Skip to content

Conversation

@ryantm
Copy link
Collaborator

@ryantm ryantm commented Oct 22, 2025

Why

What changed

  • bump to 0.9.5

Test plan

  • locally, I built python 3.12 and uv --version produced the correct version
  • check that uv --version is 0.9.5

Rollout

Describe any procedures or requirements needed to roll this out safely (or check the box below)

  • This is fully backward and forward compatible

@ryantm ryantm requested a review from a team as a code owner October 22, 2025 14:30
@ryantm ryantm requested review from cbrewster and removed request for a team October 22, 2025 14:30
@macroscopeapp
Copy link

macroscopeapp bot commented Oct 22, 2025

Bump pkgs/modules/python/uv to version 0.9.5 for security and source the release by Git tag in default.nix

Update the uv Nix derivation to build version 0.9.5 and switch source fetching from a fixed commit to the Git tag matching the version in default.nix.

  • Change uv version from 0.5.11 to 0.9.5
  • Fetch source by Git tag equal to the version
  • Update source hash and cargo vendor hash

📍Where to Start

Start with the uv derivation changes in default.nix, reviewing the version bump, source fetching method, and updated hashes.


📊 Macroscope summarized 5e985b3. 0 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@ryantm ryantm enabled auto-merge October 22, 2025 14:32
@ryantm ryantm disabled auto-merge October 22, 2025 14:54
@ryantm ryantm enabled auto-merge October 22, 2025 14:54
@ryantm ryantm removed the request for review from cbrewster October 22, 2025 14:54
Why
===
* uv fixed a security issue in 0.9.5
https://github.com/astral-sh/uv/releases/tag/0.9.5

What changed
===
* bump to 0.9.5

Test plan
===
* check that uv --version is 0.9.5
@ryantm ryantm merged commit eb80187 into main Oct 22, 2025
4 checks passed
@ryantm ryantm deleted the rtm1022bumpuv branch October 22, 2025 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants