Commit 489c847
authored
fix(deps): Update ghcr.io/astral-sh/uv Docker tag to v0.12.21 (#413)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://redirect.github.com/astral-sh/uv) | final | patch | `0.12.8` → `0.12.21` |
---
### Release Notes
<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>
### [`v0.12.21`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01221)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.20...0.12.21)
Released on 2026-09-29.
##### Python
- Update CPython to use OpenSSL 3.5.9 ([#​22076](https://redirect.github.com/astral-sh/uv/pull/22076))
##### Enhancements
- Omit empty `[manifest]` tables from lockfiles that contain only manifest subtables ([#​22070](https://redirect.github.com/astral-sh/uv/pull/22070))
##### Preview features
- Omit redundant runtime constraints from `uv.lock`, including those involving pre-releases, with the `resolution-inputs` preview feature ([#​22004](https://redirect.github.com/astral-sh/uv/pull/22004), [#​22068](https://redirect.github.com/astral-sh/uv/pull/22068))
##### Bug fixes
- Prevent `uv python pin --rm` from removing a global `.python-versions` file without `--global` ([#​21992](https://redirect.github.com/astral-sh/uv/pull/21992))
- Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases ([#​22049](https://redirect.github.com/astral-sh/uv/pull/22049))
### [`v0.12.20`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01220)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.19...0.12.20)
Released on 2026-09-28.
##### Enhancements
- Reuse lockfiles when dependency declarations are semantically equivalent ([#​21951](https://redirect.github.com/astral-sh/uv/pull/21951))
- Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs ([#​21990](https://redirect.github.com/astral-sh/uv/pull/21990))
##### Preview features
- Write normalized requirement declarations with the `lockfile-normalization` preview feature ([#​21951](https://redirect.github.com/astral-sh/uv/pull/21951))
- Honor synthetic default groups when installing or syncing from `pylock.toml` ([#​22003](https://redirect.github.com/astral-sh/uv/pull/22003))
- Resolve local paths in exported `pylock.toml` files relative to the output file ([#​22042](https://redirect.github.com/astral-sh/uv/pull/22042))
- Install each package only once when repeated `tool-install-locks` requirements resolve to the same package ([#​22000](https://redirect.github.com/astral-sh/uv/pull/22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with distinct base and extra requirement specifiers ([#​22055](https://redirect.github.com/astral-sh/uv/pull/22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv tree --format json` output ([#​22050](https://redirect.github.com/astral-sh/uv/pull/22050))
##### Configuration
- Continue searching `XDG_CONFIG_DIRS` after empty entries ([#​21987](https://redirect.github.com/astral-sh/uv/pull/21987))
##### Performance
- Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems ([#​22051](https://redirect.github.com/astral-sh/uv/pull/22051))
##### Bug fixes
- Apply hash constraints to every repeated requirement under `--require-hashes` and `--verify-hashes` ([#​21996](https://redirect.github.com/astral-sh/uv/pull/21996))
- Allow metadata builds for first-party workspace projects under `--no-build` ([#​21988](https://redirect.github.com/astral-sh/uv/pull/21988))
- Honor project exclusion flags with `--all-packages`, including `--no-install-project` and `--no-emit-project` ([#​21994](https://redirect.github.com/astral-sh/uv/pull/21994))
- Restore `pyproject.toml` if `uv upgrade` fails or is interrupted ([#​21983](https://redirect.github.com/astral-sh/uv/pull/21983))
- Generate working Nushell activation scripts for relocatable virtual environments ([#​21979](https://redirect.github.com/astral-sh/uv/pull/21979))
- Prevent commands from running and changing state after displaying `--show-settings` ([#​21989](https://redirect.github.com/astral-sh/uv/pull/21989))
- Treat UTF-16 requirements files containing only a byte-order mark as empty ([#​21991](https://redirect.github.com/astral-sh/uv/pull/21991))
- Ignore unrecognized managed-Python implementation directories during `uv python list` and `uv python upgrade` instead of panicking ([#​22033](https://redirect.github.com/astral-sh/uv/pull/22033))
- Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with `/install` ([#​22036](https://redirect.github.com/astral-sh/uv/pull/22036))
- Report whitespace-only non-ASCII requirements as invalid instead of panicking ([#​22035](https://redirect.github.com/astral-sh/uv/pull/22035))
- Avoid a resolver panic when trace logging an always-false constraint ([#​22034](https://redirect.github.com/astral-sh/uv/pull/22034))
### [`v0.12.19`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01219)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.18...0.12.19)
Released on 2026-09-24.
##### Python
- Add PyPy 3.11.16 and 3.12.14 ([#​21847](https://redirect.github.com/astral-sh/uv/pull/21847))
- Update GraalPy 3.13.0 to build 25.4.4 ([#​21847](https://redirect.github.com/astral-sh/uv/pull/21847))
##### Enhancements
- Format upload URLs with backticks in `uv publish` errors ([#​21934](https://redirect.github.com/astral-sh/uv/pull/21934))
##### Preview features
- Run build-backend hooks with lazy imports on CPython 3.15 and later using the `build-lazy-imports` preview feature ([#​21967](https://redirect.github.com/astral-sh/uv/pull/21967))
- Omit unused resolution settings from `uv.lock` and ignore changes to them when checking lockfile freshness with the `resolution-inputs` preview feature ([#​21913](https://redirect.github.com/astral-sh/uv/pull/21913))
##### Bug fixes
- Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages ([#​21971](https://redirect.github.com/astral-sh/uv/pull/21971))
- Recognize `1.0.0` as satisfying `===1` during installed-package checks, matching resolution ([#​21931](https://redirect.github.com/astral-sh/uv/pull/21931))
- Avoid collisions between Git checkout readiness markers and `.ok` files in dependencies ([#​21891](https://redirect.github.com/astral-sh/uv/pull/21891))
- Preserve always-false `python_version` markers when parsing their serialized form ([#​21939](https://redirect.github.com/astral-sh/uv/pull/21939))
##### Rust API
- Restore the public `FlatDistributions` export and its `BTreeMap` conversion for downstream resolvers ([#​21965](https://redirect.github.com/astral-sh/uv/pull/21965))
##### Documentation
- Make individual preview-feature reference entries linkable by name ([#​21950](https://redirect.github.com/astral-sh/uv/pull/21950))
### [`v0.12.18`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01218)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.17...0.12.18)
Released on 2026-09-22.
This release addresses [GHSA-2cv4-cqwr-gwf7](https://redirect.github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7), which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.
##### Enhancements
- Add `--output-format json` to `uv pip install` and `uv pip sync`, including for `--dry-run` and `--check` ([#​21893](https://redirect.github.com/astral-sh/uv/pull/21893))
- Add `--check` to `uv pip install` and `uv pip sync` to report planned changes without modifying the environment ([#​21844](https://redirect.github.com/astral-sh/uv/pull/21844))
- Identify failures from `get_requires_for_build_*` hooks correctly in build errors ([#​21881](https://redirect.github.com/astral-sh/uv/pull/21881))
##### Preview features
- Validate build requirements for `uv build --no-build-isolation` with `--preview-features build-dependency-check`; use `--skip-dependency-check` to opt out ([#​21880](https://redirect.github.com/astral-sh/uv/pull/21880))
##### Performance
- Speed up `uv_build` editable wheel creation by omitting compression from temporary wheels ([#​21918](https://redirect.github.com/astral-sh/uv/pull/21918))
##### Bug fixes
- Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags ([#​21835](https://redirect.github.com/astral-sh/uv/pull/21835), [#​21836](https://redirect.github.com/astral-sh/uv/pull/21836))
- Restore project, script, and lock files when `uv add`, `uv remove`, or `uv version` fails or is interrupted ([#​21860](https://redirect.github.com/astral-sh/uv/pull/21860), [#​21856](https://redirect.github.com/astral-sh/uv/pull/21856))
- Use configured `dependency-metadata` when checking whether installed requirements are satisfied ([#​21843](https://redirect.github.com/astral-sh/uv/pull/21843))
- Reject archive entries that normalize to absolute Windows paths ([#​21923](https://redirect.github.com/astral-sh/uv/pull/21923))
- Recognize distribution filenames and archive extensions when URL fragments contain `?` ([#​21920](https://redirect.github.com/astral-sh/uv/pull/21920))
- Generate correctly lowercased platform tags for BSD and Haiku releases ([#​21853](https://redirect.github.com/astral-sh/uv/pull/21853))
- Avoid rebuilding a Windows relative path into an absolute form ([#​21923](https://redirect.github.com/astral-sh/uv/pull/21923))
### [`v0.12.17`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01217)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.16...0.12.17)
Released on 2026-09-18.
##### Enhancements
- Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports ([#​21780](https://redirect.github.com/astral-sh/uv/pull/21780))
##### Preview features
- Set minimum glibc and musl versions that universal resolutions must support with `minimum-libc-version` ([#​21651](https://redirect.github.com/astral-sh/uv/pull/21651))
- Reject `pylock.toml` files whose wheel filenames do not match their declared package names or versions ([#​20746](https://redirect.github.com/astral-sh/uv/pull/20746))
- Keep `uv workspace metadata` read-only unless `--sync` is provided ([#​21821](https://redirect.github.com/astral-sh/uv/pull/21821))
- Apply `uv check` lock modes when retrieving workspace metadata ([#​21821](https://redirect.github.com/astral-sh/uv/pull/21821))
##### Performance
- Speed up builds with many exclusion patterns by avoiding quadratic deduplication ([#​21650](https://redirect.github.com/astral-sh/uv/pull/21650))
- Reduce resolver allocations when deduplicating package and distribution requests ([#​21810](https://redirect.github.com/astral-sh/uv/pull/21810))
##### Bug fixes
- Prevent `required-environments` from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline ([#​21825](https://redirect.github.com/astral-sh/uv/pull/21825))
##### Documentation
- Clarify the 0.12.14 and 0.12.15 release notes ([#​21817](https://redirect.github.com/astral-sh/uv/pull/21817))
### [`v0.12.16`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01216)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.15...0.12.16)
Released on 2026-09-17.
##### Python
- Add Pyodide 314.0.7, 0.29.5, and 0.27.8 ([#​21741](https://redirect.github.com/astral-sh/uv/pull/21741))
##### Enhancements
- Verify downloaded wheels and source distributions against hashes supplied by package indexes ([#​21562](https://redirect.github.com/astral-sh/uv/pull/21562))
- Allow `build-constraint-dependencies` entries to include hashes for verifying downloaded build dependencies ([#​21467](https://redirect.github.com/astral-sh/uv/pull/21467))
- Honor Darwin `platform_release` markers in `required-environments` using macOS wheel deployment targets ([#​21766](https://redirect.github.com/astral-sh/uv/pull/21766))
- Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports ([#​21779](https://redirect.github.com/astral-sh/uv/pull/21779))
##### Preview features
- Support `lock-without-metadata` across all dependency types while retaining `package.metadata` for remote URL dependencies to enable offline validation ([#​21163](https://redirect.github.com/astral-sh/uv/pull/21163))
- Honor configured and command-line index settings, including credentials, in `uv upgrade` ([#​21776](https://redirect.github.com/astral-sh/uv/pull/21776))
- Allow `uv check` to run in projects that are not managed by uv and outside workspaces ([#​21777](https://redirect.github.com/astral-sh/uv/pull/21777))
- Respect `--python` and `UV_PYTHON` when selecting the Python version for `uv check` ([#​21744](https://redirect.github.com/astral-sh/uv/pull/21744))
##### Bug fixes
- Redact Azure shared access signatures from displayed and logged URLs ([#​21755](https://redirect.github.com/astral-sh/uv/pull/21755))
- Check archive sizes from `pylock.toml` before reusing cached distributions ([#​21609](https://redirect.github.com/astral-sh/uv/pull/21609))
- Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths ([#​20631](https://redirect.github.com/astral-sh/uv/pull/20631))
- Use the bundled `uv_build` backend only when its version matches active version pins ([#​21742](https://redirect.github.com/astral-sh/uv/pull/21742))
- Handle malformed index URLs without panicking when credentials are configured ([#​21784](https://redirect.github.com/astral-sh/uv/pull/21784))
- Report a configuration error instead of panicking for proxy URLs without a host ([#​21781](https://redirect.github.com/astral-sh/uv/pull/21781))
- Return a credential-redacted error instead of panicking when a URL cannot be converted to a path ([#​21783](https://redirect.github.com/astral-sh/uv/pull/21783))
### [`v0.12.15`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01215)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.14...0.12.15)
Released on 2026-09-15.
##### Performance
- Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes ([#​21675](https://redirect.github.com/astral-sh/uv/pull/21675))
##### Bug fixes
- Fix regressions in `0.12.14` when installing to symlinked destinations or using `uv pip install --target .` ([#​21699](https://redirect.github.com/astral-sh/uv/pull/21699))
### [`v0.12.14`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01214)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.13...0.12.14)
Released on 2026-09-15.
##### Enhancements
- Resume interrupted downloads with HTTP Range requests when supported ([#​21570](https://redirect.github.com/astral-sh/uv/pull/21570))
- Use a consistent format for error rendering ([#​17110](https://redirect.github.com/astral-sh/uv/pull/17110))
- Render error and warning causes with compact `cause:` labels ([#​21599](https://redirect.github.com/astral-sh/uv/pull/21599), [#​21603](https://redirect.github.com/astral-sh/uv/pull/21603))
- Show underlying causes and hints in user warnings ([#​21565](https://redirect.github.com/astral-sh/uv/pull/21565))
- Show resolver hints for failed `uv tool upgrade` operations ([#​21566](https://redirect.github.com/astral-sh/uv/pull/21566))
##### Preview features
- Export multiple dependency selections from a shared lockfile in one `uv export --batch` invocation with the `batch-export` preview feature ([#​21618](https://redirect.github.com/astral-sh/uv/pull/21618))
##### Performance
- Speed up dependency resolution from local wheelhouses by reading wheel metadata in a single blocking task ([#​21619](https://redirect.github.com/astral-sh/uv/pull/21619))
- Speed up cold resolution against large package indexes by parsing Simple API responses in bounded background workers ([#​21593](https://redirect.github.com/astral-sh/uv/pull/21593))
- Speed up warm-cache resolution by decoding fresh HTTP cache entries in the cache-read task ([#​21621](https://redirect.github.com/astral-sh/uv/pull/21621))
##### Bug fixes
- Select releases that satisfy `required-environments` within each resolver fork instead of combining incompatible wheel coverage across forks ([#​21672](https://redirect.github.com/astral-sh/uv/pull/21672))
- Install packages with paths longer than `MAX_PATH` on Windows systems without long-path support enabled ([#​21625](https://redirect.github.com/astral-sh/uv/pull/21625))
- Prevent `uv python install` from overwriting valid unmanaged Python symlinks with relative targets on Unix ([#​21639](https://redirect.github.com/astral-sh/uv/pull/21639))
- Redact credentials and signatures from missing-path-segment URL errors ([#​21616](https://redirect.github.com/astral-sh/uv/pull/21616))
- Avoid exceeding the configured retry budget when cached HTTP responses fail revalidation ([#​21640](https://redirect.github.com/astral-sh/uv/pull/21640))
- Prefer `bin/python` over `bin/python3` when discovering interpreters in Unix environments ([#​21559](https://redirect.github.com/astral-sh/uv/pull/21559))
- Classify package-operation exit codes by their underlying cause: return `1` for expected failures and `2` for recognized operational and internal failures ([#​17110](https://redirect.github.com/astral-sh/uv/pull/17110))
- Suppress managed-Python fallback warnings under `--quiet` ([#​21565](https://redirect.github.com/astral-sh/uv/pull/21565))
- Keep failed `uv tool upgrade` errors visible with `-q` while suppressing them with `-qq` ([#​21566](https://redirect.github.com/astral-sh/uv/pull/21566))
### [`v0.12.13`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01213)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.12...0.12.13)
Released on 2026-09-10.
##### Python
- Add GraalPy 3.13.0 ([#​21431](https://redirect.github.com/astral-sh/uv/pull/21431))
##### Enhancements
- Verify hashes when downloading PEP 658 metadata sidecars ([#​21563](https://redirect.github.com/astral-sh/uv/pull/21563))
##### Preview features
- Respect `ty` exclusions when `uv check` automatically selects members of a virtual workspace ([#​21555](https://redirect.github.com/astral-sh/uv/pull/21555))
##### Performance
- Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately ([#​21279](https://redirect.github.com/astral-sh/uv/pull/21279))
##### Bug fixes
- Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention ([#​18713](https://redirect.github.com/astral-sh/uv/pull/18713))
- Prefer `core-metadata` over legacy aliases in JSON index responses ([#​21563](https://redirect.github.com/astral-sh/uv/pull/21563))
### [`v0.12.12`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01212)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.11...0.12.12)
Released on 2026-09-09.
The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.
##### Bug fixes
- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#​21539](https://redirect.github.com/astral-sh/uv/pull/21539))
### [`v0.12.11`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01211)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.10...0.12.11)
Released on 2026-09-08.
##### Preview features
- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#​20146](https://redirect.github.com/astral-sh/uv/pull/20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#​21462](https://redirect.github.com/astral-sh/uv/pull/21462))
##### Performance
- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#​21478](https://redirect.github.com/astral-sh/uv/pull/21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#​21468](https://redirect.github.com/astral-sh/uv/pull/21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#​21500](https://redirect.github.com/astral-sh/uv/pull/21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#​21499](https://redirect.github.com/astral-sh/uv/pull/21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#​21523](https://redirect.github.com/astral-sh/uv/pull/21523))
##### Bug fixes
- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#​21223](https://redirect.github.com/astral-sh/uv/pull/21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#​21543](https://redirect.github.com/astral-sh/uv/pull/21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#​21544](https://redirect.github.com/astral-sh/uv/pull/21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#​19159](https://redirect.github.com/astral-sh/uv/pull/19159))
- Trim surrounding whitespace from entries in `.python-version` and `.python-versions` files ([#​21529](https://redirect.github.com/astral-sh/uv/pull/21529))
- Suppress `VIRTUAL_ENV` mismatch warnings for `uv add --no-sync`, `uv remove --no-sync`, and `uv add --frozen` ([#​21496](https://redirect.github.com/astral-sh/uv/pull/21496))
- Warn and continue when `uv python list` cannot query an interpreter ([#​21498](https://redirect.github.com/astral-sh/uv/pull/21498))
##### Documentation
- Restore TOML syntax highlighting for `exclude-newer` examples ([#​21534](https://redirect.github.com/astral-sh/uv/pull/21534))
### [`v0.12.10`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01210)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.9...0.12.10)
Released on 2026-09-04.
##### Enhancements
- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#​21423](https://redirect.github.com/astral-sh/uv/pull/21423))
##### Preview features
- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#​21455](https://redirect.github.com/astral-sh/uv/pull/21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#​21404](https://redirect.github.com/astral-sh/uv/pull/21404))
##### Performance
- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#​21399](https://redirect.github.com/astral-sh/uv/pull/21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#​21389](https://redirect.github.com/astral-sh/uv/pull/21389))
##### Bug fixes
- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#​21454](https://redirect.github.com/astral-sh/uv/pull/21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#​19571](https://redirect.github.com/astral-sh/uv/pull/19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#​21450](https://redirect.github.com/astral-sh/uv/pull/21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#​21395](https://redirect.github.com/astral-sh/uv/pull/21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#​21453](https://redirect.github.com/astral-sh/uv/pull/21453))
### [`v0.12.9`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0129)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.12.8...0.12.9)
Released on 2026-09-01.
##### Python
- Add CPython 3.15.0rc2 ([#​21413](https://redirect.github.com/astral-sh/uv/pull/21413), [#​21415](https://redirect.github.com/astral-sh/uv/pull/21415))
##### Enhancements
- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#​21408](https://redirect.github.com/astral-sh/uv/pull/21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#​21402](https://redirect.github.com/astral-sh/uv/pull/21402))
##### Performance
- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#​21372](https://redirect.github.com/astral-sh/uv/pull/21372))
##### Bug fixes
- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#​21401](https://redirect.github.com/astral-sh/uv/pull/21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#​21382](https://redirect.github.com/astral-sh/uv/pull/21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#​21381](https://redirect.github.com/astral-sh/uv/pull/21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#​21396](https://redirect.github.com/astral-sh/uv/pull/21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#​21400](https://redirect.github.com/astral-sh/uv/pull/21400))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, on day 1 of the month (`* 0-3 1 * *`)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhdXRvbWVyZ2UiXX0=-->1 parent 1aa9aa4 commit 489c847
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
0 commit comments