8fbc61437f
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/uv](https://redirect.github.com/astral-sh/uv) | uses-with | patch | `0.9.26` → `0.9.28` | --- ### Release Notes <details> <summary>astral-sh/uv (astral-sh/uv)</summary> ### [`v0.9.28`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0928) [Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.9.27...0.9.28) Released on 2026-01-29. ##### Python - Update CPython to use [OpenSSL 3.5.5](https://redirect.github.com/openssl/openssl/releases/tag/openssl-3.5.5) which includes fixes for high severity CVEs ([python-build-standalone#960](https://redirect.github.com/astral-sh/python-build-standalone/pull/960)) ##### Enhancements - Add support for Pyodide interpreter on Windows ([#​17658](https://redirect.github.com/astral-sh/uv/pull/17658)) - Warn if multiple indexes include `default = true` ([#​17713](https://redirect.github.com/astral-sh/uv/pull/17713)) - Skip uploads when validation reports 'Already uploaded' ([#​17412](https://redirect.github.com/astral-sh/uv/pull/17412)) ##### Configuration - Add a reflink alias for the "clone" link mode ([#​17724](https://redirect.github.com/astral-sh/uv/pull/17724)) ##### Bug fixes - Ensure `uv.exe` exits when `uvw.exe` or `uvx.exe` is killed ([#​17500](https://redirect.github.com/astral-sh/uv/pull/17500)) ### [`v0.9.27`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0927) [Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.9.26...0.9.27) Released on 2026-01-26. ##### Python - Upgrade Pyodide to 0.29.2 ([#​17652](https://redirect.github.com/astral-sh/uv/pull/17652)) - Upgrade to GraalPy 25.0.2 ([#​17634](https://redirect.github.com/astral-sh/uv/pull/17634)) ##### Enhancements - Add `-t` shortform for `--target` to `uv pip` subcommands ([#​17501](https://redirect.github.com/astral-sh/uv/pull/17501)) - Add support for ROCm 7.0 and 7.1 accelerator backends ([#​17681](https://redirect.github.com/astral-sh/uv/pull/17681)) - Further improve free-threading ABI incompatibility errors ([#​17491](https://redirect.github.com/astral-sh/uv/pull/17491)) - Implement `uv pip freeze --exclude` flag ([#​17045](https://redirect.github.com/astral-sh/uv/pull/17045)) - Improve warnings for `--system` and `--no-system` in `uv venv` ([#​17647](https://redirect.github.com/astral-sh/uv/pull/17647)) - Make `uv pip compile` attempt to download a specified `--python-version` if it can. ([#​17249](https://redirect.github.com/astral-sh/uv/pull/17249)) - Support Trusted Publishing with pyx ([#​17438](https://redirect.github.com/astral-sh/uv/pull/17438)) - Fix JSON schema for `exclude-newer-package` ([#​17665](https://redirect.github.com/astral-sh/uv/pull/17665)) ##### Preview features - Better detection for conflicting packages ([#​17623](https://redirect.github.com/astral-sh/uv/pull/17623)) - Upgrade based on outdated build versions in `uv python upgrade` ([#​17653](https://redirect.github.com/astral-sh/uv/pull/17653)) ##### Bug fixes - Change chocolatey system test to ensure uv uses the right python ([#​17533](https://redirect.github.com/astral-sh/uv/pull/17533)) - Fix infinite loop when `SSL_CERT_FILE` is a directory ([#​17503](https://redirect.github.com/astral-sh/uv/pull/17503)) ##### Documentation - Add cargo-xwin to the CONTRIBUTING guide ([#​17507](https://redirect.github.com/astral-sh/uv/pull/17507)) - Fix typo in the documentation of UV\_PUBLISH\_INDEX ([#​17672](https://redirect.github.com/astral-sh/uv/pull/17672)) - Move MSRV to platform support section ([#​17534](https://redirect.github.com/astral-sh/uv/pull/17534)) - Update the testing instructions in the CONTRIBUTING guide ([#​17528](https://redirect.github.com/astral-sh/uv/pull/17528)) - Use `--locked` to install `cargo-xwin` in guide ([#​17530](https://redirect.github.com/astral-sh/uv/pull/17530)) - Warn about PyPy being unmaintained ([#​17643](https://redirect.github.com/astral-sh/uv/pull/17643)) - docs: Correct gitlab-ci.yml to .gitlab-ci.yml ([#​17682](https://redirect.github.com/astral-sh/uv/pull/17682)) ##### Other changes - Update MSRV to 1.91 ([#​17677](https://redirect.github.com/astral-sh/uv/pull/17677)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/astral-sh/uv). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45Mi4xIiwidXBkYXRlZEluVmVyIjoiNDIuOTIuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYnVpbGQ6c2tpcC1yZWxlYXNlIiwiaW50ZXJuYWwiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
166 lines
5.5 KiB
YAML
166 lines
5.5 KiB
YAML
on:
|
|
workflow_call:
|
|
inputs:
|
|
code-changed:
|
|
required: true
|
|
type: string
|
|
save-rust-cache:
|
|
required: false
|
|
type: string
|
|
default: "true"
|
|
|
|
permissions: {}
|
|
|
|
env:
|
|
CARGO_INCREMENTAL: 0
|
|
CARGO_NET_RETRY: 10
|
|
CARGO_TERM_COLOR: always
|
|
RUSTUP_MAX_RETRIES: 10
|
|
|
|
jobs:
|
|
ruff:
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Install uv"
|
|
uses: astral-sh/setup-uv@803947b9bd8e9f986429fa0c5a41c367cd732b41 # v7.2.1
|
|
with:
|
|
version: "0.9.28"
|
|
- run: uvx ruff check .
|
|
|
|
ty:
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Install uv"
|
|
uses: astral-sh/setup-uv@803947b9bd8e9f986429fa0c5a41c367cd732b41 # v7.2.1
|
|
with:
|
|
version: "0.9.28"
|
|
- run: |
|
|
uvx ty check python/uv
|
|
uvx \
|
|
--directory crates/uv-python \
|
|
--with-requirements fetch-download-metadata.py \
|
|
ty check --python-version 3.13 fetch-download-metadata.py
|
|
|
|
shellcheck:
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Install shellcheck"
|
|
run: |
|
|
# renovate: datasource=github-releases depName=koalaman/shellcheck
|
|
SHELLCHECK_VERSION="v0.11.0"
|
|
curl -sSL "https://github.com/koalaman/shellcheck/releases/download/${SHELLCHECK_VERSION}/shellcheck-${SHELLCHECK_VERSION}.linux.x86_64.tar.xz" | tar -xJf -
|
|
sudo mv "shellcheck-${SHELLCHECK_VERSION}/shellcheck" /usr/local/bin/
|
|
- name: "Run shellcheck"
|
|
run: find . -name '*.sh' -type f | xargs shellcheck --shell bash --severity style
|
|
|
|
validate-pyproject:
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Install uv"
|
|
uses: astral-sh/setup-uv@803947b9bd8e9f986429fa0c5a41c367cd732b41 # v7.2.1
|
|
with:
|
|
version: "0.9.28"
|
|
- run: uvx --from 'validate-pyproject[all,store]' validate-pyproject pyproject.toml
|
|
|
|
readme:
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- uses: actions/setup-python@83679a892e2d95755f2dac6acb0bfd1e9ac5d548 # v6.1.0
|
|
with:
|
|
python-version: 3.12
|
|
- run: python scripts/transform_readme.py --target pypi
|
|
|
|
clippy-ubuntu:
|
|
name: "clippy on linux"
|
|
timeout-minutes: 10
|
|
if: ${{ inputs.code-changed == 'true' || github.ref == 'refs/heads/main' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2
|
|
with:
|
|
save-if: ${{ inputs.save-rust-cache == 'true' }}
|
|
- name: "Check uv_build dependencies"
|
|
uses: EmbarkStudios/cargo-deny-action@3fd3802e88374d3fe9159b834c7714ec57d6c979 # v2.0.15
|
|
with:
|
|
command: check bans
|
|
manifest-path: crates/uv-build/Cargo.toml
|
|
- name: "Install Rust toolchain"
|
|
run: rustup component add clippy
|
|
- name: "Clippy"
|
|
run: cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
|
|
|
|
clippy-windows:
|
|
name: "clippy on windows"
|
|
timeout-minutes: 15
|
|
if: ${{ inputs.code-changed == 'true' || github.ref == 'refs/heads/main' }}
|
|
runs-on: windows-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Dev Drive
|
|
run: ${{ github.workspace }}/.github/workflows/setup-dev-drive.ps1
|
|
|
|
# actions/checkout does not let us clone into anywhere outside ${{ github.workspace }}, so we have to copy the clone...
|
|
- name: Copy Git Repo to Dev Drive
|
|
run: |
|
|
Copy-Item -Path "${{ github.workspace }}" -Destination "$Env:UV_WORKSPACE" -Recurse
|
|
|
|
- uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2
|
|
with:
|
|
workspaces: ${{ env.UV_WORKSPACE }}
|
|
save-if: ${{ inputs.save-rust-cache == 'true' }}
|
|
|
|
- name: "Install Rust toolchain"
|
|
run: rustup component add clippy
|
|
|
|
- name: "Clippy"
|
|
working-directory: ${{ env.UV_WORKSPACE }}
|
|
run: cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
|
|
|
|
shear:
|
|
name: "cargo shear"
|
|
timeout-minutes: 10
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Install cargo shear"
|
|
uses: taiki-e/install-action@542cebaaed782771e619bd5609d97659d109c492 # v2.66.7
|
|
with:
|
|
tool: cargo-shear
|
|
- run: cargo shear
|
|
|
|
typos:
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
- uses: crate-ci/typos@65120634e79d8374d1aa2f27e54baa0c364fff5a # v1.42.1
|