Skip to content

chore(deps-dev): bump uv from 0.11.29 to 0.11.32 - #22

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/uv-0.11.32
Closed

chore(deps-dev): bump uv from 0.11.29 to 0.11.32#22
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/uv-0.11.32

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps uv from 0.11.29 to 0.11.32.

Release notes

Sourced from uv's releases.

0.11.32

Release Notes

Released on 2026-07-23.

Preview features

  • Add --package and --all-packages selection to uv check (#20628)
  • Allow uv upgrade to update multiple marker-specific declarations of the same package (#20335)
  • Reject non-canonically formatted lockfiles in uv lock --check and commands using --locked (#20646)
  • Regenerate non-canonically formatted lockfiles with uv lock --refresh (#20634)
  • Include best-effort information about the active environment in uv workspace metadata by default (#20643)

Performance

  • Skip dependency-group conflict expansion when no additional conflicts can be inferred (#20611)

Bug fixes

  • Fork universal resolutions when Requires-Python is discovered only from distribution metadata (#20586)

Install uv 0.11.32

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"

Download uv 0.11.32

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.11.32

Released on 2026-07-23.

Preview features

  • Add --package and --all-packages selection to uv check (#20628)
  • Allow uv upgrade to update multiple marker-specific declarations of the same package (#20335)
  • Reject non-canonically formatted lockfiles in uv lock --check and commands using --locked (#20646)
  • Regenerate non-canonically formatted lockfiles with uv lock --refresh (#20634)
  • Include best-effort information about the active environment in uv workspace metadata by default (#20643)

Performance

  • Skip dependency-group conflict expansion when no additional conflicts can be inferred (#20611)

Bug fixes

  • Fork universal resolutions when Requires-Python is discovered only from distribution metadata (#20586)

0.11.31

Released on 2026-07-21.

Enhancements

  • Allow workspace sources to reference members in another workspace by path (#18401)
  • Support .venv files containing paths to centralized project environments (#20022)
  • Update bundled Windows timezone data to IANA 2026c (#20554)

Preview features

  • Add an index-specific hash-algorithm setting for lockfile generation (#20605)

Configuration

  • Add audit.malware-check and audit.malware-check-url settings (#20587)

Performance

  • Avoid quadratic work when deduplicating transitive conflicts (#20578)

Bug fixes

  • Suggest --emit-build-options for unsupported uv pip compile --emit-options (#20582)
  • Reject source distributions and wheels with mismatched package names (#20432)
  • Avoid retrying TLS certificate verification failures (#16245)
  • Avoid warnings about uv_build settings for in-tree build backends (#20153)

0.11.30

... (truncated)

Commits
  • 3010295 Bump version to 0.11.32 (#20654)
  • cb1bce0 Regenerate the uv.lock TOML with uv lock --refresh (#20634)
  • c2e07d5 Remove obsolete Python upgrade preview feature (#20651)
  • b6b2e76 Reject unformatted lockfiles in uv lock --check (and --locked) (#20646)
  • a549562 Enable Ruff default lint rules across the repository (and fix all the errors)...
  • e4e2f69 Fix uv check workspace snapshots and ruff lints (#20649)
  • 241df05 Add --package and --all-packages to uv check (#20628)
  • d332950 Include best-effort environment info by default in uv workspace metadata ...
  • b12ab98 Clarify first-party trust in the threat model (#20647)
  • 1fd5716 Use canonical issue references in Codex prompts (#20645)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uv](https://github.com/astral-sh/uv) from 0.11.29 to 0.11.32.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.29...0.11.32)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.11.32
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from abrichr as a code owner July 27, 2026 13:36
abrichr added a commit that referenced this pull request Jul 27, 2026
…ut (#27)

Dependabot's #22 changed only the `release` extra, so `uv sync --locked`
rejected the stale uv.lock and every CI leg failed. Complete the bump instead:
the `release` extra, the semantic-release build_command, its contract test,
and the regenerated lock all move together.

Adds a guard that the two pyproject uv pins agree. Only the `release` extra is
reflected in uv.lock, so a half-applied bump would otherwise let the release
build install a uv that is neither declared nor locked.


Claude-Session: https://claude.ai/code/session_01NyCHrzA1psrKMFfroYbzaM

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

Looks like uv is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 27, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/uv-0.11.32 branch July 27, 2026 22:55
@abrichr

abrichr commented Jul 27, 2026

Copy link
Copy Markdown
Member

Closed in favour of #27, now merged.

This PR bumped only [project.optional-dependencies].release. It could not have gone green: uv.lock was left at 0.11.29, so the first CI step on every leg failed with

error: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided.

The uv pin is declared in three places, and only one of them is what Dependabot's pip ecosystem updates. #27 moves all of them plus the regenerated lock:

  • pyproject.toml [project.optional-dependencies].release — the declared pin; the only one reflected in uv.lock
  • pyproject.toml [tool.semantic_release].build_command — the uv actually installed to build the release
  • tests/test_release_contract.py — asserts the build command's literal pin
  • uv.lock

#27 also adds test_release_uv_pin_is_declared_once, so a future half-applied bump fails on the pin divergence instead of silently letting the release build install a uv that is neither declared nor locked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant