Skip to content

ci: Bump astral-sh/setup-uv from 8.3.2 to 9.0.0 - #12

Merged
hseshadr merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0
Aug 3, 2026
Merged

ci: Bump astral-sh/setup-uv from 8.3.2 to 9.0.0#12
hseshadr merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 2, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 8.3.2 to 9.0.0.

Release notes

Sourced from astral-sh/setup-uv's releases.

v9.0.0 🌈 Change prune-cache default to false

Changes

This release disables the default cache cache pruning to ease the load on the PyPi infrastructure. Since users might experience more GitHub Actions cache usage which might result in higher costs this is marked as a breaking change. To read more on why we did this (now) you can read the detailed analysis and reasoning in #967

Besides this big breaking change we also have a small bugfix while building caches for linux distributions that behave a big different than the "big ones" and a speed up in version resolution by only reading the version manifest until a matching version is found saving runtime and network bandwith.

🚨 Breaking changes

🐛 Bug fixes

  • fix: fall back to distribution ID when os-release has no version field @​cxzhong (#961)

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits
  • c771a70 chore(deps): roll up Dependabot updates (#970)
  • 2f537ca chore: update known checksums for 0.11.30 (#968)
  • 2269552 Speed up version client by partial response reads (#807)
  • 47a7f4f Change prune-cache default to false (#967)
  • 71966ef chore(deps): roll up Dependabot updates (#962)
  • f12b1f0 fix: fall back to distribution ID when os-release has no version field (#961)
  • ecd24dd chore: update known checksums for 0.11.29 (#960)
  • 6a19136 docs: update version references to v8.3.2 (#949)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@11f9893...c771a70)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 2, 2026
@hseshadr
hseshadr merged commit ca31ca0 into main Aug 3, 2026
4 checks passed
@hseshadr
hseshadr deleted the dependabot/github_actions/astral-sh/setup-uv-9.0.0 branch August 3, 2026 13:43
hseshadr added a commit that referenced this pull request Aug 3, 2026
…#14)

#12 bumped astral-sh/setup-uv 8.3.2 -> 9.0.0 but touched only
.github/workflows/ci.yml — this repo's own self-test. The file consumers
actually execute, .github/actions/setup-python-uv/action.yml, stayed on
v8.3.2, so the bump reached nobody downstream.

The split was already visible in the field: edge-proc and edgeproc-core
run v9.0.0 directly in their own ci.yml while calling this composite on
their publish path — v9 on test, v8.3.2 on publish, same repo, same PR.

c771a70e6277c0a99b617c7a806ffedaca235ff9 is v9.0.0, confirmed against
`gh api repos/astral-sh/setup-uv/tags` (v8.3.2 there is the outgoing
11f9893b), and is the same SHA #12 and both consumers already run.

The version comment names v9.0.0 exactly. #13 just removed five
floating-major comments for this reason: zizmor's ref-version-mismatch
resolves the comment against upstream, so `# v9` turns main red the
moment astral-sh cuts a patch. No floating major tag exists upstream
anyway — `v9` and `v8` both 404.

Claim touched: "consumers of this composite run a pinned, immutable,
auditable setup-uv." It was true about immutability and false about
which version — the audited pin and the executed pin were different files.

Evidence:
- GH_TOKEN=... uvx zizmor@1.26.1 . -> exit 0, "No findings to report"
- actionlint -> clean; shellcheck -x + bash -n -> clean
- tests/security-policy.sh -> exit 0
- tests/lint-examples.sh -> exit 0, 173 refs resolved, 0 MISSING

Still on the old SHA after this change: nothing executable. README.md:422
and CHANGELOG.md:273,401 mention v8.3.2 as prose; README.md:197 shows
v8.1.0 in a sample. Reported, not edited — no gate reads them.


Claude-Session: https://claude.ai/code/session_015o7tjWLFZvzRv4KyNfDukx

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant