build(deps): update astral-sh/setup-uv action to v10 (main) - autoclosed
Metadata
Current evaluation
Merged into main after passing CI and two approvals. Updates astral-sh/setup-uv from v9.0.0 to v10.0.1, adding security hardening, a latest-known version selector, and disabling automatic caching for sensitive events.
Suggested action: —
No scores available.
Issue body
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.1` |
---
### Release Notes
<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>
### [`v10.0.1`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.1): 🌈 Tolerate transient manifest timeouts
[Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v10.0.0...v10.0.1)
##### Changes
Thank you [@​arguile-](https://redirect.github.com/arguile-) for making this action more resilient.
##### 🐛 Bug fixes
- Tolerate transient manifest timeouts [@​arguile-](https://redirect.github.com/arguile-) ([#​1016](https://redirect.github.com/astral-sh/setup-uv/issues/1016))
##### 🧰 Maintenance
- chore: update known checksums for 0.12.4 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​1017](https://redirect.github.com/astral-sh/setup-uv/issues/1017))
##### 📚 Documentation
- docs: update version references to v10.0.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​1014](https://redirect.github.com/astral-sh/setup-uv/issues/1014))
### [`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features
[Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0)
##### Changes
Another breaking release, directly after v9.0.0 but we think the added security justifies that.
##### Extra security by default
If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events:
- `pull_request_target`
- `workflow_run`
- `release`
You can read the full reasoning in [#​984](https://redirect.github.com/astral-sh/setup-uv/issues/984)
##### `version: latest-known`
```yaml
- name: Install the latest version of uv known to setup-uv
uses: astral-sh/setup-uv@v10.0.0
with:
version: "latest-known"
```
This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.
##### Read python version from `.tool-versions`
```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
uses: astral-sh/setup-uv@v10.0.0
with:
version-file: "pyproject.toml"
```
Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)
##### 🚨 Breaking changes
- Disable automatic caching for sensitive events [@​eifinger](https://redirect.github.com/eifinger) ([#​992](https://redirect.github.com/astral-sh/setup-uv/issues/992))
##### 🐛 Bug fixes
- Reject paths in .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007))
##### 🚀 Enhancements
- Read Python version from .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​996](https://redirect.github.com/astral-sh/setup-uv/issues/996))
- Add latest-known version selector [@​eifinger](https://redirect.github.com/eifinger) ([#​993](https://redirect.github.com/astral-sh/setup-uv/issues/993))
##### 🧰 Maintenance
- Require pull requests for Dependabot rollups [@​eifinger](https://redirect.github.com/eifinger) ([#​1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005))
- ci: pin Alpine container image [@​eifinger](https://redirect.github.com/eifinger) ([#​995](https://redirect.github.com/astral-sh/setup-uv/issues/995))
- chore: update known checksums for 0.12.3 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​991](https://redirect.github.com/astral-sh/setup-uv/issues/991))
- chore: update known checksums for 0.12.2 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​985](https://redirect.github.com/astral-sh/setup-uv/issues/985))
- chore: update known checksums for 0.12.1 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​982](https://redirect.github.com/astral-sh/setup-uv/issues/982))
- chore: update known checksums for 0.12.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​981](https://redirect.github.com/astral-sh/setup-uv/issues/981))
- chore: update known checksums for 0.11.31/0.11.32 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​972](https://redirect.github.com/astral-sh/setup-uv/issues/972))
##### 📚 Documentation
- docs: update version references to v9.0.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​971](https://redirect.github.com/astral-sh/setup-uv/issues/971))
##### ⬆️ Dependency updates
- chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013))
- chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004))
- chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​994](https://redirect.github.com/astral-sh/setup-uv/issues/994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​976](https://redirect.github.com/astral-sh/setup-uv/issues/976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​980](https://redirect.github.com/astral-sh/setup-uv/issues/980))
</details>
---
### Configuration
📅 **Schedule**: (in timezone Etc/UTC)
- Branch creation
- "every weekend"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/craft-grammar).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUFI6IERlcGVuZGVuY2llcyJdfQ==-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged into main after passing CI and two approvals. Updates astral-sh/setup-uv from v9.0.0 to v10.0.1, adding security hardening, a latest-known version selector, and disabling automatic caching for sensitive events. | |
| qwen/qwen3.6-35b-a3b |
Staleness:
0
Complexity:
5
Confidence:
95
|
needs review | Updates astral-sh/setup-uv GitHub Action from v9 to v10.0.1. Includes breaking changes disabling cache for sensitive events and new features. Currently passing CI, awaiting maintainer review, with automerge enabled. |
Update history
| Date | Change |
|---|---|
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #413 build(deps): update astral-sh/setup-uv action to v10 (main) | craft-store | closed | Closed without merging. The dependency update was abandoned, and Renovate will ignore all future 10.x releases for this repository. | |
| #82 build(deps): update astral-sh/setup-uv action to v8 (main) | craft-artifacts | merged | Merged automated dependency update upgrading astral-sh/setup-uv action from v7 to v8.1.0. Approved by reviewers, passed CI checks, and automatically merged into main by Renovate. | |
| #417 build(deps): update setup-uv action to v10 | craft-store | merged | Merged upgrade of the setup-uv GitHub Action to v10. Supersedes PR #413 by resolving zizmor security audit warnings. Approved by two reviewers and passed CI checks prior to merge. | |
| #43 build(deps): update astral-sh/setup-uv action to v7 | craft-artifacts | merged | Merged an automated dependency update upgrading the astral-sh/setup-uv GitHub Action from v6 to v7. Approved by two reviewers, all CI checks passed, and the change was automatically merged into the main branch. | |
| #92 build(deps): update github actions to v8.2.0 (main) | craft-artifacts | merged | Merged automated dependency update upgrading astral-sh/setup-uv GitHub Action from v8.1.0 to v8.2.0. Approved by two reviewers, cleared CI checks, and applied to main via Renovate automerge. | |
| #2062 build(deps): update github actions (main) (major) | charmcraft | merged | Merged automated GitHub Actions dependency updates. Renovate bot upgraded astral-sh/setup-uv to v5 and the Ubuntu runner to 24.04. Changes passed CI, received approvals, and were successfully merged. | |
| #2290 build(deps): update github actions (main) (major) | charmcraft | merged | Merged an automated dependency update by Renovate bot. Updated astral-sh/setup-uv to v6 and Node.js to v22 in GitHub Actions. Approved and automerged after CI checks passed. |