Skip to content

chore(deps): update dependency uv to v0.12.20 - #290

Open
renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/uv-0.x
Open

renovate[bot] wants to merge 1 commit into
stagingfrom
renovate/uv-0.x

Conversation

@renovate

@renovate renovate Bot commented Mar 29, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
uv minor 0.11.0 → 0.12.20

Release Notes

astral-sh/uv (uv)

v0.12.20

Compare Source

Released on 2026-09-28.

Enhancements
  • Reuse lockfiles when dependency declarations are semantically equivalent (#​21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#​21990)
Preview features
  • Write normalized requirement declarations with the lockfile-normalization preview feature (#​21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#​22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#​22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#​22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#​22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#​22050)
Configuration
  • Continue searching XDG_CONFIG_DIRS after empty entries (#​21987)
Performance
  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#​22051)
Bug fixes
  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#​21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#​21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#​21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#​21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#​21979)
  • Prevent commands from running and changing state after displaying --show-settings (#​21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#​21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#​22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#​22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#​22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#​22034)

v0.12.19

Compare Source

Released on 2026-09-24.

Python
  • Add PyPy 3.11.16 and 3.12.14 (#​21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#​21847)
Enhancements
  • Format upload URLs with backticks in uv publish errors (#​21934)
Preview features
  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#​21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#​21913)
Bug fixes
  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#​21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#​21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#​21891)
  • Preserve always-false python_version markers when parsing their serialized form (#​21939)
Rust API
  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#​21965)
Documentation
  • Make individual preview-feature reference entries linkable by name (#​21950)

v0.12.18

Compare Source

Released on 2026-09-22.

Enhancements
  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#​21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#​21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#​21881)
Preview features
  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#​21880)
Performance
  • Speed up uv_build editable wheel creation by omitting compression from temporary wheels (#​21918)
Bug fixes
  • Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#​21835, #​21836)
  • Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#​21860, #​21856)
  • Use configured dependency-metadata when checking whether installed requirements are satisfied (#​21843)
  • Reject archive entries that normalize to absolute Windows paths (#​21923)
  • Recognize distribution filenames and archive extensions when URL fragments contain ? (#​21920)
  • Generate correctly lowercased platform tags for BSD and Haiku releases (#​21853)
  • Avoid rebuilding a Windows relative path into an absolute form (#​21923)

v0.12.17

Compare Source

Released on 2026-09-18.

Enhancements
  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#​21780)
Preview features
  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#​21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#​20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#​21821)
  • Apply uv check lock modes when retrieving workspace metadata (#​21821)
Performance
  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#​21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#​21810)
Bug fixes
  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#​21825)
Documentation
  • Clarify the 0.12.14 and 0.12.15 release notes (#​21817)

v0.12.16

Compare Source

Released on 2026-09-17.

Python
  • Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#​21741)
Enhancements
  • Verify downloaded wheels and source distributions against hashes supplied by package indexes (#​21562)
  • Allow build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#​21467)
  • Honor Darwin platform_release markers in required-environments using macOS wheel deployment targets (#​21766)
  • Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#​21779)
Preview features
  • Support lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#​21163)
  • Honor configured and command-line index settings, including credentials, in uv upgrade (#​21776)
  • Allow uv check to run in projects that are not managed by uv and outside workspaces (#​21777)
  • Respect --python and UV_PYTHON when selecting the Python version for uv check (#​21744)
Bug fixes
  • Redact Azure shared access signatures from displayed and logged URLs (#​21755)
  • Check archive sizes from pylock.toml before reusing cached distributions (#​21609)
  • Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths (#​20631)
  • Use the bundled uv_build backend only when its version matches active version pins (#​21742)
  • Handle malformed index URLs without panicking when credentials are configured (#​21784)
  • Report a configuration error instead of panicking for proxy URLs without a host (#​21781)
  • Return a credential-redacted error instead of panicking when a URL cannot be converted to a path (#​21783)

v0.12.15

Compare Source

Released on 2026-09-15.

This release fixes a regression in 0.12.14 that lead to rejecting valid installation commands such as using
uv pip install --system in python:* docker images or when using uv pip install --target .. (#​21699)

Performance
  • Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes (#​21675)
Bug fixes
  • Revert "Reject symlinked wheel installation destinations" (#​21699)

v0.12.14

Compare Source

Released on 2026-09-15.

Package-operation errors now use uv's standard diagnostics, with consistent hints and compact, labeled cause chains. (#​17110, #​21599, #​21603)

Package-operation exit codes now reflect the underlying cause: expected failures return 1, while recognized operational and internal failures return 2. (#​17110)

Enhancements
  • Resume interrupted downloads with HTTP Range requests when supported (#​21570)
  • Show underlying causes and hints in user warnings (#​21565)
  • Show resolver hints for failed uv tool upgrade operations (#​21566)
Preview features
  • Export multiple dependency selections from a shared lockfile in one uv export --batch invocation with the batch-export preview feature (#​21618)
Performance
  • Speed up dependency resolution from local wheelhouses by reading wheel metadata in a single blocking task (#​21619)
  • Speed up cold resolution against large package indexes by parsing Simple API responses in bounded background workers (#​21593)
  • Speed up warm-cache resolution by decoding fresh HTTP cache entries in the cache-read task (#​21621)
Bug fixes
  • Select releases that satisfy required-environments within each resolver fork instead of combining incompatible wheel coverage across forks (#​21672)
  • Install packages with paths longer than MAX_PATH on Windows systems without long-path support enabled (#​21625)
  • Prevent uv python install from overwriting valid unmanaged Python symlinks with relative targets on Unix (#​21639)
  • Redact credentials and signatures from missing-path-segment URL errors (#​21616)
  • Avoid exceeding the configured retry budget when cached HTTP responses fail revalidation (#​21640)
  • Prefer bin/python over bin/python3 when discovering interpreters in Unix environments (#​21559)
  • Suppress managed-Python fallback warnings under --quiet (#​21565)
  • Keep failed uv tool upgrade errors visible with -q while suppressing them with -qq (#​21566)

v0.12.13

Compare Source

Released on 2026-09-10.

Python
Enhancements
  • Verify hashes when downloading PEP 658 metadata sidecars (#​21563)
Preview features
  • Respect ty exclusions when uv check automatically selects members of a virtual workspace (#​21555)
Performance
  • Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately (#​21279)
Bug fixes
  • Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention (#​18713)
  • Prefer core-metadata over legacy aliases in JSON index responses (#​21563)

v0.12.12

Compare Source

Released on 2026-09-09.

The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

Bug fixes
  • Exclude distributions uploaded after the exclude-newer cutoff from lockfiles and generated requirement hashes (#​21539)

v0.12.11

Compare Source

Released on 2026-09-08.

Preview features
  • Generate missing artifact hashes when exporting pylock.toml files to ensure they conform to PEP 751 (#​20146)
  • Warn when pylock.toml artifact hash tables are empty, which will be rejected in a future uv release (#​21462)
Performance
  • Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements (#​21478)
  • Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files (#​21468)
  • Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads (#​21500)
  • Speed up local wheel installs by reusing ZIP readers and buffers across extracted files (#​21499)
  • Avoid transitive dependency checks and unnecessary resolution when uv pip install --no-deps finds the requested packages already installed (#​21523)
Bug fixes
  • Verify source archives against hashes recorded in uv.lock before reading their metadata or running their build backends (#​21223)
  • Verify supplied hashes for registry requirements pinned with === under both --verify-hashes and --require-hashes (#​21543)
  • Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided (#​21544)
  • Support PowerShell virtual environment activation from UNC paths, including WSL paths (#​19159)
  • Trim surrounding whitespace from entries in .python-version and .python-versions files (#​21529)
  • Suppress VIRTUAL_ENV mismatch warnings for uv add --no-sync, uv remove --no-sync, and uv add --frozen (#​21496)
  • Warn and continue when uv python list cannot query an interpreter (#​21498)
Documentation
  • Restore TOML syntax highlighting for exclude-newer examples (#​21534)

v0.12.10

Compare Source

Released on 2026-09-04.

Enhancements
  • Attempt to revoke short-lived PyPI trusted-publishing tokens after uv publish completes, including when publishing fails (#​21423)
Preview features
  • Omit exclude-newer-package settings for packages outside the resolution from uv.lock with the missing-exclude-newer-package-lock preview feature (#​21455)
  • Show terminal dependency cycles in uv tree --invert output (#​21404)
Performance
  • Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification (#​21399)
  • Speed up uv publish by hashing each artifact in a single blocking task and reusing the buffer across reads (#​21389)
Bug fixes
  • Prevent --locked from failing when exclude-newer-package settings differ only for packages outside the resolution (#​21454)
  • Allow uv lock --check to reuse a lockfile when an absolute exclude-newer cutoff is moved later (#​19571)
  • Allow uv lock --check to reuse a lockfile when a package-specific exclude-newer cutoff is disabled (#​21450)
  • Require an explicit --name when uv init would infer a project name reserved for a Python interpreter (#​21395)
  • Write package-specific exclude-newer cutoffs to uv.lock in a deterministic order (#​21453)

v0.12.9

Compare Source

Released on 2026-09-01.

Python
Enhancements
  • Add --no-locked and --no-frozen to disable lock modes enabled by UV_LOCKED and UV_FROZEN for a single invocation (#​21408)
  • Report the exact command-line lock-mode flag in warnings and errors (#​21402)
Performance
  • Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#​21372)
Bug fixes
  • Update async_http_range_reader to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#​21401)
  • Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#​21382)
  • Redact secrets in signed URLs from retry diagnostics, including nested request errors (#​21381)
  • Give --locked, --frozen, --check, and --check-exists precedence over conflicting UV_LOCKED and UV_FROZEN values (#​21396)
  • Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#​21400)

v0.12.8

Compare Source

Released on 2026-08-31.

Enhancements
  • Warn about invalid tool directories and continue upgrading valid tools with uv tool upgrade --all (#​21368)
Preview features
  • Deduplicate identical files within and across cached wheels with the content-addressed-cache preview feature (#​21327)
  • Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files (#​21340)
  • Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk (#​21344)
Performance
  • Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once (#​21379)
  • Speed up dependency graph construction from large lockfiles by indexing packages during traversal (#​21373)
  • Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks (#​21377)
  • Speed up warm resolutions by reducing repeated marker interner work (#​21300)
Bug fixes
  • Do not trust hashes from direct URLs discovered only in wheel metadata when installing with --require-hashes (#​21348)
  • Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled (#​21366)
  • Redact Azure shared access signature (sig) query parameters from displayed URLs (#​21360)
  • Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery (#​21341)
Other changes
  • Update astral-tokio-tar to 0.7.0 and use effective sizes when tracking extracted hard links (#​21346)

v0.12.7

Compare Source

Released on 2026-08-27.

Python
  • Replace managed Python installations when upgrading to a newer build of the same version (#​21323)
Enhancements
  • Support Linux s390x, ppc64le, and loongarch64 targets for cross-platform dependency resolution (#​21313)
  • Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via UV_AZURE_ENDPOINT_URL (#​21318)
Preview features
  • Use content-based directory hashes to deduplicate extracted wheels in the cache with the content-addressed-cache preview feature (#​19693)
Bug fixes
  • Reject source archives with hash mismatches before persisting their extracted contents to the cache (#​21248)
Other changes

v0.12.6

Compare Source

Released on 2026-08-25.

Python
  • Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #​21295)
Enhancements
  • Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links (#​21261)
  • Limit warnings about unbounded uv_build requirements to source-distribution builds (#​21078)
  • Display byte counts below 1 KiB without a fractional part (#​21237)
Preview features
  • Add uv workspace metadata --sync --exact to remove packages outside the selected resolution (#​21117)
  • Add the artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#​21235)
  • Respect package-specific exclude-newer cutoffs when uv check selects its ty executable (#​21227)
  • Preserve virtual-environment hints from tar-codec source-distribution errors when the base interpreter is outside a bin directory (#​21146)
Performance
  • Enable profile-guided optimization for Linux x86-64 release binaries (#​21001)
  • Enable profile-guided optimization for Windows x86-64 release binaries (#​21003)
  • Enable profile-guided optimization for macOS ARM64 release binaries (#​21002)
  • Enable profile-guided optimization for Linux ARM64 release binaries (#​21004)
  • Speed up syncing projects with many activated conflict items by reusing their encoded representation (#​21148)
Bug fixes
  • Allow explicit uv build and non-editable first-party workspace packages when no-build is enabled (#​21294)
  • Reuse configured index credentials during uv tool upgrade when the tool receipt references the same index (#​21275)
  • Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch (#​21224)
  • Prevent TLS segfaults in riscv64 musl release binaries (#​21158)
  • Preserve dependencies selected by recursive extras when markers mix production and extra conditions (#​21181)
  • Preserve version constraints from transitively referenced recursive extras (#​21209)
  • Resolve repository-relative Git archive dependencies inside the checkout during the initial uv sync (#​21264)
  • Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header (#​21282)
  • Do not misclassify package URLs ending in .py as local script paths (#​21144)
  • Use directory creation times consistently across libc implementations for directory cache-keys entries (#​21137)
  • Promote human-readable sizes to the next unit at rounding boundaries (#​21136)
Other changes
  • Add Python 3.15 release-candidate Docker images (#​21293)
  • Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 (#​21258)

v0.12.5

Compare Source

Released on 2026-08-14.

Python
  • Add CPython 3.10.21, 3.11.16, and 3.12.14 (#​21138)
  • Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#​21134)
Enhancements
  • Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#​21130)
Preview features
  • Allow --index and --default-index to select configured package indexes by name with the index-by-name preview feature (#​17455)
  • Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#​21131)
  • Fall back to logical file sizes when using cache-physical-space on filesystems that do not support physical-space accounting (#​21133)
Bug fixes
  • Resolve relative package index paths in PEP 723 scripts against the script directory (#​21097)

v0.12.4

Compare Source

Released on 2026-08-13.

Enhancements
  • Prefer post-quantum key exchange and enable opt-in TLS diagnostics (#​21054)
  • Accept whitespace before versions in noncompliant wildcard comparisons such as Requires-Python: >= 3.5.* (#​21012)
  • Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content (#​20944)
  • Omit source-span carets from diagnostics for empty PEP 508 requirements (#​21094)
Preview features
  • Add uv check --no-install-project and respect UV_NO_INSTALL_PROJECT to install dependencies without building or installing the project (#​21085)
  • Make the ty subprocess invoked by uv check honor uv's color and progress settings, including quiet mode (#​21086)
Performance
  • Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges (#​20804)
  • Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly (#​21041)
Bug fixes
  • Use windowed pythonw.exe launchers for virtual environments created from managed Python minor-version links (#​19235)
  • Allow uv lock to proceed when .venv is an unusable project environment (#​21068)
  • Respect fork-strategy when ordering forks created from environments or existing lockfile resolution-markers (#​21000)
  • Preserve consecutive wildcard Python minor-version exclusions such as !=3.11.*, !=3.12.* in uv.lock (#​21045)
  • Preserve inline comments on the final item in dependency arrays when uv add updates it (#​21008)
  • Recover from stale base-interpreter cache metadata when an existing virtual environment exposes a version mismatch (#​21073)
  • Prevent interpreter cache reuse across different PYTHONEXECUTABLE and __PYVENV_LAUNCHER__ overrides (#​21075)
  • Show standard styling, usage guidance, and line termination for invalid uv version --bump values (#​21076)

v0.12.3

Compare Source

Released on 2026-08-07.

Python
Preview features
  • Add --output-format to select automatic, human-readable, or raw-byte output for uv cache size (#​20992)
  • Preserve JSON output from uv workspace metadata --quiet while suppressing diagnostics (#​20991)
  • Reduce memory usage for large workspaces by streaming uv workspace metadata JSON output (#​20990)
Performance
  • Reduce Linux startup latency by initializing the workspace cache before spawning another thread (#​20989)
  • Reuse compiled workspace exclusion patterns during workspace discovery (#​20988)
  • Speed up conflict-heavy resolutions by avoiding materialized range complements (#​20982)
  • Avoid slow procfs reads during Python interpreter discovery on Linux (#​20987)
Documentation
  • Add PEP 740 attestations to the GitHub Actions publishing example (#​20986)
  • Restrict the GitHub Actions publishing example to Python version tags (#​20973)
  • Correct --python-pin to --pin-python in the uv init --bare example (#​20876)

v0.12.2

Compare Source

Released on 2026-08-05.

Python
Enhancements
  • Ensure diagnostic hints end with a newline to prevent malformed terminal output (#​20959)
Preview features
  • Audit one or all installed tools with uv tool audit (#​20921)
  • Report physically reclaimed disk space during cache cleanup with the cache-physical-space preview feature (#​20925)
Configuration
  • Add UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#​20926)
Performance
  • Speed up uv.lock parsing for wheel entries (#​20881)
  • Speed up uv.lock parsing for source distribution entries (#​20882)
  • Speed up filename extraction from distribution URLs (#​20879)
  • Reduce filesystem metadata lookups during bytecode compilation (#​20928)
  • Reuse file metadata when building source distributions (#​20927)
Bug fixes
  • Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions (#​20963)
  • Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested (#​20930)
Documentation
  • Separate build and publish jobs in the GitHub Actions publishing guide (#​20946)
  • Ensure the GitHub Actions publishing example waits for the build job to finish (#​20957)
  • Correct typos in the Docker integration guide (#​20970)

v0.12.1

Compare Source

Released on 2026-07-31.

Enhancements
  • Add package-specific pre-release policies with --prerelease-package (#​20837)
  • Support local HTML files as flat indexes (#​20802)
  • Add Xonsh virtual environment activation scripts (activate.xsh) (#​19740)
  • Preserve filesystem paths passed to uv add --index when updating pyproject.toml (#​20817)
Preview features
  • Add automatic fixes to uv check with --fix (#​20793)
  • Avoid rejecting unchanged metadata-free lockfiles when workspace dependencies share direct sources (#​20847)
  • Honor direct URL constraints when validating metadata-free lockfiles (#​20796)
  • Ignore malformed PEP 723 scripts discovered during project checks (#​20784)
  • Use ty's native script exclusion in uv check (#​20742)
Performance
  • Parse canonical uv lockfiles directly, with a fallback for other valid TOML syntax (#​20648)
  • Accelerate SHA-256 hashing on non-Windows ARM64 platforms (#​20805)
Bug fixes
  • Flush shell startup file updates before uv tool update-shell and uv python update-shell exit (#​20842)
  • Make workspace-root dependency groups available to commands run from workspace members (#​20840)
  • Resolve --find-links paths in requirements files relative to the containing file (#​20832)
  • Respect configured indexes in uv tool list --outdated (#​20770)
Documentation
  • Document Astral GPU indexes in the PyTorch guide (#​20785)
  • Use consistent dependency-group argument descriptions throughout the CLI documentation (#​20823)

v0.12.0

Compare Source

Released on 2026-07-28.

Since we released uv 0.11.0 in March, we've accumulated changes that improve correctness, safety, and compatibility with specifications, but could break some workflows. This release contains those changes; many have been marked as breaking out of an abundance of caution.

We expect most users to be able to upgrade without making changes.

There are no breaking changes to the configuration of the uv build backend. If your [build-system] table includes an upper bound on uv_build, update it to allow uv_build 0.12, e.g., uv_build>=0.11.32,<0.13.

Breaking changes
  • Define build systems by default with uv init (#​19197)

    Projects created with uv init now declare a build system and are packaged by default. This was the default project layout all the way back in v0.3, but we found that the use of the hatchling build system was confusing to newcomers and consequently dropped use of a build system by default in v0.4. Since then, we've created our own build system (uv_build) with tight integration with uv and are excited to restore the default to a best-practice project layout.

    Previously, uv init example created an unpackaged layout containing main.py and a pyproject.toml without a build system. The project could declare dependencies but was not itself installed into its virtual environment.

    Now, uv init example defines a [build-system] using uv_build, places application source code in src/example, and includes a [project.scripts] entry named example. Defining a build system allows the project to be imported from tests or other code, installed as a dependency, and run as a command:

    $ uv init example
    $ cd example
    $ uv run example
    Hello from example!

    Existing projects are unaffected. Use uv init --no-package example to create the previous unpackaged layout without a build system.

    See the project creation documentation for more details.

    This stabilizes the packaged-init preview feature.

  • Reject unsupported source distribution and wheel archive formats (#​18927)

    PEP 625 requires source distributions to use .tar.gz archives. Previously, uv also accepted legacy formats such as .tar.bz2 and .tar.xz. Those formats are now rejected, including when referenced by an existing lockfile. Legacy .zip source distributions remain supported for backwards compatibility.

    Wheels and other ZIP archives can no longer contain entries compressed with bzip2, LZMA, or XZ. Entries must use the stored, DEFLATE, or zstd compression methods.

    Removing support for uncommon compression methods reduces uv's compression dependencies and the attack surface exposed when processing untrusted packages.

    You cannot opt out of this behavior. If you depend on a legacy source distribution that uses an unsupported format, we recommend rebuilding it as a .tar.gz archive and regenerating any lockfile containing references to the legacy archive.

  • Reject wheel files that could replace the Python interpreter (#​20748, #​20749)

    uv already rejected wheel entry points named python, but case variants such as Python were still accepted. On case-insensitive filesystems, including common macOS and Windows setups, these entry points could overwrite the virtual environment's interpreter.

    Wheels could also place interpreter files in their .data/scripts directory or in paths such as .data/data/bin/python, bypassing the entry-point check and replacing the interpreter during installation.

    uv now rejects case-insensitive variants of reserved interpreter names and wheel data files that would be installed over an interpreter. This includes names such as Python, python.py, and Python.exe, along with other reserved interpreter names and their versioned variants.

    You cannot opt out of these checks. Rename conflicting entry points or wheel data files and rebuild the affected wheel.

  • Prefer stable releases before falling back to pre-releases (#​19993)

    A dependency can introduce a pre-release requirement after resolution starts. uv previously required each package's pre-release eligibility to be known before resolution began: the default if-necessary-or-explicit mode allowed them for direct requirements that explicitly requested a pre-release, or for packages that only published pre-releases.

    This meant that a pre-release requirement discovered in a dependency's metadata, e.g., example>=2.0.0b1, would fail to resolve even when a compatible pre-release existed. To resolve it, you had to add that dependency as a direct requirement or allow pre-releases across your entire dependency graph.

    The default mode is now if-necessary. uv tries stable candidates first and falls back to pre-releases when no stable candidate satisfies the active constraints. Like pip, uv now supports pre-release requirements discovered transitively, but can select different versions than previous uv releases when both stable and pre-release candidates are available.

    You can opt out of automatic pre-release selection with --prerelease disallow. Alternatively, --prerelease allow considers pre-releases without first preferring stable releases, and --prerelease explicit only allows them for direct requirements that mention a pre-release.

    The old if-necessary-or-explicit mode distinguished between explicitly requested pre-releases and packages with no stable releases. That distinction is unnecessary now that if-necessary handles both cases, including transitive requirements. The old name remains available as an alias but is deprecated and will be removed in a future release.

  • Respect --require-hashes directives in requirements.txt (#​19336)

    Previously, uv pip install and uv pip sync warned about --require-hashes inside a requirements.txt file but still installed dependencies without checking their hashes. Now, the directive enables hash-checking mode, just as if --require-hashes had been passed on the command line.

    For example, this requirements file is no longer accepted because the requirement is neither pinned nor hashed:

    --require-hashes
    anyio
    

    You cannot opt out while the directive is present. Pin every requirement with == and provide its hash, or remove --require-hashes if hash checking is not intended.

  • Reject MD5-only hashes in hash-checking mode (#​20758)

    Previously, uv pip install --require-hashes and uv pip sync --require-hashes accepted requirements whose only available digest used MD5. MD5 is not collision-resistant, so relying on it undermined installations that require hash verification and differed from pip's behavior.

    Hash-checking mode now requires at least one secure digest for every requirement. For example, the following requirement is rejected unless a secure hash, such as SHA-256, is also supplied:

    anyio==4.0.0 --hash=md5:420d85e19168705cdf0223621b18831a
    

    A secure hash can be supplied directly on the requirement or in a matching constraints file. Ordinary hash verification without --require-hashes continues to support MD5.

    You cannot opt out while hash checking is required. Regenerate affected hashes with SHA-256 or another supported secure hash.

  • Reject invalid pylock.toml files and artifacts (#​20402, #​20440, #​20443)

    uv now validates additional requirements from the pylock.toml specification:

    • The packages array must be present. Previously, uv interpreted a missing array as an empty lockfile, so uv pip sync could uninstall an environment instead of rejecting malformed input. An explicitly empty packages = [] array remains valid.
    • Lockfile filenames must be pylock.toml or a single-name variant such as pylock.dev.toml. Names such as pylock..toml and pylock.foo.bar.toml are rejected.
    • If a wheel, source distribution, or other artifact declares a size, the downloaded or cached artifact must match. Previously, an incorrect size was accepted when the hash was correct. Sizes reported by package indexes remain advisory.

    You cannot opt out of these checks. Regenerate malformed lockfiles, rename invalid filenames, and either correct or remove an incorrect optional size value.

  • Honor explicit certificate overrides even when no certificates can be loaded (#​20741, #​20767)

    Previously, uv ignored SSL_CERT_FILE or SSL_CERT_DIR values that pointed to missing or inaccessible paths, empty files or directories, or sources without valid certificates. Instead, it fell back to its default trust r

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "before 4:00am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate label Mar 29, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.2 chore(deps): update dependency uv to v0.11.3 Apr 1, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 009dc49 to 21a4d5d Compare April 1, 2026 23:41
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.3 chore(deps): update dependency uv to v0.11.4 Apr 8, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch 2 times, most recently from 88074b0 to ceb1c72 Compare April 9, 2026 02:07
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.4 chore(deps): update dependency uv to v0.11.5 Apr 9, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.5 chore(deps): update dependency uv to v0.11.6 Apr 9, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from ceb1c72 to 7afa1bd Compare April 9, 2026 15:08
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.6 chore(deps): update dependency uv to v0.11.7 Apr 16, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 7afa1bd to de13e22 Compare April 16, 2026 10:12
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from de13e22 to adf985c Compare April 27, 2026 15:30
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.7 chore(deps): update dependency uv to v0.11.8 Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.8 chore(deps): update dependency uv to v0.11.9 May 5, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from adf985c to 4730241 Compare May 5, 2026 09:30
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.9 chore(deps): update dependency uv to v0.11.10 May 5, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch 2 times, most recently from 5a13601 to cad6f68 Compare May 6, 2026 22:02
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.10 chore(deps): update dependency uv to v0.11.11 May 6, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.11 chore(deps): update dependency uv to v0.11.12 May 9, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from cad6f68 to 85f2f5b Compare May 9, 2026 02:00
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.12 chore(deps): update dependency uv to v0.11.13 May 11, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 85f2f5b to 4aebada Compare May 11, 2026 01:57
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.13 chore(deps): update dependency uv to v0.11.14 May 12, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 4aebada to 660b92d Compare May 12, 2026 18:46
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.14 chore(deps): update dependency uv to v0.11.15 May 18, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 660b92d to 86e6a8d Compare May 18, 2026 22:08
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.15 chore(deps): update dependency uv to v0.11.16 May 21, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 86e6a8d to cc5e8ae Compare May 21, 2026 22:26
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.16 chore(deps): update dependency uv to v0.11.17 May 28, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.22 chore(deps): update dependency uv to v0.11.23 Jun 19, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 9f381fa to 3ea507b Compare June 19, 2026 19:08
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.23 chore(deps): update dependency uv to v0.11.24 Jun 24, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 3ea507b to 2f74399 Compare June 24, 2026 01:13
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.24 chore(deps): update dependency uv to v0.11.25 Jun 27, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 2f74399 to 817bb5e Compare June 27, 2026 01:54
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.25 chore(deps): update dependency uv to v0.11.26 Jun 30, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch 2 times, most recently from 026e2d9 to 45e8ee5 Compare July 7, 2026 02:33
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.26 chore(deps): update dependency uv to v0.11.27 Jul 7, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 45e8ee5 to 5e30c19 Compare July 8, 2026 01:13
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.27 chore(deps): update dependency uv to v0.11.28 Jul 8, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 5e30c19 to 91911a9 Compare July 15, 2026 22:38
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.28 chore(deps): update dependency uv to v0.11.29 Jul 15, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 91911a9 to 465a8b8 Compare July 20, 2026 23:08
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.29 chore(deps): update dependency uv to v0.11.30 Jul 20, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 465a8b8 to e2459de Compare July 22, 2026 02:11
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.30 chore(deps): update dependency uv to v0.11.31 Jul 22, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from e2459de to ba5afe1 Compare July 24, 2026 02:46
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.31 chore(deps): update dependency uv to v0.11.32 Jul 24, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from ba5afe1 to d01e66d Compare July 28, 2026 17:31
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.32 chore(deps): update dependency uv to v0.11.33 Jul 28, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from d01e66d to 8c59e8a Compare July 28, 2026 21:49
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.11.33 chore(deps): update dependency uv to v0.12.0 Jul 28, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 8c59e8a to 80da7d3 Compare July 31, 2026 21:00
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.12.0 chore(deps): update dependency uv to v0.12.1 Jul 31, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 80da7d3 to 00a0aee Compare August 5, 2026 23:13
@renovate renovate Bot changed the title chore(deps): update dependency uv to v0.12.1 chore(deps): update dependency uv to v0.12.2 Aug 5, 2026
@renovate
renovate Bot force-pushed the renovate/uv-0.x branch from 00a0aee to 8b50700 Compare August 7, 2026 22:26

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants