Skip to content

Bump uv from 0.6.17 to 0.10.8 in /__tests__/fixtures/uv-in-requirements-txt-project - #62

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/__tests__/fixtures/uv-in-requirements-txt-project/uv-0.10.8
Closed

Bump uv from 0.6.17 to 0.10.8 in /__tests__/fixtures/uv-in-requirements-txt-project#62
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/__tests__/fixtures/uv-in-requirements-txt-project/uv-0.10.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 4, 2026

Copy link
Copy Markdown

Bumps uv from 0.6.17 to 0.10.8.

Release notes

Sourced from uv's releases.

0.10.8

Release Notes

Released on 2026-03-03.

Python

  • Add CPython 3.10.20
  • Add CPython 3.11.15
  • Add CPython 3.12.13

Enhancements

  • Add Docker images based on Docker Hardened Images (#18247)
  • Add resolver hint when --exclude-newer filters out all versions of a package (#18217)
  • Configure a real retry minimum delay of 1s (#18201)
  • Expand uv_build direct build compatibility (#17902)
  • Fetch CPython from an Astral mirror by default (#18207)
  • Download uv releases from an Astral mirror in installers by default (#18191)
  • Add SBOM attestations to Docker images (#18252)
  • Improve hint for installing meson-python when missing as build backend (#15826)

Configuration

  • Add UV_INIT_BARE environment variable for uv init (#18210)

Bug fixes

  • Prevent uv tool upgrade from installing excluded dependencies (#18022)
  • Promote authentication policy when saving tool receipts (#18246)
  • Respect exclusions in scripts (#18269)
  • Retain default-branch Git SHAs in pylock.toml files (#18227)
  • Skip installed Python check for URL dependencies (#18211)
  • Respect constraints during --upgrade (#18226)
  • Fix uv tree orphaned roots and premature deduplication (#17212)

Documentation

  • Mention cooldown and tweak inline script metadata in dependency bots documentation (#18230)
  • Move cache prune in GitLab to after_script (#18206)

Install uv 0.10.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.sh | sh

Install prebuilt binaries via powershell script

... (truncated)

Changelog

Sourced from uv's changelog.

0.10.8

Released on 2026-03-03.

Python

  • Add CPython 3.10.20
  • Add CPython 3.11.15
  • Add CPython 3.12.13

Enhancements

  • Add Docker images based on Docker Hardened Images (#18247)
  • Add resolver hint when --exclude-newer filters out all versions of a package (#18217)
  • Configure a real retry minimum delay of 1s (#18201)
  • Expand uv_build direct build compatibility (#17902)
  • Fetch CPython from an Astral mirror by default (#18207)
  • Download uv releases from an Astral mirror in installers by default (#18191)
  • Add SBOM attestations to Docker images (#18252)
  • Improve hint for installing meson-python when missing as build backend (#15826)

Configuration

  • Add UV_INIT_BARE environment variable for uv init (#18210)

Bug fixes

  • Prevent uv tool upgrade from installing excluded dependencies (#18022)
  • Promote authentication policy when saving tool receipts (#18246)
  • Respect exclusions in scripts (#18269)
  • Retain default-branch Git SHAs in pylock.toml files (#18227)
  • Skip installed Python check for URL dependencies (#18211)
  • Respect constraints during --upgrade (#18226)
  • Fix uv tree orphaned roots and premature deduplication (#17212)

Documentation

  • Mention cooldown and tweak inline script metadata in dependency bots documentation (#18230)
  • Move cache prune in GitLab to after_script (#18206)

0.10.7

Released on 2026-02-27.

Bug fixes

  • Fix handling of junctions in Windows Containers on Windows (#18192)

Enhancements

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uv](https://github.com/astral-sh/uv) from 0.6.17 to 0.10.8.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.6.17...0.10.8)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.10.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Mar 4, 2026
@dependabot @github

dependabot Bot commented on behalf of github Mar 9, 2026

Copy link
Copy Markdown
Author

Superseded by #65.

@dependabot dependabot Bot closed this Mar 9, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/__tests__/fixtures/uv-in-requirements-txt-project/uv-0.10.8 branch March 9, 2026 04:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants