Skip to content

Bump uv-build from 0.12.5 to 0.12.6 - #1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-build-0.12.6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-build-0.12.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown

Bumps uv-build from 0.12.5 to 0.12.6.

Release notes

Sourced from uv-build's releases.

0.12.6

Release Notes

Released on 2026-08-25.

Python

  • Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #21295)

Enhancements

  • Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links (#21261)
  • Limit warnings about unbounded uv_build requirements to source-distribution builds (#21078)
  • Display byte counts below 1 KiB without a fractional part (#21237)

Preview features

  • Add uv workspace metadata --sync --exact to remove packages outside the selected resolution (#21117)
  • Add the artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#21235)
  • Respect package-specific exclude-newer cutoffs when uv check selects its ty executable (#21227)
  • Preserve virtual-environment hints from tar-codec source-distribution errors when the base interpreter is outside a bin directory (#21146)

Performance

  • Enable profile-guided optimization for Linux x86-64 release binaries (#21001)
  • Enable profile-guided optimization for Windows x86-64 release binaries (#21003)
  • Enable profile-guided optimization for macOS ARM64 release binaries (#21002)
  • Enable profile-guided optimization for Linux ARM64 release binaries (#21004)
  • Speed up syncing projects with many activated conflict items by reusing their encoded representation (#21148)

Bug fixes

  • Allow explicit uv build and non-editable first-party workspace packages when no-build is enabled (#21294)
  • Reuse configured index credentials during uv tool upgrade when the tool receipt references the same index (#21275)
  • Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch (#21224)
  • Prevent TLS segfaults in riscv64 musl release binaries (#21158)
  • Preserve dependencies selected by recursive extras when markers mix production and extra conditions (#21181)
  • Preserve version constraints from transitively referenced recursive extras (#21209)
  • Resolve repository-relative Git archive dependencies inside the checkout during the initial uv sync (#21264)
  • Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header (#21282)
  • Do not misclassify package URLs ending in .py as local script paths (#21144)
  • Use directory creation times consistently across libc implementations for directory cache-keys entries (#21137)
  • Promote human-readable sizes to the next unit at rounding boundaries (#21136)

Other changes

  • Add Python 3.15 release-candidate Docker images (#21293)
  • Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 (#21258)

Install uv 0.12.6

... (truncated)

Changelog

Sourced from uv-build's changelog.

0.12.6

Released on 2026-08-25.

Python

  • Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #21295)

Enhancements

  • Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links (#21261)
  • Limit warnings about unbounded uv_build requirements to source-distribution builds (#21078)
  • Display byte counts below 1 KiB without a fractional part (#21237)

Preview features

  • Add uv workspace metadata --sync --exact to remove packages outside the selected resolution (#21117)
  • Add the artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#21235)
  • Respect package-specific exclude-newer cutoffs when uv check selects its ty executable (#21227)
  • Preserve virtual-environment hints from tar-codec source-distribution errors when the base interpreter is outside a bin directory (#21146)

Performance

  • Enable profile-guided optimization for Linux x86-64 release binaries (#21001)
  • Enable profile-guided optimization for Windows x86-64 release binaries (#21003)
  • Enable profile-guided optimization for macOS ARM64 release binaries (#21002)
  • Enable profile-guided optimization for Linux ARM64 release binaries (#21004)
  • Speed up syncing projects with many activated conflict items by reusing their encoded representation (#21148)

Bug fixes

  • Allow explicit uv build and non-editable first-party workspace packages when no-build is enabled (#21294)
  • Reuse configured index credentials during uv tool upgrade when the tool receipt references the same index (#21275)
  • Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch (#21224)
  • Prevent TLS segfaults in riscv64 musl release binaries (#21158)
  • Preserve dependencies selected by recursive extras when markers mix production and extra conditions (#21181)
  • Preserve version constraints from transitively referenced recursive extras (#21209)
  • Resolve repository-relative Git archive dependencies inside the checkout during the initial uv sync (#21264)
  • Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header (#21282)
  • Do not misclassify package URLs ending in .py as local script paths (#21144)
  • Use directory creation times consistently across libc implementations for directory cache-keys entries (#21137)
  • Promote human-readable sizes to the next unit at rounding boundaries (#21136)

Other changes

  • Add Python 3.15 release-candidate Docker images (#21293)
  • Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 (#21258)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uv-build](https://github.com/astral-sh/uv) from 0.12.5 to 0.12.6.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.5...0.12.6)

---
updated-dependencies:
- dependency-name: uv-build
  dependency-version: 0.12.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github

dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants