Skip to content

Python: Chore(deps-dev): Bump uv from 0.12.5 to 0.12.6 in /python - #8038

Merged
Eduard van Valkenburg (eavanvalkenburg) merged 2 commits into
mainfrom
dependabot/pip/python/uv-0.12.6
Sep 4, 2026
Merged

Python: Chore(deps-dev): Bump uv from 0.12.5 to 0.12.6 in /python#8038
Eduard van Valkenburg (eavanvalkenburg) merged 2 commits into
mainfrom
dependabot/pip/python/uv-0.12.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps uv from 0.12.5 to 0.12.6.

Release notes

Sourced from uv's releases.

0.12.6

Release Notes

Released on 2026-08-25.

Python

  • Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #21295)

Enhancements

  • Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links (#21261)
  • Limit warnings about unbounded uv_build requirements to source-distribution builds (#21078)
  • Display byte counts below 1 KiB without a fractional part (#21237)

Preview features

  • Add uv workspace metadata --sync --exact to remove packages outside the selected resolution (#21117)
  • Add the artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#21235)
  • Respect package-specific exclude-newer cutoffs when uv check selects its ty executable (#21227)
  • Preserve virtual-environment hints from tar-codec source-distribution errors when the base interpreter is outside a bin directory (#21146)

Performance

  • Enable profile-guided optimization for Linux x86-64 release binaries (#21001)
  • Enable profile-guided optimization for Windows x86-64 release binaries (#21003)
  • Enable profile-guided optimization for macOS ARM64 release binaries (#21002)
  • Enable profile-guided optimization for Linux ARM64 release binaries (#21004)
  • Speed up syncing projects with many activated conflict items by reusing their encoded representation (#21148)

Bug fixes

  • Allow explicit uv build and non-editable first-party workspace packages when no-build is enabled (#21294)
  • Reuse configured index credentials during uv tool upgrade when the tool receipt references the same index (#21275)
  • Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch (#21224)
  • Prevent TLS segfaults in riscv64 musl release binaries (#21158)
  • Preserve dependencies selected by recursive extras when markers mix production and extra conditions (#21181)
  • Preserve version constraints from transitively referenced recursive extras (#21209)
  • Resolve repository-relative Git archive dependencies inside the checkout during the initial uv sync (#21264)
  • Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header (#21282)
  • Do not misclassify package URLs ending in .py as local script paths (#21144)
  • Use directory creation times consistently across libc implementations for directory cache-keys entries (#21137)
  • Promote human-readable sizes to the next unit at rounding boundaries (#21136)

Other changes

  • Add Python 3.15 release-candidate Docker images (#21293)
  • Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 (#21258)

Install uv 0.12.6

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.6

Released on 2026-08-25.

Python

  • Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #21295)

Enhancements

  • Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links (#21261)
  • Limit warnings about unbounded uv_build requirements to source-distribution builds (#21078)
  • Display byte counts below 1 KiB without a fractional part (#21237)

Preview features

  • Add uv workspace metadata --sync --exact to remove packages outside the selected resolution (#21117)
  • Add the artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#21235)
  • Respect package-specific exclude-newer cutoffs when uv check selects its ty executable (#21227)
  • Preserve virtual-environment hints from tar-codec source-distribution errors when the base interpreter is outside a bin directory (#21146)

Performance

  • Enable profile-guided optimization for Linux x86-64 release binaries (#21001)
  • Enable profile-guided optimization for Windows x86-64 release binaries (#21003)
  • Enable profile-guided optimization for macOS ARM64 release binaries (#21002)
  • Enable profile-guided optimization for Linux ARM64 release binaries (#21004)
  • Speed up syncing projects with many activated conflict items by reusing their encoded representation (#21148)

Bug fixes

  • Allow explicit uv build and non-editable first-party workspace packages when no-build is enabled (#21294)
  • Reuse configured index credentials during uv tool upgrade when the tool receipt references the same index (#21275)
  • Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch (#21224)
  • Prevent TLS segfaults in riscv64 musl release binaries (#21158)
  • Preserve dependencies selected by recursive extras when markers mix production and extra conditions (#21181)
  • Preserve version constraints from transitively referenced recursive extras (#21209)
  • Resolve repository-relative Git archive dependencies inside the checkout during the initial uv sync (#21264)
  • Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header (#21282)
  • Do not misclassify package URLs ending in .py as local script paths (#21144)
  • Use directory creation times consistently across libc implementations for directory cache-keys entries (#21137)
  • Promote human-readable sizes to the next unit at rounding boundaries (#21136)

Other changes

  • Add Python 3.15 release-candidate Docker images (#21293)
  • Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 (#21258)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uv](https://github.com/astral-sh/uv) from 0.12.5 to 0.12.6.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.5...0.12.6)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Usage: [Issues, PRs], Target: dependencies in the project python Usage: [Issues, PRs], Target: Python labels Sep 3, 2026
Copilot AI balanced review requested due to automatic review settings September 3, 2026 14:35
@dependabot dependabot Bot added the python Usage: [Issues, PRs], Target: Python label Sep 3, 2026
@dependabot dependabot Bot added the dependencies Usage: [Issues, PRs], Target: dependencies in the project label Sep 3, 2026
@dependabot
dependabot Bot deployed to github-app-auth September 3, 2026 14:35 Active
@github-actions github-actions Bot changed the title Chore(deps-dev): Bump uv from 0.12.5 to 0.12.6 in /python Python: Chore(deps-dev): Bump uv from 0.12.5 to 0.12.6 in /python Sep 3, 2026
@dependabot
dependabot Bot deployed to github-app-auth September 3, 2026 14:35 Active
@dependabot
dependabot Bot deployed to github-app-auth September 3, 2026 14:35 Active
@dependabot
dependabot Bot deployed to github-app-auth September 3, 2026 14:36 Active

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The workspace has conflicting exact uv pins and an outdated lockfile.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Bumps the Python workspace’s pinned uv development dependency from 0.12.5 to 0.12.6.

Changes:

  • Updates the root Python uv dependency pin.
File summaries
File Review
python/pyproject.toml Critical (2 votes): Update the conflicting lab pin and regenerate python/uv.lock.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread python/pyproject.toml
Co-authored-by: eavanvalkenburg <13749212+eavanvalkenburg@users.noreply.github.com>
Copilot AI deployed to github-app-auth September 3, 2026 15:36 Active
@agent-framework-automation agent-framework-automation Bot added the lab Usage: [Issues, PRs], Target: lab packages label Sep 3, 2026
@github-code-quality

Copy link
Copy Markdown

Code Coverage Overview

Languages: Python

Python / code-coverage/python

The overall line coverage in commit 07a3976 in the dependabot/pip/pytho... branch is 91%. Line coverage data for the main branch is not yet available.

Show a line coverage summary of the most covered files.
File main dependabot/pip/pytho... 07a3976 +/-
packages/core/a...work/_skills.py 95%
packages/core/a...ework/_tools.py 94%
packages/core/a...rk/_sessions.py 94%
packages/core/a...ework/_types.py 93%
packages/core/a...bservability.py 93%
packages/core/a.../_compaction.py 93%
packages/openai..._chat_client.py 92%
packages/core/a...amework/_mcp.py 92%
packages/ag-ui/...i/_agent_run.py 91%
packages/foundr...g/_responses.py 87%

Merged via the queue into main with commit fcc07b3 Sep 4, 2026
56 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/python/uv-0.12.6 branch September 4, 2026 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Usage: [Issues, PRs], Target: dependencies in the project lab Usage: [Issues, PRs], Target: lab packages python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants