Commit cdc4dc8
authored
fix(deps): Update ghcr.io/astral-sh/uv Docker tag to v0.11.17 (#402)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://redirect.github.com/astral-sh/uv) | final | patch | `0.11.8` → `0.11.17` |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/379) for more information.
---
### Release Notes
<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>
### [`v0.11.17`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01117)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.16...0.11.17)
Released on 2026-05-28.
##### Enhancements
- Add a diagnostic for `uv add` with standard library modules ([#​19572](https://redirect.github.com/astral-sh/uv/pull/19572))
- Expose `uv workspace` and its `list` subcommand in help output ([#​19533](https://redirect.github.com/astral-sh/uv/pull/19533))
- Improve the "403 forbidden" hint to suggest `ignore-error-codes` when applicable ([#​19521](https://redirect.github.com/astral-sh/uv/pull/19521))
- Skip direct URL lock freshness checks while offline ([#​19596](https://redirect.github.com/astral-sh/uv/pull/19596))
- Add `import-names` and `import-namespaces` support to `uv-build` ([PEP 794](https://peps.python.org/pep-0794/)) ([#​19380](https://redirect.github.com/astral-sh/uv/pull/19380))
- Add a `--no-editable-package` flag to various commands ([#​19584](https://redirect.github.com/astral-sh/uv/pull/19584))
- Infer Python version requests from source trees in `uv tool` invocations ([#​19577](https://redirect.github.com/astral-sh/uv/pull/19577))
##### Preview features
- Add module owners to `uv workspace metadata` ([#​19122](https://redirect.github.com/astral-sh/uv/pull/19122))
- Do not allow `uv venv --clear` to remove non-virtual environments ([#​19595](https://redirect.github.com/astral-sh/uv/pull/19595))
##### Bug fixes
- Improve the performance of large entries in `tool.uv.conflicts` ([#​19538](https://redirect.github.com/astral-sh/uv/pull/19538))
- Avoid modifying the parent process' env with `--env-file` in `uv run` ([#​19567](https://redirect.github.com/astral-sh/uv/pull/19567))
- Fix script environment creation for scripts with long filenames ([#​19539](https://redirect.github.com/astral-sh/uv/pull/19539))
- Fix transitive Git archive dependencies in lockfiles ([#​19589](https://redirect.github.com/astral-sh/uv/pull/19589))
- Preserve Git repository URLs in direct URL metadata ([#​19590](https://redirect.github.com/astral-sh/uv/pull/19590))
- Support redirects in `--check-url` ([#​19594](https://redirect.github.com/astral-sh/uv/pull/19594))
- Accept case-insensitive HTML tags in `--find-links` parsing ([#​19537](https://redirect.github.com/astral-sh/uv/pull/19537))
- Reject duplicate script metadata blocks ([#​19544](https://redirect.github.com/astral-sh/uv/pull/19544))
- Ban names like "python3" as script entry points ([#​19535](https://redirect.github.com/astral-sh/uv/pull/19535), [#​19536](https://redirect.github.com/astral-sh/uv/pull/19536))
- Validate Git LFS artifacts for Git archives ([#​19592](https://redirect.github.com/astral-sh/uv/pull/19592))
- Use a relative path when creating symlinks in cache to improve relocatability ([#​19033](https://redirect.github.com/astral-sh/uv/pull/19033))
##### Documentation
- Fix malformed positional anchors in the CLI reference ([#​19575](https://redirect.github.com/astral-sh/uv/pull/19575))
### [`v0.11.16`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01116)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.15...0.11.16)
Released on 2026-05-21.
##### Enhancements
- Add support for direct archive dependencies in Git ([#​10072](https://redirect.github.com/astral-sh/uv/pull/10072))
- Adjust hint rendering ([#​18090](https://redirect.github.com/astral-sh/uv/pull/18090))
##### Preview features
- uv audit: specialize malformed OSV error ([#​19515](https://redirect.github.com/astral-sh/uv/pull/19515))
- Reject locked malware installations ([#​18936](https://redirect.github.com/astral-sh/uv/pull/18936))
##### Configuration
- Allow disabling reading the system config with `UV_NO_SYSTEM_CONFIG` ([#​19476](https://redirect.github.com/astral-sh/uv/pull/19476))
##### Bug fixes
- Allow environment variables that take a list to be empty ([#​19503](https://redirect.github.com/astral-sh/uv/pull/19503))
- Ensure that incompatible wheel hints do not leak secrets ([#​19504](https://redirect.github.com/astral-sh/uv/pull/19504))
- Reject unsafe entry points in `uv-build` ([#​19495](https://redirect.github.com/astral-sh/uv/pull/19495))
- Restrict delimiters in entry point parsing ([#​19471](https://redirect.github.com/astral-sh/uv/pull/19471))
- uv-netrc: fix multi-word no-space comment lines causing parse errors ([#​19494](https://redirect.github.com/astral-sh/uv/pull/19494))
##### Documentation
- Document and test relative exclude-newer support for uv pip ([#​19475](https://redirect.github.com/astral-sh/uv/pull/19475))
### [`v0.11.15`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01115)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.14...0.11.15)
Released on 2026-05-18.
##### Security
- Fix a TAR parser differential, see [GHSA-3cv2-h65g-fgmm](https://redirect.github.com/astral-sh/tokio-tar/security/advisories/GHSA-3cv2-h65g-fgmm) ([#​19463](https://redirect.github.com/astral-sh/uv/pull/19463))
- Enforce that entry points cannot escape in the scripts directory, see [GHSA-4gg8-gxpx-9rph](https://redirect.github.com/astral-sh/uv/security/advisories/GHSA-4gg8-gxpx-9rph) ([#​19464](https://redirect.github.com/astral-sh/uv/pull/19464))
##### Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions ([#​18741](https://redirect.github.com/astral-sh/uv/pull/18741))
- Add support for Azure request signing ([#​19421](https://redirect.github.com/astral-sh/uv/pull/19421))
- Apply stricter validation to all wheel filename segments ([#​19364](https://redirect.github.com/astral-sh/uv/pull/19364))
- Reject empty strings as an invalid package name ([#​19435](https://redirect.github.com/astral-sh/uv/pull/19435))
- Use structured errors for signing authentication failures ([#​19422](https://redirect.github.com/astral-sh/uv/pull/19422))
##### Preview
- uv audit: Add JSON output ([#​19305](https://redirect.github.com/astral-sh/uv/pull/19305))
##### Configuration
- Respect `required-environments` in `uv pip compile` ([#​19378](https://redirect.github.com/astral-sh/uv/pull/19378))
##### Performance
- Avoid parsing JSON manifest when local Python is available ([#​19398](https://redirect.github.com/astral-sh/uv/pull/19398))
- Avoid walking nested directories in linker conflict registration ([#​19382](https://redirect.github.com/astral-sh/uv/pull/19382))
- Optimize async wheel ZIP writing ([#​19383](https://redirect.github.com/astral-sh/uv/pull/19383))
- Fix dead "already trimmed" fast-path in `Version::only_release_trimmed` ([#​19425](https://redirect.github.com/astral-sh/uv/pull/19425))
##### Bug fixes
- Apply workspace-member `[tool.uv.sources]` credentials under `uv sync --frozen` ([#​19423](https://redirect.github.com/astral-sh/uv/pull/19423))
- Skip empty directories in uv build outputs ([#​19437](https://redirect.github.com/astral-sh/uv/pull/19437))
- Fix Git submodule handling when using relative paths ([#​12156](https://redirect.github.com/astral-sh/uv/pull/12156))
- Fix line number reporting in netrc parsing ([#​19452](https://redirect.github.com/astral-sh/uv/pull/19452))
##### Documentation
- Move Bazel auth helper setup into integration guide ([#​19392](https://redirect.github.com/astral-sh/uv/pull/19392))
### [`v0.11.14`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01114)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.13...0.11.14)
Released on 2026-05-12.
##### Enhancements
- Add Astral mirror URL override ([#​19206](https://redirect.github.com/astral-sh/uv/pull/19206))
- Ignore `top_level.txt` entries in uninstall that are not valid Python identifiers ([#​19340](https://redirect.github.com/astral-sh/uv/pull/19340))
##### Bug fixes
- Avoid applying `.env` files in parent process ([#​19343](https://redirect.github.com/astral-sh/uv/pull/19343))
- Filter ANSI codes in logging output ([#​19311](https://redirect.github.com/astral-sh/uv/pull/19311))
- Fix `uv tree` showing extra-conditional deps for packages required without extras ([#​19332](https://redirect.github.com/astral-sh/uv/pull/19332))
- Respect build options (e.g., `--no-build`) during lock validation ([#​19366](https://redirect.github.com/astral-sh/uv/pull/19366))
### [`v0.11.13`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01113)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.12...0.11.13)
Released on 2026-05-10.
##### Bug fixes
- Include data files in editable builds ([#​19312](https://redirect.github.com/astral-sh/uv/pull/19312))
- Respect `--require-hashes` when installing from `pylock.toml` files ([#​19334](https://redirect.github.com/astral-sh/uv/pull/19334))
##### Python
##### Python
- Add CPython 3.14.5
### [`v0.11.12`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01112)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.11...0.11.12)
Released on 2026-05-08.
##### Python
- Add CPython 3.15.0b1
##### Enhancements
- Add `--no-editable` support to `uv pip install` ([#​19306](https://redirect.github.com/astral-sh/uv/pull/19306))
- Require git refs in URLs to be percent-encoded ([#​19320](https://redirect.github.com/astral-sh/uv/pull/19320))
##### Bug fixes
- Respect `--no-dev` over `UV_DEV=1` ([#​19313](https://redirect.github.com/astral-sh/uv/pull/19313))
- Don't suggest non-existent `--no-frozen` flag ([#​19290](https://redirect.github.com/astral-sh/uv/issues/19290)) ([#​19294](https://redirect.github.com/astral-sh/uv/pull/19294))
##### Documentation
- Fix bug from inconsistent workflow name in GHA-PyPI guide example ([#​19309](https://redirect.github.com/astral-sh/uv/pull/19309))
### [`v0.11.11`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01111)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.10...0.11.11)
Released on 2026-05-06.
##### Bug fixes
- Accept legacy ID format from pre-0.11.9 cache entries ([#​19301](https://redirect.github.com/astral-sh/uv/pull/19301))
### [`v0.11.10`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01110)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.9...0.11.10)
Released on 2026-05-05.
##### Bug fixes
- Allow pre-release Python requests with non-zero patch versions ([#​19286](https://redirect.github.com/astral-sh/uv/pull/19286))
### [`v0.11.9`](https://redirect.github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0119)
[Compare Source](https://redirect.github.com/astral-sh/uv/compare/0.11.8...0.11.9)
Released on 2026-05-04.
This release includes a special release candidate for the next Python 3.14 patch release. Python 3.14 included a new garbage collection implementation, which reduced pause times but caused significant unexpected memory pressure in production environments. In 3.14.5 and 3.15, the previous garbage collection implementation will be restored.
We would greatly appreciate if you tested the 3.14.5rc1 version included in this release. The stable version is expected to be released soon and any feedback on potential issues would be helpful to the Python development team.
For more context, see the [announcement](https://discuss.python.org/t/reverting-the-incremental-gc-in-python-3-14-and-3-15/107014), [issue](https://redirect.github.com/python/cpython/issues/148726), and [pull request](https://redirect.github.com/python/cpython/pull/148720).
Issues with the new release can be reported in the uv or CPython issue trackers.
##### Python
- Upgrade PyPy to v7.3.22
- Add CPython 3.14.5rc1
- On macOS, CPython statically links `libpython` to match Linux
##### Enhancements
- Omit compatible release desugaring for pre-release hints ([#​19267](https://redirect.github.com/astral-sh/uv/pull/19267))
- Fix file locks on Android ([#​18323](https://redirect.github.com/astral-sh/uv/pull/18323))
##### Preview
- `uv audit` add reporting for adverse project statuses ([#​19128](https://redirect.github.com/astral-sh/uv/pull/19128))
##### Bug fixes
- Discover versioned Python executables when `requires-python` pins a version ([#​18700](https://redirect.github.com/astral-sh/uv/pull/18700))
- Fix URL prefix matching to require path boundaries ([#​19154](https://redirect.github.com/astral-sh/uv/pull/19154))
- Fix transitive Git path dependencies in lockfiles ([#​19269](https://redirect.github.com/astral-sh/uv/pull/19269))
- Handle incorrect unlock error in `LockedFile::drop` on Wine ([#​19229](https://redirect.github.com/astral-sh/uv/pull/19229))
- Prevent uninstalling site-packages for empty `top_level.txt` in `.egg-info` ([#​19114](https://redirect.github.com/astral-sh/uv/pull/19114))
- Use symlinks instead of junctions on Wine ([#​19213](https://redirect.github.com/astral-sh/uv/pull/19213))
- Fix floating-point environment handling on ARMv7 ([#​19157](https://redirect.github.com/astral-sh/uv/pull/19157))
- Redact credentials from remote requirements URL in offline errors ([#​19216](https://redirect.github.com/astral-sh/uv/pull/19216))
- Windows tramplolines no longer set `PYTHONHOME` and only set `__PYVENV_LAUNCHER__` for virtual environments ([#​19199](https://redirect.github.com/astral-sh/uv/pull/19199))
##### Documentation
- Mark `--native-tls` and `UV_NATIVE_TLS` as deprecated ([#​18705](https://redirect.github.com/astral-sh/uv/pull/18705))
- Re-add `pytorch-triton-rocm` to PyTorch ROCm docs ([#​19241](https://redirect.github.com/astral-sh/uv/pull/19241))
- Tweak changelog entries for 0.11.8 ([#​19188](https://redirect.github.com/astral-sh/uv/pull/19188))
- Add 'Exporting lockfiles' to the Concepts->Projects index ([#​19209](https://redirect.github.com/astral-sh/uv/pull/19209))
- Clarify that `uv init` creates git files / folders in the projects guide ([#​19183](https://redirect.github.com/astral-sh/uv/pull/19183))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, on day 1 of the month (`* 0-3 1 * *`)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE0MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhdXRvbWVyZ2UiXX0=-->1 parent 757c407 commit cdc4dc8
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
0 commit comments