Immutable
release. Only release title and notes can be modified.
Release Notes
Released on 2026-07-21.
Enhancements
- Allow workspace sources to reference members in another workspace by path (#18401)
- Support
.venvfiles containing paths to centralized project environments (#20022) - Update bundled Windows timezone data to IANA 2026c (#20554)
Preview features
- Add an index-specific
hash-algorithmsetting for lockfile generation (#20605)
Configuration
- Add
audit.malware-checkandaudit.malware-check-urlsettings (#20587)
Performance
- Avoid quadratic work when deduplicating transitive conflicts (#20578)
Bug fixes
- Suggest
--emit-build-optionsfor unsupporteduv pip compile --emit-options(#20582) - Reject source distributions and wheels with mismatched package names (#20432)
- Avoid retrying TLS certificate verification failures (#16245)
- Avoid warnings about
uv_buildsettings for in-tree build backends (#20153)
Install uv 0.11.31
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"Download uv 0.11.31
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>