Update all non-major dependencies #294
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.
This PR contains the following updates:
v3.4.0->v3.5.00.8.4->0.8.22v3.9.2->v3.10.0Release Notes
docker/login-action (docker/login-action)
v3.5.0Compare Source
Full Changelog: docker/login-action@v3.4.0...v3.5.0
astral-sh/uv (ghcr.io/astral-sh/uv)
v0.8.22Compare Source
Released on 2025-09-23.
Python
Security
astral-tokio-tarto 0.5.5 which hardens tar archive extraction (#16004)v0.8.21Compare Source
Released on 2025-09-23.
Enhancements
--refreshis provided (#15994)Preview features
Add support for S3 request signing (#15925)
v0.8.20Compare Source
Released on 2025-09-22.
Enhancements
--forceflag foruv cache clean(#15992)Preview features
Bug fixes
freethreaded+debugPython downloads inuv python list(#15985)uv runanduvx(#15990)Documentation
packagelevel conflicts to the conflicting dependencies docs (#15963)v0.8.19Compare Source
Released on 2025-09-19.
Python
See the python-build-standalone release notes for more details.
Bug fixes
uv cache cleanparallel process safe (#15888)platform_machinemarker forwin_arm64platform tag (#15921)v0.8.18Compare Source
Released on 2025-09-17.
Enhancements
uv initdefaults for native build backend cache keys (#15705)pyproject.tomltarget does not exist for dependency groups (#15831)--no-cleartouv venvto disable removal prompts (#15795)--only-groupand--extraflags (#15788)[project]to be missing from apyproject.toml(#14113)baseandrootas base environments (#15682)uv_buildis skipped (#15898)_CONDA_ROOTto detect Conda base environments (#15680)uv publishupload form (#15794)uv sync(#15881)Deprecations
tool.uv.dev-dependencies(#15469)Preview features
native-authfeature (#15872)Bug fixes
uv sync --no-sourcesnot switching from editable to registry installations (#15234)@latest(#15827)tritonas a torch backend package (#15910)UV_INSECURE_NO_ZIP_VALIDATION=1in duplicate header errors (#15912)Documentation
NO_PROXYsupport (#15816)requires-python(#14282)v0.8.17Compare Source
Released on 2025-09-10.
Enhancements
PYX_API_URLwhen suggestinguv auth loginon 401 (#15774)Bug fixes
uv init --script(#15747)v0.8.16Compare Source
Enhancements
--editableto overrideeditable = falseannotations (#15712)editable = falsefor workspace sources (#15708)--with-requirementsand--requirements(#12763)Preview features
--no-projectinuv format(#15572)uv formatin unmanaged projects (#15553)Bug fixes
match-runtimetarget is optional (#15671)uv auth(#15743)uv publish(#15759)Documentation
uv authcommands take a URL (#15664)v0.8.15Compare Source
Python
Enhancements
uv authcommands for credential management (#15570)uv authcommands (#15636)uv tree --show-sizesto show package sizes (#15531)--python-platform riscv64-unknown-linux(#15630)--python-platformtouv runanduv tool(#15515)uv publish --dry-run(#15638)Bug fixes
extra-build-dependencies(#15622)Error messages
v0.8.14Compare Source
Python
Enhancements
--python-platformtouv pip check(#15486)UV_ISOLATED(#15428)--no-install-localoption touv sync,uv addanduv export(#15328)uv pipCLI (#15453)Preview features
{version}onuv formatfailure (#15527)uv formatto prevent races (#15551)--projectinuv format(#15438)uv formatin the project root (#15440)Configuration
Performance
WHEELandMETADATAreads in installed distributions (#15489)Bug fixes
venvin current working directory (#15537)uv publishchecks (#15545)uv venv(#15538)CLICOLOR_FORCE=1when calling build backends (#15472)Documentation
uvw.exeneeds to be removed (#15536)v0.8.13Compare Source
Enhancements
--no-install-*arguments touv add(#15375)uv init(#15377)Preview features
uv formatcommand (#15017)extra-build-dependenciesif match-runtime is explicitlyfalse(#15420)Bug fixes
tritontotorch-backendmanifest (#15405)uv_buildwheel hashes (#15400)--upgrade-packageon the command-line as overridingupgrade = falsein configuration (#15395)v0.8.12Compare Source
Python
See the python-build-standalone release notes for details.
Enhancements
aarch64-pc-windows-msvctarget forpython-platform(#15347)uv tool update-shell(#15356)buildpack-deps:trixie,debian:trixie-slim,alpine:3.22(#15351)Bug fixes
match-runtime = truefor dynamic packages (#15292)Documentation
uv cache cleaninstead ofclear(#15313)v0.8.11Compare Source
Python
Enhancements
extra-build-dependencieshint for any missing module on build failure (#15252)Bug fixes
Rust API
reqwestclients toRegistryClient(#15281)v0.8.10Compare Source
Python
Enhancements
aarch64(#14399)Preview
v0.8.9Compare Source
Enhancements
--reinstallflag touv python upgrade(#15194)Bug fixes
uv python upgradeif they don't already exist (#15192)Documentation
v0.8.8Compare Source
Bug fixes
find_uv_bincompatibility with Python <3.10 (#15177)v0.8.7Compare Source
Python
tkaggbackend (the default on Linux), Pillow'sPIL.ImageTklibrary, and other extension modules that need to use libtcl/libtk directly.See the
python-build-standalonerelease notes for details.Enhancements
uv.lockwhen using--isolated(#15154)--prefixand--withinstallations infind_uv_bin(#14184)find_uv_bin(#14181)find_uv_bin(#14182)Preview features
package-level conflicts in workspaces (#14906)Configuration
UV_DEVandUV_NO_DEVenvironment variables (for--devand--no-dev) (#15010)Bug fixes
--require-hashesapplied to build dependencies inuv pip install(#15153)find_uv_bin(#14191)Documentation
.) to list elements inFeaturesdocs page (#15138)v0.8.6Compare Source
This release contains hardening measures to address differentials in behavior between uv and Python's built-in ZIP parser (CVE-2025-54368).
Prior to this release, attackers could construct ZIP files that would be extracted differently by pip, uv, and other tools. As a result, ZIPs could be constructed that would be considered harmless by (e.g.) scanners, but contain a malicious payload when extracted by uv. As of v0.8.6, uv now applies additional checks to reject such ZIPs.
Thanks to a triage effort with the Python Security Response Team and PyPI maintainers, we were able to determine that these differentials were not exploited via PyPI during the time they were present. The PyPI team has also implemented similar checks and now guards against these parsing differentials on upload.
Although the practical risk of exploitation is low, we take the hypothetical risk of parser differentials very seriously. Out of an abundance of caution, we have assigned this advisory a CVE identifier and have given it a "moderate" severity suggestion.
These changes have been validated against the top 15,000 PyPI packages; however, it's plausible that a non-malicious ZIP could be falsely rejected with this additional hardening. As an escape hatch, users who do encounter breaking changes can enable
UV_INSECURE_NO_ZIP_VALIDATIONto restore the previous behavior. If you encounter such a rejection, please file an issue in uv and to the upstream package.For additional information, please refer to the following blog posts:
Security
Python
Configuration
Bug fixes
UV_HTTP_RETRIESinuv publish(#15106)UV_NO_EDITABLEwhere--no-editableis supported (#15107)cargo-distto addUV_INSTALLER_URLto PowerShell installer (#15114)h2again to avoidtoo_many_internal_resetserrors (#15111)pythonwwhen copying entry points in uv run (#15134)Documentation
v0.8.5Compare Source
Enhancements
uv runwith a GitHub Gist (#15058)uv tool install(#14014)Preview features
extra-build-dependencieswarnings foruv pip(#15088)pylockwarning (#15089)Bug fixes
python-preference = systemwhen managed interpreters are on the PATH (#15059)--systemis used (#15061)h2upgrade (#15079)Documentation
sigstore/cosign-installer (sigstore/cosign-installer)
v3.10.0Compare Source
What's Changed
Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.