Skip to content

ci: bump astral-sh/setup-uv from 9.0.0 to 10.0.1 - #82

Open
dependabot[bot] wants to merge 1 commit into
integrationfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1
Open

ci: bump astral-sh/setup-uv from 9.0.0 to 10.0.1#82
dependabot[bot] wants to merge 1 commit into
integrationfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown

Bumps astral-sh/setup-uv from 9.0.0 to 10.0.1.

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.0.1 🌈 Tolerate transient manifest timeouts

Changes

Thank you @​arguile- for making this action more resilient.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in astral-sh/setup-uv#984

version: latest-known

- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions

- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions github-actions Bot added the status:needs-triage Not yet triaged. Applied by the issue forms label Sep 10, 2026
@github-actions

Copy link
Copy Markdown

Thanks for this. It is queued rather than ignored.

This pull request does not reference an issue carrying status:accepted, so a maintainer has not looked at it yet and will not until the underlying issue is triaged. Nothing here is rejected. See Current Priority Scope for what the project is working on, and help wanted for work that is already accepted.

If this is an editorial correction, tick that box in the description and this comment stops applying.

@rocklambros
rocklambros changed the base branch from main to integration September 10, 2026 13:53
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@c771a70...20cfd1b)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-10.0.1 branch from 671e849 to b2cc87c Compare September 10, 2026 13:54
@rocklambros rocklambros moved this to In progress in ACS Project Tracker Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file status:needs-triage Not yet triaged. Applied by the issue forms

Projects

Status: In progress

Development

Successfully merging this pull request may close these issues.

1 participant