Commit 72fb4e1
authored
chore(deps): update astral-sh/setup-uv action to v10 (#369)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v9.0.0` → `v10.0.0` |
---
### Release Notes
<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>
###
[`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0):
🌈 Disable automatic caching for sensitive events and new QOL features
[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0)
##### Changes
Another breaking release, directly after v9.0.0 but we think the added
security justifies that.
##### Extra security by default
If you use the default `enable-cache: auto` this will now **DISABLE THE
CACHE** to protect against cache poisoning for the following events:
- `pull_request_target`
- `workflow_run`
- `release`
You can read the full reasoning in
[#​984](https://redirect.github.com/astral-sh/setup-uv/issues/984)
##### `version: latest-known`
```yaml
- name: Install the latest version of uv known to setup-uv
uses: astral-sh/setup-uv@v10.0.0
with:
version: "latest-known"
```
This will now install the latest version with a checksum that is known
by this action. The [known `uv`
checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts)
are automatically updated but will take a release of this action to take
effect. You won't be always using the latest & greatest but you will
have an extra level of security.
##### Read python version from `.tool-versions`
```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
uses: astral-sh/setup-uv@v10.0.0
with:
version-file: "pyproject.toml"
```
Will now also set the python version if it is defined in
`.tool-versions`. You can read the details [in the
docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)
##### 🚨 Breaking changes
- Disable automatic caching for sensitive events
[@​eifinger](https://redirect.github.com/eifinger)
([#​992](https://redirect.github.com/astral-sh/setup-uv/issues/992))
##### 🐛 Bug fixes
- Reject paths in .tool-versions
[@​eifinger](https://redirect.github.com/eifinger)
([#​1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007))
##### 🚀 Enhancements
- Read Python version from .tool-versions
[@​eifinger](https://redirect.github.com/eifinger)
([#​996](https://redirect.github.com/astral-sh/setup-uv/issues/996))
- Add latest-known version selector
[@​eifinger](https://redirect.github.com/eifinger)
([#​993](https://redirect.github.com/astral-sh/setup-uv/issues/993))
##### 🧰 Maintenance
- Require pull requests for Dependabot rollups
[@​eifinger](https://redirect.github.com/eifinger)
([#​1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005))
- ci: pin Alpine container image
[@​eifinger](https://redirect.github.com/eifinger)
([#​995](https://redirect.github.com/astral-sh/setup-uv/issues/995))
- chore: update known checksums for 0.12.3
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​991](https://redirect.github.com/astral-sh/setup-uv/issues/991))
- chore: update known checksums for 0.12.2
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​985](https://redirect.github.com/astral-sh/setup-uv/issues/985))
- chore: update known checksums for 0.12.1
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​982](https://redirect.github.com/astral-sh/setup-uv/issues/982))
- chore: update known checksums for 0.12.0
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​981](https://redirect.github.com/astral-sh/setup-uv/issues/981))
- chore: update known checksums for 0.11.31/0.11.32
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​972](https://redirect.github.com/astral-sh/setup-uv/issues/972))
##### 📚 Documentation
- docs: update version references to v9.0.0
@​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#​971](https://redirect.github.com/astral-sh/setup-uv/issues/971))
##### ⬆️ Dependency updates
- chore(deps): roll up Dependabot updates
[@​eifinger](https://redirect.github.com/eifinger)
([#​1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013))
- chore(deps): roll up Dependabot updates
[@​eifinger](https://redirect.github.com/eifinger)
([#​1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004))
- chore(deps): roll up Dependabot updates
[@​eifinger](https://redirect.github.com/eifinger)
([#​994](https://redirect.github.com/astral-sh/setup-uv/issues/994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0
@​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
([#​976](https://redirect.github.com/astral-sh/setup-uv/issues/976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
@​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
([#​980](https://redirect.github.com/astral-sh/setup-uv/issues/980))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 909a4b5 commit 72fb4e1
5 files changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
0 commit comments