Skip to content

ci(deps): bump astral-sh/uv from 0.12.19 to 0.12.23 in /dockerfiles - #1518

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/dockerfiles/astral-sh/uv-0.12.23
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/dockerfiles/astral-sh/uv-0.12.23

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Warning

Cooldown could not be applied because no publication date was available from the registry.

Bumps astral-sh/uv from 0.12.19 to 0.12.23.

Release notes

Sourced from astral-sh/uv's releases.

0.12.23

Release Notes

Released on 2026-10-03.

Python

  • Add CPython 3.15.0rc3 (#22164)

Preview features

  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#22017, #22018)

Bug fixes

  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#22099)

Install uv 0.12.23

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"

Download uv 0.12.23

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum

... (truncated)

Changelog

Sourced from astral-sh/uv's changelog.

0.12.23

Released on 2026-10-03.

Python

  • Add CPython 3.15.0rc3 (#22164)

Preview features

  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#22017, #22018)

Bug fixes

  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#22099)

0.12.22

Released on 2026-10-01.

Python

  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#22147)

Enhancements

  • Accept uppercase release suffixes in wheel platform tags (#22113)
  • Record workspace-member default groups in lockfiles (#22010, #22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#22044, #22103)
  • Record default groups for non-project workspace roots in lockfiles (#22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#22104)
  • Format URLs and paths consistently in CLI messages (#21937)
  • Hide the unsupported --offline option from uv publish help (#22124)

Preview features

  • Honor --no-default-groups in uv audit (#22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#22114)

Configuration

  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#22098)

Performance

  • Reduce uv's binary size by compressing embedded Python download metadata (#22126)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.12.19 to 0.12.23.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.19...0.12.23)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.12.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Oct 3, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Performance Alert ⚠️

Possible performance regression was detected for benchmark 'TiTiler performance Benchmarks'.
Benchmark result of this commit is worse than the previous benchmark result exceeding threshold 1.30.

Benchmark suite Current: 35d5f57 Previous: ce7753e Ratio
WGS1984Quad response_time 0.03 s 0.02 s 1.50

This comment was automatically generated by workflow using github-action-benchmark.

This branch was successfully deployed

No deployments
ci — 35d5f570 Deployed Oct 3, 2026 by dependabot[bot] via tests (3.13) #96
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants