No description
  • Shell 89.3%
  • JavaScript 10.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Renovate 5cda3881ec
All checks were successful
NodeJS check / check-nodejs (push) Successful in 2m11s
Run renovate / renovate (push) Successful in 3m8s
Update https://github.com/astral-sh/setup-uv action to v10 (#255)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [https://github.com/astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.0` |

---

### Release Notes

<details>
<summary>astral-sh/setup-uv (https://github.com/astral-sh/setup-uv)</summary>

### [`v10.0.0`](https://github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features

[Compare Source](https://github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0)

#### Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

##### Extra security by default

If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events:

- `pull_request_target`
- `workflow_run`
- `release`

You can read the full reasoning in [#&#8203;984](https://github.com/astral-sh/setup-uv/issues/984)

##### `version: latest-known`

```yaml
- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"
```

This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](4f6036f71c/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

##### Read python version from `.tool-versions`

```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
```

Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)

#### 🚨 Breaking changes

- Disable automatic caching for sensitive events [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;992](https://github.com/astral-sh/setup-uv/issues/992))

#### 🐛 Bug fixes

- Reject paths in .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1007](https://github.com/astral-sh/setup-uv/issues/1007))

#### 🚀 Enhancements

- Read Python version from .tool-versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;996](https://github.com/astral-sh/setup-uv/issues/996))
- Add latest-known version selector [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;993](https://github.com/astral-sh/setup-uv/issues/993))

#### 🧰 Maintenance

- Require pull requests for Dependabot rollups [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1005](https://github.com/astral-sh/setup-uv/issues/1005))
- ci: pin Alpine container image [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;995](https://github.com/astral-sh/setup-uv/issues/995))
- chore: update known checksums for 0.12.3 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;991](https://github.com/astral-sh/setup-uv/issues/991))
- chore: update known checksums for 0.12.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;985](https://github.com/astral-sh/setup-uv/issues/985))
- chore: update known checksums for 0.12.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;982](https://github.com/astral-sh/setup-uv/issues/982))
- chore: update known checksums for 0.12.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;981](https://github.com/astral-sh/setup-uv/issues/981))
- chore: update known checksums for 0.11.31/0.11.32 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;972](https://github.com/astral-sh/setup-uv/issues/972))

#### 📚 Documentation

- docs: update version references to v9.0.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;971](https://github.com/astral-sh/setup-uv/issues/971))

#### ⬆️ Dependency updates

- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1013](https://github.com/astral-sh/setup-uv/issues/1013))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;1004](https://github.com/astral-sh/setup-uv/issues/1004))
- chore(deps): roll up Dependabot updates [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;994](https://github.com/astral-sh/setup-uv/issues/994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;976](https://github.com/astral-sh/setup-uv/issues/976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;980](https://github.com/astral-sh/setup-uv/issues/980))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: #255
2026-08-12 09:09:33 -07:00
.forgejo/workflows Update https://github.com/astral-sh/setup-uv action to v10 (#255) 2026-08-12 09:09:33 -07:00
tasks reorganize 2026-07-29 07:50:56 -07:00
tools No more ruby, finally 2026-07-28 16:49:34 -07:00
workflow-templates Actually use stable 2026-07-30 09:27:00 -07:00
.gitignore Move reposyncer over 2025-11-16 19:42:08 -08:00
.nvmrc Enforce node versiobn 2026-01-07 16:04:47 -08:00
.prettierignore Move reposyncer over 2025-11-16 19:42:08 -08:00
.prettierrc add rc 2025-11-16 19:48:35 -08:00
package-lock.json Update dependency renovate to v44.26.0 (#254) 2026-08-12 09:09:23 -07:00
package.json Path condition the expensive jobs 2026-07-29 06:45:49 -07:00
renovate-global.js fixup 2026-07-27 07:31:02 -07:00
renovate.json reorganize 2026-07-29 07:50:56 -07:00
renovate.json.nosync reorganize 2026-07-29 07:54:21 -07:00
reposyncer.sh Raise limit 2026-08-04 13:56:08 -07:00