Skip to content

chore(deps): bump uv from 0.10.7 to 0.10.8#372

Merged
mergify[bot] merged 1 commit intomainfrom
dependabot/pip/uv-0.10.8
Mar 4, 2026
Merged

chore(deps): bump uv from 0.10.7 to 0.10.8#372
mergify[bot] merged 1 commit intomainfrom
dependabot/pip/uv-0.10.8

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 4, 2026

Bumps uv from 0.10.7 to 0.10.8.

Release notes

Sourced from uv's releases.

0.10.8

Release Notes

Released on 2026-03-03.

Python

  • Add CPython 3.10.20
  • Add CPython 3.11.15
  • Add CPython 3.12.13

Enhancements

  • Add Docker images based on Docker Hardened Images (#18247)
  • Add resolver hint when --exclude-newer filters out all versions of a package (#18217)
  • Configure a real retry minimum delay of 1s (#18201)
  • Expand uv_build direct build compatibility (#17902)
  • Fetch CPython from an Astral mirror by default (#18207)
  • Download uv releases from an Astral mirror in installers by default (#18191)
  • Add SBOM attestations to Docker images (#18252)
  • Improve hint for installing meson-python when missing as build backend (#15826)

Configuration

  • Add UV_INIT_BARE environment variable for uv init (#18210)

Bug fixes

  • Prevent uv tool upgrade from installing excluded dependencies (#18022)
  • Promote authentication policy when saving tool receipts (#18246)
  • Respect exclusions in scripts (#18269)
  • Retain default-branch Git SHAs in pylock.toml files (#18227)
  • Skip installed Python check for URL dependencies (#18211)
  • Respect constraints during --upgrade (#18226)
  • Fix uv tree orphaned roots and premature deduplication (#17212)

Documentation

  • Mention cooldown and tweak inline script metadata in dependency bots documentation (#18230)
  • Move cache prune in GitLab to after_script (#18206)

Install uv 0.10.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.sh | sh

Install prebuilt binaries via powershell script

... (truncated)

Changelog

Sourced from uv's changelog.

0.10.8

Released on 2026-03-03.

Python

  • Add CPython 3.10.20
  • Add CPython 3.11.15
  • Add CPython 3.12.13

Enhancements

  • Add Docker images based on Docker Hardened Images (#18247)
  • Add resolver hint when --exclude-newer filters out all versions of a package (#18217)
  • Configure a real retry minimum delay of 1s (#18201)
  • Expand uv_build direct build compatibility (#17902)
  • Fetch CPython from an Astral mirror by default (#18207)
  • Download uv releases from an Astral mirror in installers by default (#18191)
  • Add SBOM attestations to Docker images (#18252)
  • Improve hint for installing meson-python when missing as build backend (#15826)

Configuration

  • Add UV_INIT_BARE environment variable for uv init (#18210)

Bug fixes

  • Prevent uv tool upgrade from installing excluded dependencies (#18022)
  • Promote authentication policy when saving tool receipts (#18246)
  • Respect exclusions in scripts (#18269)
  • Retain default-branch Git SHAs in pylock.toml files (#18227)
  • Skip installed Python check for URL dependencies (#18211)
  • Respect constraints during --upgrade (#18226)
  • Fix uv tree orphaned roots and premature deduplication (#17212)

Documentation

  • Mention cooldown and tweak inline script metadata in dependency bots documentation (#18230)
  • Move cache prune in GitLab to after_script (#18206)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uv](https://github.com/astral-sh/uv) from 0.10.7 to 0.10.8.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.10.7...0.10.8)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.10.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Mar 4, 2026
@mergify mergify bot deployed to Mergify Merge Protections March 4, 2026 08:09 Active
@mergify
Copy link

mergify bot commented Mar 4, 2026

Merge Protections

Your pull request matches the following merge protections and will not be merged until they are valid.

🟢 Continuous Integration

Wonderful, this rule succeeded.
  • all of:
    • check-success = test (3.10)
    • check-success = test (3.11)
    • check-success = test (3.12)
    • check-success = test (3.13)
    • check-success = test (3.8)
    • check-success = test (3.9)

🟢 Enforce conventional commit

Wonderful, this rule succeeded.

Make sure that we follow https://www.conventionalcommits.org/en/v1.0.0/

  • title ~= ^(fix|feat|docs|style|refactor|perf|test|build|ci|chore|revert)(?:\(.+\))?:

🟢 🔎 Reviews

Wonderful, this rule succeeded.
  • #changes-requested-reviews-by = 0
  • #review-requested = 0
  • #review-threads-unresolved = 0

🟢 📕 PR description

Wonderful, this rule succeeded.
  • body ~= (?ms:.{48,})

@mergify
Copy link

mergify bot commented Mar 4, 2026

🧪 CI Insights

Here's what we observed from your CI run for 3cc86b2.

🟢 All jobs passed!

But CI Insights is watching 👀

@mergify mergify bot merged commit 3fc6a5e into main Mar 4, 2026
9 checks passed
@mergify mergify bot deleted the dependabot/pip/uv-0.10.8 branch March 4, 2026 08:10
@mergify
Copy link

mergify bot commented Mar 4, 2026

Merge Queue Status

Rule: default


  • Entered queue2026-03-04 08:10 UTC
  • Checks passed · in-place
  • Merged2026-03-04 08:10 UTC · at 3cc86b24d5e9c746832f0b0d1c6bd9e471a290bf

This pull request spent 8 seconds in the queue, with no time running CI.

Required conditions to merge

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Development

Successfully merging this pull request may close these issues.

0 participants