Skip to content

chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 - #203

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1
Closed

chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1#203
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 9.0.0 to 10.0.1.

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.0.1 🌈 Tolerate transient manifest timeouts

Changes

Thank you @​arguile- for making this action more resilient.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in astral-sh/setup-uv#984

version: latest-known

- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions

- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v9.0.0...v10.0.1)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

jfrench9 added a commit that referenced this pull request Sep 1, 2026
)

Brings this repo up to the CI dependency posture the three frontend apps
landed today. It was the fleet's blind spot: `dependabot.yml` declared
only the `github-actions` ecosystem, so **nothing was ever proposed for
`pyproject.toml` or `uv.lock`** — the runtime dependencies of a
published package had no update coverage at all.

## Changes

**Dependabot gains the `uv` ecosystem**, mirroring the robosystems
backend.

**Four third-party actions pinned by commit SHA.** GitHub-owned actions
(`actions/checkout`, `actions/setup-python`) stay on tags, matching the
frontends' convention. The `action-gh-release` and `claude-code-action`
SHAs are the ones already running across the three frontends.

Two pins worth a closer look:

- **`pypa/gh-action-pypi-publish`** moves from the `release/v1` *branch*
to `dc37677b # v1.14.2`. That commit **is** the current `release/v1`
head, so nothing about what runs today changes — it just stops the
reference being a moving branch, and gives Dependabot a version to
track. This is the action that publishes to PyPI, so an unpinned moving
reference was the most consequential one in the fleet.
- **`astral-sh/setup-uv`** is pinned where it already sat, `v9.0.0`, and
majors are now ignored — closing the loop on PR #203 and the two earlier
declines.

## Why v9 rather than matching the backend's v8.3.2

The backend holds at v8.3.2 because v9 flipped `prune-cache` to `false`
and would grow its uv cache. This repo is **not** downgraded to match,
because neither v9's nor v10's breaking change actually bites here: no
workflow triggers on `release`, `pull_request_target` or `workflow_run`,
which is the only surface v10's cache guard touches. Downgrading would
be churn with a real behavior change and no security gain.

So what the fleet shares is the *rule* — don't take setup-uv majors
without a deliberate decision — not the version number. The comment in
`dependabot.yml` says exactly that, rather than copying the backend's
cache rationale, which isn't true of this repo.

## Note on the uv block

Intentionally no groups. Unlike the backend there's no version-coupled
family here — `httpx`, `pydantic`, `attrs` and `typing-extensions` move
independently — and majors on those land on consumers of the published
package, so they're left ungrouped for individual triage.

## Verification

All workflow YAML parses, and the `dependabot.yml` schema is validated
by GitHub's own check on this PR. Changes are workflow/config YAML only;
no Python source touched.
@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like astral-sh/setup-uv is no longer being updated by Dependabot, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 1, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/astral-sh/setup-uv-10.0.1 branch September 1, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants