Skip to content

chore(deps): update astral-sh/setup-uv action to v10 - #101

Open
kognic-renovate[bot] wants to merge 1 commit into
masterfrom
renovate/astral-sh-setup-uv-10.x
Open

chore(deps): update astral-sh/setup-uv action to v10#101
kognic-renovate[bot] wants to merge 1 commit into
masterfrom
renovate/astral-sh-setup-uv-10.x

Conversation

@kognic-renovate

@kognic-renovate kognic-renovate Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
astral-sh/setup-uv action major v9.0.0v10.0.1

Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v10.0.1: 🌈 Tolerate transient manifest timeouts

Compare Source

Changes

Thank you @​arguile- for making this action more resilient.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v10.0.0: 🌈 Disable automatic caching for sensitive events and new QOL features

Compare Source

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in #​984

version: latest-known
- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions
- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"

Will now also set the python version if it is defined in .tool-versions. You can read the details in the docs

🚨 Breaking changes
🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates

Configuration

📅 Schedule: (in timezone Europe/Stockholm)

  • Branch creation
    • "after 09:00 and before 15:00 on monday, tuesday, wednesday and thursday,after 09:00 and before 13:00 on friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@kognic-renovate
kognic-renovate Bot requested a review from a team as a code owner August 20, 2026 07:06
@kognic-renovate kognic-renovate Bot added autoreview Enable the Kognic GitHub App to automatically review and approve the PR if meeting all criteria dependencies Pull requests that update a dependency file labels Aug 20, 2026
@kognic-github-app

kognic-github-app Bot commented Aug 20, 2026

Copy link
Copy Markdown

Agent review approved this PR.

v9.0.0→v10.0.1 of astral-sh/setup-uv. The only breaking change in v10.0.0 is disabling auto-caching for pull_request_target/workflow_run/release events. This workflow explicitly sets enable-cache: true, so the breaking change does not apply. v10.0.1 is a pure bug-fix (transient manifest timeout tolerance). No chatter signals indicating compromise. SHA pin is correct for v10.0.1.

Sources:

Package Ecosystem Source repo Verification
astral-sh/setup-uv oci github.com/astral-sh/setup-uv chatter+changelog

kognic-github-app[bot]
kognic-github-app Bot previously approved these changes Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autoreview Enable the Kognic GitHub App to automatically review and approve the PR if meeting all criteria dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants