Skip to content

build(deps): bump the pinned-runtime-dependencies group with 2 updates - #863

Merged
jku merged 1 commit into
mainfrom
dependabot/uv/pinned-runtime-dependencies-f9b9d29f61
Oct 6, 2026
Merged

jku merged 1 commit into
mainfrom
dependabot/uv/pinned-runtime-dependencies-f9b9d29f61

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the pinned-runtime-dependencies group with 2 updates: uv and platformdirs.

Updates uv from 0.12.17 to 0.12.19

Release notes

Sourced from uv's releases.

0.12.19

Release Notes

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

  • Format upload URLs with backticks in uv publish errors (#21934)

Preview features

  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#21913)

Bug fixes

  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#21891)
  • Preserve always-false python_version markers when parsing their serialized form (#21939)

Rust API

  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#21965)

Documentation

  • Make individual preview-feature reference entries linkable by name (#21950)

Install uv 0.12.19

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1 | iex"

Download uv 0.12.19

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.19

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

  • Format upload URLs with backticks in uv publish errors (#21934)

Preview features

  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#21913)

Bug fixes

  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#21891)
  • Preserve always-false python_version markers when parsing their serialized form (#21939)

Rust API

  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#21965)

Documentation

  • Make individual preview-feature reference entries linkable by name (#21950)

0.12.18

Released on 2026-09-22.

This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.

Enhancements

  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#21881)

Preview features

  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#21880)

Performance

... (truncated)

Commits

Updates platformdirs from 4.11.11 to 4.12.1

Release notes

Sourced from platformdirs's releases.

4.12.1

What's Changed

Full Changelog: tox-dev/platformdirs@4.12.0...4.12.1

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.14...4.11.15

4.11.14

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.3 (2026-10-03)


  • Place files from place_config_file and place_data_file in the first site directory for root on Unix with use_site_for_root=True and multipath=True, where find_config_file and find_data_file look for them. :pr:607

4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600

... (truncated)

Commits
  • 0a50795 Release 4.12.1
  • 72e93ff fix(pytest): allow import before pytest startup (#602)
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • c34e758 🐛 fix(dirs): create user directories with mode 0700 (#588)
  • f88693c ✨ feat(api): add find_*_file methods for user and site lookup (#586)
  • ba1cc1e 🐛 fix(windows): resolve templates, public and bin dirs by known folder (#587)
  • 9f2ee08 ✨ feat(testing): redirect every directory under a test root (#590)
  • dfaeabf ✨ feat(api): add place_*_file methods that create parents as 0700 (#585)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the pinned-runtime-dependencies group with 2 updates: [uv](https://github.com/astral-sh/uv) and [platformdirs](https://github.com/tox-dev/platformdirs).


Updates `uv` from 0.12.17 to 0.12.19
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.17...0.12.19)

Updates `platformdirs` from 4.11.11 to 4.12.1
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.11...4.12.1)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.19
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: pinned-runtime-dependencies
- dependency-name: platformdirs
  dependency-version: 4.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pinned-runtime-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
@jku
jku merged commit 8931640 into main Oct 6, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/pinned-runtime-dependencies-f9b9d29f61 branch October 6, 2026 08:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant