Skip to content

chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 - #1235

Merged
frankbria merged 2 commits into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1
Sep 17, 2026
Merged

frankbria merged 2 commits into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 9.0.0 to 10.0.1.

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.0.1 🌈 Tolerate transient manifest timeouts

Changes

Thank you @​arguile- for making this action more resilient.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in astral-sh/setup-uv#984

version: latest-known

- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions

- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-10.0.1 branch 2 times, most recently from ddabfc4 to 68ab7b0 Compare September 17, 2026 03:46
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@c771a70...20cfd1b)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-10.0.1 branch from 68ab7b0 to 5dfe9a9 Compare September 17, 2026 15:28
@frankbria

Copy link
Copy Markdown
Owner

Dependabot Triage — PR #1235: astral-sh/setup-uv 9.0.0 → 10.0.1

Classification

  • Update type: High-impact core (installs uv in every Python job; major bump)
  • Security urgency: Medium — the major is itself security-motivated upstream (cache-poisoning hardening)
  • Supply-chain risk: Low

Key observations

  • Pin 20cfd1bf… verified against the v10.0.1 tag. Published 2026-08-14 (v10.0.0 on 2026-08-12); over four weeks old.
  • The v10 breaking change: with enable-cache: auto, caching is now disabled on pull_request_target, workflow_run, and release events (Automatically disable caching on release-shaped triggers? astral-sh/setup-uv#984). Every use here either sets enable-cache: true explicitly (test.yml ×5, engine-smoke.yml ×2, lifecycle.yml) or uses no cache (release.yml, unlocked-resolution.yml, which deliberately runs uncached). None of our workflows run on those three events, so behaviour is unchanged.
  • New opt-in version: latest-known (install only a uv whose checksum the action ships) and .tool-versions python reading; both opt-in, neither touches our python-version: "3.11" inputs.
  • v10.0.1 adds tolerance for transient manifest timeouts — a resilience gain for the daily unattended Unlocked Resolution run.
  • CI green on the PR across all 10 call sites, including Fresh resolve + smoke test, Backend Unit Tests, and check / check.

Recommendation

Merge now.

A major bump, but the breaking change is a safety default that does not apply to any event we run on, the pin is authentic, and the release has had a month in the wild. Staying on v9 forgoes the hardening for no benefit.

Follow-up actions

  • Rebase after the preceding merges, then merge.
  • Optional later: consider version: latest-known on the daily Unlocked Resolution job for an extra checksum layer, weighed against it lagging the newest uv.

@frankbria
frankbria merged commit fd208a3 into main Sep 17, 2026
18 checks passed
@frankbria
frankbria deleted the dependabot/github_actions/astral-sh/setup-uv-10.0.1 branch September 17, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant