-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.8.22 #72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
develop
Choose a base branch
from
renovate/ghcr.io-astral-sh-uv-0.x
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
6c0c2a2
to
3445f98
Compare
3445f98
to
0206403
Compare
0206403
to
7a3853f
Compare
7a3853f
to
f0b4e52
Compare
f0b4e52
to
72595e1
Compare
72595e1
to
aa7e8c8
Compare
aa7e8c8
to
a6a73ba
Compare
a6a73ba
to
dd70aaa
Compare
dd70aaa
to
0e4896b
Compare
0e4896b
to
cbb58ef
Compare
cbb58ef
to
a423f9f
Compare
a423f9f
to
1a3781c
Compare
1a3781c
to
576968d
Compare
576968d
to
ae22cec
Compare
ae22cec
to
7351d57
Compare
7351d57
to
0e9a906
Compare
0e9a906
to
61d863c
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Note
Mend has cancelled the proposed renaming of the Renovate GitHub app being renamed to
mend[bot]
.This notice will be removed on 2025-10-07.
This PR contains the following updates:
0.8.2
->0.8.22
Release Notes
astral-sh/uv (ghcr.io/astral-sh/uv)
v0.8.22
Compare Source
Released on 2025-09-23.
Python
Security
astral-tokio-tar
to 0.5.5 which hardens tar archive extraction (#16004)v0.8.21
Compare Source
Released on 2025-09-23.
Enhancements
--refresh
is provided (#15994)Preview features
Add support for S3 request signing (#15925)
v0.8.20
Compare Source
Released on 2025-09-22.
Enhancements
--force
flag foruv cache clean
(#15992)Preview features
Bug fixes
freethreaded+debug
Python downloads inuv python list
(#15985)uv run
anduvx
(#15990)Documentation
package
level conflicts to the conflicting dependencies docs (#15963)v0.8.19
Compare Source
Released on 2025-09-19.
Python
See the python-build-standalone release notes for more details.
Bug fixes
uv cache clean
parallel process safe (#15888)platform_machine
marker forwin_arm64
platform tag (#15921)v0.8.18
Compare Source
Released on 2025-09-17.
Enhancements
uv init
defaults for native build backend cache keys (#15705)pyproject.toml
target does not exist for dependency groups (#15831)--no-clear
touv venv
to disable removal prompts (#15795)--only-group
and--extra
flags (#15788)[project]
to be missing from apyproject.toml
(#14113)base
androot
as base environments (#15682)uv_build
is skipped (#15898)_CONDA_ROOT
to detect Conda base environments (#15680)uv publish
upload form (#15794)uv sync
(#15881)Deprecations
tool.uv.dev-dependencies
(#15469)Preview features
native-auth
feature (#15872)Bug fixes
uv sync --no-sources
not switching from editable to registry installations (#15234)@latest
(#15827)triton
as a torch backend package (#15910)UV_INSECURE_NO_ZIP_VALIDATION=1
in duplicate header errors (#15912)Documentation
NO_PROXY
support (#15816)requires-python
(#14282)v0.8.17
Compare Source
Released on 2025-09-10.
Enhancements
PYX_API_URL
when suggestinguv auth login
on 401 (#15774)Bug fixes
uv init --script
(#15747)v0.8.16
Compare Source
Enhancements
--editable
to overrideeditable = false
annotations (#15712)editable = false
for workspace sources (#15708)--with-requirements
and--requirements
(#12763)Preview features
--no-project
inuv format
(#15572)uv format
in unmanaged projects (#15553)Bug fixes
match-runtime
target is optional (#15671)uv auth
(#15743)uv publish
(#15759)Documentation
uv auth
commands take a URL (#15664)v0.8.15
Compare Source
Python
Enhancements
uv auth
commands for credential management (#15570)uv auth
commands (#15636)uv tree --show-sizes
to show package sizes (#15531)--python-platform riscv64-unknown-linux
(#15630)--python-platform
touv run
anduv tool
(#15515)uv publish --dry-run
(#15638)Bug fixes
extra-build-dependencies
(#15622)Error messages
v0.8.14
Compare Source
Python
Enhancements
--python-platform
touv pip check
(#15486)UV_ISOLATED
(#15428)--no-install-local
option touv sync
,uv add
anduv export
(#15328)uv pip
CLI (#15453)Preview features
{version}
onuv format
failure (#15527)uv format
to prevent races (#15551)--project
inuv format
(#15438)uv format
in the project root (#15440)Configuration
Performance
WHEEL
andMETADATA
reads in installed distributions (#15489)Bug fixes
venv
in current working directory (#15537)uv publish
checks (#15545)uv venv
(#15538)CLICOLOR_FORCE=1
when calling build backends (#15472)Documentation
uvw.exe
needs to be removed (#15536)v0.8.13
Compare Source
Enhancements
--no-install-*
arguments touv add
(#15375)uv init
(#15377)Preview features
uv format
command (#15017)extra-build-dependencies
if match-runtime is explicitlyfalse
(#15420)Bug fixes
triton
totorch-backend
manifest (#15405)uv_build
wheel hashes (#15400)--upgrade-package
on the command-line as overridingupgrade = false
in configuration (#15395)v0.8.12
Compare Source
Python
See the python-build-standalone release notes for details.
Enhancements
aarch64-pc-windows-msvc
target forpython-platform
(#15347)uv tool update-shell
(#15356)buildpack-deps:trixie
,debian:trixie-slim
,alpine:3.22
(#15351)Bug fixes
match-runtime = true
for dynamic packages (#15292)Documentation
uv cache clean
instead ofclear
(#15313)v0.8.11
Compare Source
Python
Enhancements
extra-build-dependencies
hint for any missing module on build failure (#15252)Bug fixes
Rust API
reqwest
clients toRegistryClient
(#15281)v0.8.10
Compare Source
Python
Enhancements
aarch64
(#14399)Preview
v0.8.9
Compare Source
Enhancements
--reinstall
flag touv python upgrade
(#15194)Bug fixes
uv python upgrade
if they don't already exist (#15192)Documentation
v0.8.8
Compare Source
Bug fixes
find_uv_bin
compatibility with Python <3.10 (#15177)v0.8.7
Compare Source
Python
tkagg
backend (the default on Linux), Pillow'sPIL.ImageTk
library, and other extension modules that need to use libtcl/libtk directly.See the
python-build-standalone
release notes for details.Enhancements
uv.lock
when using--isolated
(#15154)--prefix
and--with
installations infind_uv_bin
(#14184)find_uv_bin
(#14181)find_uv_bin
(#14182)Preview features
package
-level conflicts in workspaces (#14906)Configuration
UV_DEV
andUV_NO_DEV
environment variables (for--dev
and--no-dev
) (#15010)Bug fixes
--require-hashes
applied to build dependencies inuv pip install
(#15153)find_uv_bin
(#14191)Documentation
.
) to list elements inFeatures
docs page (#15138)v0.8.6
Compare Source
This release contains hardening measures to address differentials in behavior between uv and Python's built-in ZIP parser (CVE-2025-54368).
Prior to this release, attackers could construct ZIP files that would be extracted differently by pip, uv, and other tools. As a result, ZIPs could be constructed that would be considered harmless by (e.g.) scanners, but contain a malicious payload when extracted by uv. As of v0.8.6, uv now applies additional checks to reject such ZIPs.
Thanks to a triage effort with the Python Security Response Team and PyPI maintainers, we were able to determine that these differentials were not exploited via PyPI during the time they were present. The PyPI team has also implemented similar checks and now guards against these parsing differentials on upload.
Although the practical risk of exploitation is low, we take the hypothetical risk of parser differentials very seriously. Out of an abundance of caution, we have assigned this advisory a CVE identifier and have given it a "moderate" severity suggestion.
These changes have been validated against the top 15,000 PyPI packages; however, it's plausible that a non-malicious ZIP could be falsely rejected with this additional hardening. As an escape hatch, users who do encounter breaking changes can enable
UV_INSECURE_NO_ZIP_VALIDATION
to restore the previous behavior. If you encounter such a rejection, please file an issue in uv and to the upstream package.For additional information, please refer to the following blog posts:
Security
Python
Configuration
Bug fixes
UV_HTTP_RETRIES
inuv publish
(#15106)UV_NO_EDITABLE
where--no-editable
is supported (#15107)cargo-dist
to addUV_INSTALLER_URL
to PowerShell installer (#15114)h2
again to avoidtoo_many_internal_resets
errors (#15111)pythonw
when copying entry points in uv run (#15134)Documentation
v0.8.5
Compare Source
Enhancements
uv run
with a GitHub Gist (#15058)uv tool install
(#14014)Preview features
extra-build-dependencies
warnings foruv pip
(#15088)pylock
warning (#15089)Bug fixes
python-preference = system
when managed interpreters are on the PATH (#15059)--system
is used (#15061)h2
upgrade (#15079)Documentation
v0.8.4
Compare Source
Enhancements
Preview features
extra-build-dependencies
(#14735)Configuration
exclude-newer
dates viaexclude-newer-package
(#14489)Bug fixes
python
vspython3
(#14970)environments
andrequired-environments
inuv.toml
(#14905)Documentation
uv_build
in projects documentation (#14968)UV_
prefix to installer environment variables (#14964)uv
from--build-backend
options (#14939)v0.8.3
Compare Source
Python
See the
python-build-standalone
release notes for more details.Enhancements
uv_build
(#14867)Bug fixes
--with
versions over base environment versions (#14863)Documentation
uv_build
reference documentation (#14853)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.