← Back to issue list

build(deps): update astral-sh/setup-uv action to v10 (main) - autoclosed

View original Github issue

Metadata

Project
craft-grammar
Number
#214
Type
pull request
State
merged
Author
renovate[bot]
Labels
PR: Dependencies
Created
Updated
Closed

Current evaluation

Merged into main after passing CI and two approvals. Updates astral-sh/setup-uv from v9.0.0 to v10.0.1, adding security hardening, a latest-known version selector, and disabling automatic caching for sensitive events.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.1` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v10.0.1`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.1): 🌈 Tolerate transient manifest timeouts [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v10.0.0...v10.0.1) ##### Changes Thank you [@&#8203;arguile-](https://redirect.github.com/arguile-) for making this action more resilient. ##### 🐛 Bug fixes - Tolerate transient manifest timeouts [@&#8203;arguile-](https://redirect.github.com/arguile-) ([#&#8203;1016](https://redirect.github.com/astral-sh/setup-uv/issues/1016)) ##### 🧰 Maintenance - chore: update known checksums for 0.12.4 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;1017](https://redirect.github.com/astral-sh/setup-uv/issues/1017)) ##### 📚 Documentation - docs: update version references to v10.0.0 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;1014](https://redirect.github.com/astral-sh/setup-uv/issues/1014)) ### [`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0) ##### Changes Another breaking release, directly after v9.0.0 but we think the added security justifies that. ##### Extra security by default If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events: - `pull_request_target` - `workflow_run` - `release` You can read the full reasoning in [#&#8203;984](https://redirect.github.com/astral-sh/setup-uv/issues/984) ##### `version: latest-known` ```yaml - name: Install the latest version of uv known to setup-uv uses: astral-sh/setup-uv@v10.0.0 with: version: "latest-known" ``` This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security. ##### Read python version from `.tool-versions` ```yaml - name: Install uv based on the version defined in .tool-versions and also set python uses: astral-sh/setup-uv@v10.0.0 with: version-file: "pyproject.toml" ``` Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file) ##### 🚨 Breaking changes - Disable automatic caching for sensitive events [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;992](https://redirect.github.com/astral-sh/setup-uv/issues/992)) ##### 🐛 Bug fixes - Reject paths in .tool-versions [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007)) ##### 🚀 Enhancements - Read Python version from .tool-versions [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;996](https://redirect.github.com/astral-sh/setup-uv/issues/996)) - Add latest-known version selector [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;993](https://redirect.github.com/astral-sh/setup-uv/issues/993)) ##### 🧰 Maintenance - Require pull requests for Dependabot rollups [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005)) - ci: pin Alpine container image [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;995](https://redirect.github.com/astral-sh/setup-uv/issues/995)) - chore: update known checksums for 0.12.3 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;991](https://redirect.github.com/astral-sh/setup-uv/issues/991)) - chore: update known checksums for 0.12.2 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;985](https://redirect.github.com/astral-sh/setup-uv/issues/985)) - chore: update known checksums for 0.12.1 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;982](https://redirect.github.com/astral-sh/setup-uv/issues/982)) - chore: update known checksums for 0.12.0 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;981](https://redirect.github.com/astral-sh/setup-uv/issues/981)) - chore: update known checksums for 0.11.31/0.11.32 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;972](https://redirect.github.com/astral-sh/setup-uv/issues/972)) ##### 📚 Documentation - docs: update version references to v9.0.0 @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#&#8203;971](https://redirect.github.com/astral-sh/setup-uv/issues/971)) ##### ⬆️ Dependency updates - chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013)) - chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004)) - chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://redirect.github.com/eifinger) ([#&#8203;994](https://redirect.github.com/astral-sh/setup-uv/issues/994)) - chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#&#8203;976](https://redirect.github.com/astral-sh/setup-uv/issues/976)) - chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#&#8203;980](https://redirect.github.com/astral-sh/setup-uv/issues/980)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Etc/UTC) - Branch creation - "every weekend" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/craft-grammar). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUFI6IERlcGVuZGVuY2llcyJdfQ==-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged into main after passing CI and two approvals. Updates astral-sh/setup-uv from v9.0.0 to v10.0.1, adding security hardening, a latest-known version selector, and disabling automatic caching for sensitive events.
qwen/qwen3.6-35b-a3b
Staleness: 0
Complexity: 5
Confidence: 95
needs review Updates astral-sh/setup-uv GitHub Action from v9 to v10.0.1. Includes breaking changes disabling cache for sensitive events and new features. Currently passing CI, awaiting maintainer review, with automerge enabled.

Update history

Date Change
updated
created

Related issues

Issue Project State Summary Similarity
#413 build(deps): update astral-sh/setup-uv action to v10 (main) craft-store closed Closed without merging. The dependency update was abandoned, and Renovate will ignore all future 10.x releases for this repository.
83%
#82 build(deps): update astral-sh/setup-uv action to v8 (main) craft-artifacts merged Merged automated dependency update upgrading astral-sh/setup-uv action from v7 to v8.1.0. Approved by reviewers, passed CI checks, and automatically merged into main by Renovate.
83%
#417 build(deps): update setup-uv action to v10 craft-store merged Merged upgrade of the setup-uv GitHub Action to v10. Supersedes PR #413 by resolving zizmor security audit warnings. Approved by two reviewers and passed CI checks prior to merge.
81%
#43 build(deps): update astral-sh/setup-uv action to v7 craft-artifacts merged Merged an automated dependency update upgrading the astral-sh/setup-uv GitHub Action from v6 to v7. Approved by two reviewers, all CI checks passed, and the change was automatically merged into the main branch.
81%
#92 build(deps): update github actions to v8.2.0 (main) craft-artifacts merged Merged automated dependency update upgrading astral-sh/setup-uv GitHub Action from v8.1.0 to v8.2.0. Approved by two reviewers, cleared CI checks, and applied to main via Renovate automerge.
73%
#2062 build(deps): update github actions (main) (major) charmcraft merged Merged automated GitHub Actions dependency updates. Renovate bot upgraded astral-sh/setup-uv to v5 and the Ubuntu runner to 24.04. Changes passed CI, received approvals, and were successfully merged.
72%
#2290 build(deps): update github actions (main) (major) charmcraft merged Merged an automated dependency update by Renovate bot. Updated astral-sh/setup-uv to v6 and Node.js to v22 in GitHub Actions. Approved and automerged after CI checks passed.
71%