Skip to content

chore(deps): bump astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.12.4-python3.11-trixie-slim in /jans-cedarling/flask-sidecar - #14792

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.12.4-python3.11-trixie-slim
Closed

chore(deps): bump astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.12.4-python3.11-trixie-slim in /jans-cedarling/flask-sidecar#14792
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.12.4-python3.11-trixie-slim

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.12.4-python3.11-trixie-slim.

Release notes

Sourced from astral-sh/uv's releases.

0.12.4

Release Notes

Released on 2026-08-13.

Enhancements

  • Prefer post-quantum key exchange and enable opt-in TLS diagnostics (#21054)
  • Accept whitespace before versions in noncompliant wildcard comparisons such as Requires-Python: >= 3.5.* (#21012)
  • Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content (#20944)
  • Omit source-span carets from diagnostics for empty PEP 508 requirements (#21094)

Preview features

  • Add uv check --no-install-project and respect UV_NO_INSTALL_PROJECT to install dependencies without building or installing the project (#21085)
  • Make the ty subprocess invoked by uv check honor uv's color and progress settings, including quiet mode (#21086)

Performance

  • Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges (#20804)
  • Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly (#21041)

Bug fixes

  • Use windowed pythonw.exe launchers for virtual environments created from managed Python minor-version links (#19235)
  • Allow uv lock to proceed when .venv is an unusable project environment (#21068)
  • Respect fork-strategy when ordering forks created from environments or existing lockfile resolution-markers (#21000)
  • Preserve consecutive wildcard Python minor-version exclusions such as !=3.11.*, !=3.12.* in uv.lock (#21045)
  • Preserve inline comments on the final item in dependency arrays when uv add updates it (#21008)
  • Recover from stale base-interpreter cache metadata when an existing virtual environment exposes a version mismatch (#21073)
  • Prevent interpreter cache reuse across different PYTHONEXECUTABLE and __PYVENV_LAUNCHER__ overrides (#21075)
  • Show standard styling, usage guidance, and line termination for invalid uv version --bump values (#21076)

Install uv 0.12.4

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.ps1 | iex"

Download uv 0.12.4

| File | Platform | Checksum |

... (truncated)

Changelog

Sourced from astral-sh/uv's changelog.

Changelog

0.12.5

Released on 2026-08-14.

Python

  • Add CPython 3.10.21, 3.11.16, and 3.12.14 (#21138)
  • Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#21134)

Enhancements

  • Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#21130)

Preview features

  • Allow --index and --default-index to select configured package indexes by name with the index-by-name preview feature (#17455)
  • Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#21131)
  • Fall back to logical file sizes when using cache-physical-space on filesystems that do not support physical-space accounting (#21133)

Bug fixes

  • Resolve relative package index paths in PEP 723 scripts against the script directory (#21097)

0.12.4

Released on 2026-08-13.

Enhancements

  • Prefer post-quantum key exchange and enable opt-in TLS diagnostics (#21054)
  • Accept whitespace before versions in noncompliant wildcard comparisons such as Requires-Python: >= 3.5.* (#21012)
  • Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content (#20944)
  • Omit source-span carets from diagnostics for empty PEP 508 requirements (#21094)

Preview features

  • Add uv check --no-install-project and respect UV_NO_INSTALL_PROJECT to install dependencies without building or installing the project (#21085)
  • Make the ty subprocess invoked by uv check honor uv's color and progress settings, including quiet mode (#21086)

Performance

  • Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges (#20804)
  • Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly (#21041)

Bug fixes

... (truncated)

Commits
  • 77803aa Bump version to 0.12.4 (#21105)
  • a82ecc9 Use test contexts for cache file-count filters (#21104)
  • 2c3f6d0 Improve regression coverage for related bug manifestations (#21101)
  • d81ed9d improve fix-bug automations PR title/summary (#21100)
  • aad7fc2 Heal interpreter metadata cache entries when creating a virtual environment i...
  • 08551f7 Use shared helpers for cache filesystem tests (#21099)
  • 791e7a9 Handle promoted regression tests during automated bug fixes (#21093)
  • 23f497e Avoid orphaned caret for empty PEP 508 requirements (#21094)
  • 09d1aa5 Forward uv check terminal settings to ty (#21086)
  • e6d90a6 Authorize issue-comment context persistence (#21091)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.11.7-python3.11-trixie-slim to 0.12.4-python3.11-trixie-slim.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.7...0.12.4)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.12.4-python3.11-trixie-slim
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@mo-auto

mo-auto commented Aug 17, 2026

Copy link
Copy Markdown
Member

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@dependabot @github

dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #14798.

@dependabot dependabot Bot closed this Aug 18, 2026
@dependabot
dependabot Bot deleted the dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.12.4-python3.11-trixie-slim branch August 18, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant