Skip to content

chore(deps): update dependency uv to v0.12.24 - #447

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/dev-dependencies
Oct 8, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/dev-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
uv tools patch 0.12.23 → 0.12.24

Release Notes

astral-sh/uv (uv)

v0.12.24

Compare Source

Released on 2026-10-08.

Enhancements
  • Remove orphaned temporary build environments with uv cache prune (#​22171)
  • Accept PEP 508 marker operators directly before grouped expressions (#​22309)
  • Reject malformed requirements-file options instead of partially parsing or ignoring them (#​22317)
  • Show underlying filesystem and registry errors when managed Python uninstallation fails (#​22362)
  • Identify the invalid source URL in Python mirror errors (#​22364)
Preview features
  • Display preferred advisory IDs in uv audit reports, prioritizing PYSEC, GHSA, then CVE identifiers (#​22292)
Configuration
  • Support custom installation mirrors for GraalPy (#​22269)
  • Support custom installation mirrors for Pyodide (#​22271)
  • Allow UV_NO_CACHE=false to override no-cache = true in configuration (#​22324)
  • Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#​22144)
Performance
  • Speed up later commands after creating an environment by warming its interpreter cache (#​21304)
  • Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#​22246)
  • Enforce resource limits when parsing package indexes and --find-links pages with astral-html (#​22203)
  • Reduce standalone uv-build executable size by 7.5% by omitting unused Zstandard support (#​22242)
  • Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#​22144)
  • Reduce Python download error formatting code size by sharing its formatter (#​22141)
Bug fixes
  • Verify supplied hashes even when hash presence is disabled with --no-require-hashes or require-hashes = false (#​22369)
  • Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#​22360)
  • Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#​22237)
  • Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#​22234)
  • Give explicit uv publish --trusted-publishing values precedence over configuration (#​22279)
  • Allow UV_OFFLINE=false to override offline = true in configuration (#​22283)
  • Allow UV_SYSTEM_CERTS=false to override system-certs = true in configuration (#​22291)
  • Allow uv auth login over IPv6 loopback addresses (#​22306)
  • Resolve GitHub dependencies whose Git references contain # or % characters (#​22281)
  • Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#​22322)
  • Preserve JSON output from uv version and uv self version with a single --quiet flag (#​22280)
  • Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#​22284)
  • Restore wheel incompatibility hints when WHEEL metadata contains multiple expanded Tag: rows (#​22235)
  • Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#​22302)
  • Prevent workspace-cache assertion failures after modifying a project at the workspace root (#​22236)
  • Hide the ignored --keyring-provider option from uv auth help (#​19520)
  • Report HTTP client setup failures directly when resolving unnamed uv tool requirements (#​22320)
Documentation
  • Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests (#​22172)
  • Fix stale links and descriptions in Rust crate documentation (#​22311, #​22361)
  • Fix a typo in the required-environments documentation (#​22238)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 8, 2026 22:03
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 2616306b-0fe1-4ef9-a533-d96c3a896f5a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot merged commit b23b98f into main Oct 8, 2026
27 checks passed
@renovate
renovate Bot deleted the renovate/dev-dependencies branch October 8, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants