug CPythons.

Before this change, wheel parsing already preserved debug ABI suffixes
like cp313d and cp314d, but Tags::from_env only propagated free-threaded
and legacy pymalloc variants. As a result, uv would detect a debug
interpreter correctly during discovery while still generating
cp313/cp314 environment tags, causing debug-built wheels to be rejected
as incompatible.

Fix this by accepting a debug_enabled flag in Tags::from_env, mapping it
to CPythonAbiVariants::Debug, and passing the interpreter debug state
from the production call sites in uv-python and uv pip resolution.

Also update the affected tests and helpers, and add a regression test
that verifies debug CPython 3.13 generates cp313-cp313d manylinux tags.

## Test Plan

Tests run:
- cargo test -p uv-platform-tags
tags::tests::test_system_tags_debug_cpython -- --exact
- cargo test -p uv-installer
plan::tests::test_abi3_on_free_threaded_python_hint -- --exact
- cargo test -p uv-installer
plan::tests::test_gil_enabled_cpython_on_free_threaded_python_hint --
--exact
- cargo test -p uv-installer
plan::tests::test_abi3_on_regular_python_no_special_hint -- --exact
- cargo test -p uv --test it
pip_install::abi_compatibility_on_debug_python -- --exact

---------

Co-authored-by: konstin <konstin@mailbox.org>
2026-04-01 19:21:12 +02:00
Zanie Blue 8120c0a950 Remove powerpc64-unknown-linux-gnu from build targets (#18800)
Removes the `powerpc64-unknown-linux-gnu` target from the list of
supported build targets in `dist-workspace.toml`. The
`powerpc64le-unknown-linux-gnu` (little-endian) target remains in the
configuration.

Closes https://github.com/astral-sh/uv/issues/18798

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-01 11:02:43 -05:00
konsti ce65a994e5 Bump simple API cache (#18797)
#18767 adds a new variant to `AbiTag`, which is incompatible with the
current rkyv cache.

By the conjoined powers of this PR and
https://github.com/astral-sh/uv/pull/18796, the cache test should pass
again.
2026-04-01 16:34:32 +02:00
konsti 5b414b1119 Don't drop blake2b hashes (#18794)
An oversight from adding blake2b hashes.
2026-04-01 14:07:56 +02:00
konsti 5b369e6370 Handle broken range request implementations (#18780)
This updates async_http_range_reader to v0.11.0 to add the missing range
request bounds validation:
https://github.com/astral-sh/async_http_range_reader/pull/8.

An open question is how we want to behave when the server has an
incorrect range request implementation (while advertising range request
support). In the current implementation, it warns with the index URL, so
that the user is aware that the massive slowdown is caused by a server
advertising broken features.

Also removes a dependency where the corresponding repo was deleted.

Fixes https://github.com/astral-sh/uv/issues/18316
2026-04-01 10:03:31 +00:00
Zsolt Dollenstein 0c1d0f7c80 Publish installers to /installers/uv/latest on the mirror (#18725) 2026-03-31 10:51:27 -04:00
Charlie Marsh 3e6c46e377 Emit abi3t tags for every abi3 version (#18777)
## Summary

See: https://github.com/astral-sh/uv/pull/18767#discussion_r3014555045.
2026-03-31 13:11:41 +00:00
konsti b7d5faf568 Reproducible Windows trampoline builds (#18665)
Build the Windows trampolines in a fully pinned docker container that
allows auditing the compilation in CI.
2026-03-31 12:15:44 +02:00
Charlie Marsh 222f988601 Implement support for PEP 803 (#18767)
## Summary

Closes https://github.com/astral-sh/uv/issues/18750.
2026-03-30 20:17:08 -04:00
Sebastian Willing 30e3342049 docs: document false opt-out for exclude-newer-package (#18768)
## Summary

The `exclude-newer-package` setting accepts `false` to exempt a specific
package from the global `exclude-newer` constraint (via
`PackageExcludeNewer::Disabled`), but this isn't documented. This PR
adds:

- A sentence in both doc comments for `exclude_newer_package` explaining
the `false` opt-out
- An example showing `false` alongside a date value

## Motivation

This came up while adding a 3-day `exclude-newer` quarantine to a
project that also uses a private registry without PEP 700 upload-time
metadata. The `false` opt-out is exactly the right mechanism, but it
took reading the source to discover it.

The `false` value is handled by the `PackageExcludeNewer::Disabled`
variant and its custom deserializer:

https://github.com/astral-sh/uv/blob/main/crates/uv-resolver/src/exclude_newer.rs

## Test plan

- Documentation-only change (doc comments in `settings.rs`)
- Verified the generated docs render correctly by checking the existing
doc generation pipeline uses these comments

## Disclaimer

Mismatch found by @alexandrukis, patch created by Claude, reviewed by
me.

---------

Co-authored-by: Charlie Marsh <charlie.r.marsh@gmail.com>
2026-03-30 20:34:14 +00:00
William Woodruff ceb0058626 uv audit: --ignore and --ignore-until-fixed (#18737)
## Summary

This adds two new options to `uv audit` plus their corresponding config
fields: `--ignore` and `--ignore-until-fixed`. These do pretty much what
they say on the tin:

- `--ignore ID` ignores the given vulnerability by ID, unconditionally.
Any ID (including aliases) can be used, since it's common for people to
use CVE IDs even though we consider PYSEC and OSV "more" canonical.
- `--ignore-until-fixed ID` ignores the given vulnerability by ID
*until* a fix version appears.

Both options are additive, i.e. can be passed multiple times. I've also
implemented a `[tool.uv.audit]` section that these will live under on
the config side.

Please bikeshed the naming, I'm not confident on it!

See https://github.com/astral-sh/uv/issues/18506.

## Test Plan

Added unit tests for both the CLI and config pathways.

---------

Signed-off-by: William Woodruff <william@astral.sh>
2026-03-30 11:03:06 -04:00
Aiman 9ed9283e9c Add progress bar for hashing phase in uv publish (#18752)
closes #17034

## Summary

When publishing a package via `uv publish`, there is a `hashing` phase
before uploading where it appears the terminal freezes.
Added a progress bar to make it clear.

## Tests

### Hashing

<img width="710" height="67" alt="uv-hash"
src="https://github.com/user-attachments/assets/9af2b963-57d1-40ff-9750-37adebb65c15"
/>

### Uploading

<img width="715" height="128" alt="uv-hash-upload"
src="https://github.com/user-attachments/assets/7d3d0108-a301-47c7-8689-e4108e5b097c"
/>

### Debug mode

<img width="711" height="204" alt="uv-debug"
src="https://github.com/user-attachments/assets/a7797454-cd5a-4a69-9641-f60a6178d5b7"
/>

---------

Co-authored-by: konstin <konstin@mailbox.org>
2026-03-30 09:10:38 +00:00
renovate[bot] 7c2f6c696b Update astral-sh/setup-uv action to v8 (#18765)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v7.6.0` → `v8.0.0` |

---

### Release Notes

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

###
[`v8.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.0.0):
🌈 Immutable releases and secure tags

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v7.6.0...v8.0.0)

### This is the first immutable release of `setup-uv` 🥳

All future releases are also immutable, if you want to know more about
what this means checkout [the
docs](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases).

This release also has two breaking changes

#### New format for `manifest-file`

The previously deprecated way of defining a custom version manifest to
control which `uv` versions are available and where to download them
from got removed. The functionality is still there but you have to use
the [new
format](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format).

#### No more major and minor tags

To increase **security** even more we will **stop publishing minor
tags**. You won't be able to use `@v8` or `@v8.0` any longer. We do this
because pinning to major releases opens up users to supply chain attacks
like what happened to
[tj-actions](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/).

> \[!TIP]
> Use the immutable tag as a version `astral-sh/setup-uv@8.0.0`
> Or even better the githash
`astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57`

#### 🚨 Breaking changes

- Remove update-major-minor-tags workflow
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;826](https://redirect.github.com/astral-sh/setup-uv/issues/826))
- Remove deprecrated custom manifest
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;813](https://redirect.github.com/astral-sh/setup-uv/issues/813))

#### 🧰 Maintenance

- Shortcircuit latest version from manifest
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;828](https://redirect.github.com/astral-sh/setup-uv/issues/828))
- Simplify inputs.ts
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;827](https://redirect.github.com/astral-sh/setup-uv/issues/827))
- Bump release-drafter to v7.1.1
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;825](https://redirect.github.com/astral-sh/setup-uv/issues/825))
- Refactor inputs
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;823](https://redirect.github.com/astral-sh/setup-uv/issues/823))
- Replace inline compile args with tsconfig
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;824](https://redirect.github.com/astral-sh/setup-uv/issues/824))
- chore: update known checksums for 0.11.2
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;821](https://redirect.github.com/astral-sh/setup-uv/issues/821))
- chore: update known checksums for 0.11.1
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;817](https://redirect.github.com/astral-sh/setup-uv/issues/817))
- chore: update known checksums for 0.11.0
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;815](https://redirect.github.com/astral-sh/setup-uv/issues/815))
- Fix latest-version workflow check
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;812](https://redirect.github.com/astral-sh/setup-uv/issues/812))
- chore: update known checksums for 0.10.11/0.10.12
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;811](https://redirect.github.com/astral-sh/setup-uv/issues/811))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on
Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule
defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/astral-sh/uv).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My45NC4xIiwidXBkYXRlZEluVmVyIjoiNDMuOTQuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYnVpbGQ6c2tpcC1kb2NrZXIiLCJidWlsZDpza2lwLXJlbGVhc2UiLCJpbnRlcm5hbCJdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-30 09:48:20 +02:00
renovate[bot] b3bee55123 Update debian Docker tag to trixie-20260316 (#18760) 2026-03-29 21:22:37 -04:00
renovate[bot] cc2a514406 Update taiki-e/install-action action to v2.69.6 (#18764) 2026-03-29 21:22:31 -04:00
renovate[bot] 4f79352b66 Update dependency astral-sh/uv to v0.11.2 (#18763) 2026-03-29 21:22:23 -04:00