Skip to content

chore(deps): update dependency astral-sh/uv to v0.13.0 - #505

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/uv
Oct 10, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/uv

Conversation

@renovate

@renovate renovate Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
astral-sh/uv uses-with minor 0.12.23 → 0.13.0

Release Notes

astral-sh/uv (astral-sh/uv)

v0.13.0

Compare Source

Released on 2026-10-09.

uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.

We expect most users to be able to upgrade without making changes.

While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. uv may download or rebuild dependencies after upgrading, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.

There are no breaking changes to the configuration of the uv build backend. If your [build-system] table includes an upper bound on uv_build, update it to allow uv_build 0.13, e.g., uv_build>=0.13.0,<0.14.

Breaking changes
  • Use Python 3.15 as the default stable version

    The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running uv python install.

    uv continues to use compatible Python installations that are already present. For example, uv venv can still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such as uv venv and uvx python can now download Python 3.15.

    You can opt out of this behavior by requesting Python 3.14 explicitly, e.g., uv venv --python 3.14. For projects, use uv python pin 3.14 to record the version in .python-version.

  • Honor --require-hashes in included constraints files (#​22275)

    Previously, uv ignored --require-hashes in constraints files included with -c from a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.

    You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the --require-hashes directive from the included constraints file if hash checking is not intended.

  • Prefer native Python on Windows ARM64 (#​22100)

    Previously, ARM64 builds of uv preferred emulated x86_64 Python installations because native wheel support was limited. Now, uv prefers native ARM64 (aarch64) interpreters across Python versions.

    This follows similar changes in CPython, the official Windows Python install manager, and GitHub's actions/setup-python.

    When a native interpreter is unavailable, uv continues to fall back to x86_64, then 32-bit x86.

    You can opt out of this behavior by setting UV_PYTHON_ARCH=x86_64 or requesting an explicit architecture, e.g., cpython-3.14-windows-x86_64. If you are using setup-uv, you can set python-arch: x86_64 instead.

  • Reject editable requirements in included constraints files (#​22282)

    Previously, uv silently ignored editable (-e) requirements in constraints files included with -c from a requirements file. Now, uv rejects these requirements with an error, matching pip's behavior.

    You cannot opt out of this behavior. Move editable requirements to a requirements file passed with -r, or pass them directly with --editable, instead of including them in a constraints file.

  • Omit the distutils startup patch on Python 3.10 and later (#​22096)

    Previously, uv installed _virtualenv.py and _virtualenv.pth into every new virtual environment to prevent distutils configuration from changing installation paths. Now, like virtualenv 21.6.0, uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.

    You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.

    This stabilizes the no-distutils-patch preview feature.

  • Treat requirement-file option values as single paths (#​22290)

    Previously, uv split values passed to --constraint, --override, --exclude, and --build-constraint on spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.

    You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace -c "a.txt b.txt" with -c a.txt -c b.txt.

    Space-separated lists in UV_CONSTRAINT, UV_OVERRIDE, UV_EXCLUDE, and UV_BUILD_CONSTRAINT remain supported.

  • Use tar-codec for tar archives by default (#​22094)

    Previously, uv used astral-tokio-tar to extract tar archives, build source distributions with uv_build, and read their metadata for uv publish. Now, uv uses tar-codec, which applies stricter validation when reading archives.

    uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by uv_build can also have different archive bytes and hashes.

    You can opt out of this behavior by setting UV_LEGACY_TAR_BACKEND=1.

    This stabilizes the tar-codec preview feature.

  • Reject uv build --clear output directories that contain a build source
    (#​22276)

    Previously, uv build --clear could delete a project or input source distribution when the
    output directory contained the source. Now, uv rejects these output directories, including
    equivalent paths reached through symlinks, before clearing any build output.

    Select an output directory that does not contain any build sources, or omit --clear.

Python
Preview features
  • Require hashes for build dependencies, including transitive dependencies, with --require-build-hashes (#​21411)
Performance
  • Speed up revalidation of cached HTTP responses by avoiding rewrites of unchanged payloads (#​22130)
  • Reduce allocations when reading cached HTTP responses (#​22136)
  • Reduce cache storage for HTTP policies and package records (#​22135, #​22133)
  • Reduce allocations for cached source distribution revisions (#​22131)
Bug fixes
  • Fix incorrect dependency resolution when reusing source metadata with different build settings (#​22404)
  • Avoid overlong wheel cache lock filenames on Windows (#​22134)

v0.12.24

Compare Source

Release Notes

Released on 2026-10-08.

Enhancements
  • Remove orphaned temporary build environments with uv cache prune (#​22171)
  • Accept PEP 508 marker operators directly before grouped expressions (#​22309)
  • Reject malformed requirements-file options instead of partially parsing or ignoring them (#​22317)
  • Show underlying filesystem and registry errors when managed Python uninstallation fails (#​22362)
  • Identify the invalid source URL in Python mirror errors (#​22364)
Preview features
  • Display preferred advisory IDs in uv audit reports, prioritizing PYSEC, GHSA, then CVE identifiers (#​22292)
Configuration
  • Support custom installation mirrors for GraalPy (#​22269)
  • Support custom installation mirrors for Pyodide (#​22271)
  • Allow UV_NO_CACHE=false to override no-cache = true in configuration (#​22324)
  • Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#​22144)
Performance
  • Speed up later commands after creating an environment by warming its interpreter cache (#​21304)
  • Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#​22246)
  • Enforce resource limits when parsing package indexes and --find-links pages with astral-html (#​22203)
  • Reduce standalone uv-build executable size by 7.5% by omitting unused Zstandard support (#​22242)
  • Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#​22144)
  • Reduce Python download error formatting code size by sharing its formatter (#​22141)
Bug fixes
  • Verify supplied hashes even when hash presence is disabled with --no-require-hashes or require-hashes = false (#​22369)
  • Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#​22360)
  • Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#​22237)
  • Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#​22234)
  • Give explicit uv publish --trusted-publishing values precedence over configuration (#​22279)
  • Allow UV_OFFLINE=false to override offline = true in configuration (#​22283)
  • Allow UV_SYSTEM_CERTS=false to override system-certs = true in configuration (#​22291)
  • Allow uv auth login over IPv6 loopback addresses (#​22306)
  • Resolve GitHub dependencies whose Git references contain # or % characters (#​22281)
  • Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#​22322)
  • Preserve JSON output from uv version and uv self version with a single --quiet flag (#​22280)
  • Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#​22284)
  • Restore wheel incompatibility hints when WHEEL metadata contains multiple expanded Tag: rows (#​22235)
  • Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#​22302)
  • Prevent workspace-cache assertion failures after modifying a project at the workspace root (#​22236)
  • Hide the ignored --keyring-provider option from uv auth help (#​19520)
  • Report HTTP client setup failures directly when resolving unnamed uv tool requirements (#​22320)
Documentation
  • Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests (#​22172)
  • Fix stale links and descriptions in Rust crate documentation (#​22311, #​22361)
  • Fix a typo in the required-environments documentation (#​22238)

Install uv 0.12.24

Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"

Download uv 0.12.24

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum
uv-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
uv-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
uv-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Saturday (* * * * 6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Third-party library dependencies. label Oct 10, 2026
@renovate
renovate Bot enabled auto-merge (rebase) October 10, 2026 04:45
@renovate
renovate Bot merged commit 6a3831b into main Oct 10, 2026
7 checks passed
@renovate
renovate Bot deleted the renovate/uv branch October 10, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Third-party library dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants