Skip to content

chore(ci): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 in /.github/actions/setup-python in the actions group across 1 directory - #683

Merged
pratyush618 merged 1 commit into
masterfrom
dependabot/github_actions/dot-github/actions/setup-python/actions-2514a98571
Aug 17, 2026
Merged

chore(ci): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 in /.github/actions/setup-python in the actions group across 1 directory#683
pratyush618 merged 1 commit into
masterfrom
dependabot/github_actions/dot-github/actions/setup-python/actions-2514a98571

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update in the /.github/actions/setup-python directory: astral-sh/setup-uv.

Updates astral-sh/setup-uv from 9.0.0 to 10.0.1

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.0.1 🌈 Tolerate transient manifest timeouts

Changes

Thank you @​arguile- for making this action more resilient.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in astral-sh/setup-uv#984

version: latest-known

- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions

- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added ci dependencies Pull requests that update a dependency file labels Aug 17, 2026
@pratyush618

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the actions group with 1 update in the /.github/actions/setup-python directory: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).


Updates `astral-sh/setup-uv` from 9.0.0 to 10.0.1
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v9.0.0...v10.0.1)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/dot-github/actions/setup-python/actions-2514a98571 branch from 0050ea6 to 5b427bf Compare August 17, 2026 08:01
@pratyush618
pratyush618 merged commit e407bbc into master Aug 17, 2026
24 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/dot-github/actions/setup-python/actions-2514a98571 branch August 17, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant