Update dependency uv_build to >=0.11.14,<0.12.0
This MR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
| uv_build (source, changelog) | >=0.10.12,<0.11.0 -> >=0.11.14,<0.12.0 |
Release Notes
astral-sh/uv (uv_build)
v0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
- Ignore
top_level.txtentries in uninstall that are not valid Python identifiers (#19340)
Bug fixes
- Avoid applying
.envfiles in parent process (#19343) - Filter ANSI codes in logging output (#19311)
- Fix
uv treeshowing extra-conditional deps for packages required without extras (#19332) - Respect build options (e.g.,
--no-build) during lock validation (#19366)
v0.11.13
Released on 2026-05-10.
Bug fixes
- Include data files in editable builds (#19312)
- Respect
--require-hasheswhen installing frompylock.tomlfiles (#19334)
Python
Python
- Add CPython 3.14.5
v0.11.12
Released on 2026-05-08.
Python
- Add CPython 3.15.0b1
Enhancements
- Add
--no-editablesupport touv pip install(#19306) - Require git refs in URLs to be percent-encoded (#19320)
Bug fixes
- Respect
--no-devoverUV_DEV=1(#19313) - Don't suggest non-existent
--no-frozenflag (#19290) (#19294)
Documentation
- Fix bug from inconsistent workflow name in GHA-PyPI guide example (#19309)
v0.11.11
Released on 2026-05-06.
Bug fixes
- Accept legacy ID format from pre-0.11.9 cache entries (#19301)
v0.11.10
Released on 2026-05-05.
Bug fixes
- Allow pre-release Python requests with non-zero patch versions (#19286)
v0.11.9
Released on 2026-05-04.
This release includes a special release candidate for the next Python 3.14 patch release. Python 3.14 included a new garbage collection implementation, which reduced pause times but caused significant unexpected memory pressure in production environments. In 3.14.5 and 3.15, the previous garbage collection implementation will be restored.
We would greatly appreciate if you tested the 3.14.5rc1 version included in this release. The stable version is expected to be released soon and any feedback on potential issues would be helpful to the Python development team.
For more context, see the announcement, issue, and pull request.
Issues with the new release can be reported in the uv or CPython issue trackers.
Python
- Upgrade PyPy to v7.3.22
- Add CPython 3.14.5rc1
- On macOS, CPython statically links
libpythonto match Linux
Enhancements
- Omit compatible release desugaring for pre-release hints (#19267)
- Fix file locks on Android (#18323)
Preview
uv auditadd reporting for adverse project statuses (#19128)
Bug fixes
- Discover versioned Python executables when
requires-pythonpins a version (#18700) - Fix URL prefix matching to require path boundaries (#19154)
- Fix transitive Git path dependencies in lockfiles (#19269)
- Handle incorrect unlock error in
LockedFile::dropon Wine (#19229) - Prevent uninstalling site-packages for empty
top_level.txtin.egg-info(#19114) - Use symlinks instead of junctions on Wine (#19213)
- Fix floating-point environment handling on ARMv7 (#19157)
- Redact credentials from remote requirements URL in offline errors (#19216)
- Windows tramplolines no longer set
PYTHONHOMEand only set__PYVENV_LAUNCHER__for virtual environments (#19199)
Documentation
- Mark
--native-tlsandUV_NATIVE_TLSas deprecated (#18705) - Re-add
pytorch-triton-rocmto PyTorch ROCm docs (#19241) - Tweak changelog entries for 0.11.8 (#19188)
- Add 'Exporting lockfiles' to the Concepts->Projects index (#19209)
- Clarify that
uv initcreates git files / folders in the projects guide (#19183)
v0.11.8
Released on 2026-04-27.
Enhancements
- Add
--python-downloads-json-urltopython pin(#19092) - Fetch uv from Astral mirror during self-update (#18682)
- Support
pip uninstall -y(#19082) - Allow
exclude-newerto be missing from the lockfile whenexclude-newer-spanis present (#19024) - Only show the version number in
uv self version --short(#19019) - Silence warnings on empty
SSL_CERT_DIRdirectory (#19018) - Use a sentinel timestamp for relative
exclude-newerandexclude-newer-packagevalues in lockfiles (#19022, #19101)
Configuration
- Add
UV_PYTHON_NO_REGISTRY(#19035) - Add an environment variable for
UV_NO_PROJECT(#19052) - Expose
UV_PYTHON_SEARCH_PATHfor Python discoveryPATHoverrides (#19034)
Bug fixes
- Add
rust-toolchain.tomlto uv-build sdist (#19131) - Ensure uv invocations of git do not inherit repository location environment variables (#19088)
- Redact pre-signed upload URLs in verbose output (#19146)
- Handle transitive URL dependencies in PEP 517 build requirements (#19076, #19086)
- Support
uv lockon apyproject.tomlthat only contains dependency-groups (#19087) - Disable transparent Python upgrades in projects when a patch version is requested via
.python-version(#19102) - Fix Python variant tagging in the Windows registry (#19012)
- Ban external symlinks in
.tar.zstwheels (#19144)
Distributions
- Remove deprecated license classifiers from uv-build and add Python 3.14 classifier (#19130)
Documentation
- Bump astral-sh/setup-uv version in docs (#19030)
- Update PyTorch documentation for PyTorch 2.11 (#19095)
v0.11.7
Released on 2026-04-15.
Python
Enhancements
- Elevate configuration errors to
required-versionmismatches (#18977) - Further improve TLS certificate validation messages (#18933)
- Improve
--exclude-newerhints (#18952)
Preview features
Bug fixes
- De-quote
workspace metadatain linehaul data (#18966) - Avoid installing tool workspace member dependencies as editable (#18891)
- Emit JSON report for
uv sync --checkfailures (#18976) - Filter and warn on invalid TLS certificates (#18951)
- Fix equality comparisons for version specifiers with
~=operators (#18960) - Fix stale Python upgrade preview feature check in project environment construction (#18961)
- Improve Windows path normalization (#18945)
v0.11.6
Released on 2026-04-09.
This release resolves a low severity security advisory in which wheels with malformed RECORD entries could delete arbitrary files on uninstall. See GHSA-pjjw-68hj-v9mw for details.
Bug fixes
- Do not remove files outside the venv on uninstall (#18942)
- Validate and heal wheel
RECORDduring installation (#18943) - Avoid
uv cache cleanerrors due to Win32 path normalization (#18856)
v0.11.5
Released on 2026-04-08.
Python
- Add CPython 3.13.13, 3.14.4, and 3.15.0a8 (#18908)
Enhancements
- Fix
build_system.requireserror message (#18911) - Remove trailing path separators in path normalization (#18915)
- Improve error messages for unsupported or invalid TLS certificates (#18924)
Preview features
- Add
exclude-newerto[[tool.uv.index]](#18839) uv audit: add context/warnings for ignored vulnerabilities (#18905)
Bug fixes
- Normalize persisted fork markers before lock equality checks (#18612)
- Clear junction properly when uninstalling Python versions on Windows (#18815)
- Report error cleanly instead of panicking on TLS certificate error (#18904)
Documentation
- Remove the legacy
PIP_COMPATIBILITY.mdredirect file (#18928) - Fix
uv init example-bare --bareexamples (#18822, #18925)
v0.11.4
Released on 2026-04-07.
Enhancements
- Add support for
--upgrade-group(#18266) - Merge repeated archive URL hashes by version ID (#18841)
- Require all direct URL hash algorithms to match (#18842)
Bug fixes
- Avoid panics in environment finding via cycle detection (#18828)
- Enforce direct URL hashes for
pyproject.tomldependencies (#18786) - Error on
--lockedand--frozenwhen script lockfile is missing (#18832) - Fix
uv exportextra resolution for workspace member and conflicting extras (#18888) - Include conflicts defined in virtual workspace root (#18886)
- Recompute relative
exclude-newervalues duringuv tree --outdated(#18899) - Respect
--exclude-newerinuv tool list --outdated(#18861) - Sort by comparator to break specifier ties (#18850)
- Store relative timestamps in tool receipts (#18901)
- Track newly-activated extras when determining conflicts (#18852)
- Patch
Cargo.lockinuv-buildsource distributions (#18831)
Documentation
- Clarify that
--exclude-newercompares artifact upload times (#18830)
v0.11.3
Released on 2026-04-01.
Enhancements
- Add progress bar for hashing phase in uv publish (#18752)
- Add support for ROCm 7.2 (#18730)
- Emit abi3t tags for every abi3 version (#18777)
- Expand
uv workspace metadatawith dependency information from the lock (#18356) - Implement support for PEP 803 (#18767)
- Pretty-print platform in built wheel errors (#18738)
- Publish installers to
/installers/uv/lateston the mirror (#18725) - Show free-threaded Python in built-wheel errors (#18740)
Preview features
- Add
--ignoreand--ignore-until-fixedtouv audit(#18737)
Bug fixes
- Bump simple API cache (#18797)
- Don't drop
blake2bhashes (#18794) - Handle broken range request implementations (#18780)
- Remove
powerpc64-unknown-linux-gnufrom release build targets (#18800) - Respect dependency metadata overrides in
uv pip check(#18742) - Support debug CPython ABI tags in environment compatibility (#18739)
Documentation
v0.11.2
Released on 2026-03-26.
Enhancements
- Add a dedicated Windows PE editing error (#18710)
- Make
uv self updatefetch the manifest from the mirror first (#18679) - Use uv reqwest client for self update (#17982)
- Show
uv self updatesuccess and failure messages with--quiet(#18645)
Preview features
- Evaluate extras and groups when determining auditable packages (#18511)
Bug fixes
- Skip redundant project configuration parsing for
uv run(#17890)
v0.11.1
Released on 2026-05-21.
Enhancements
Preview features
Configuration
- Allow disabling reading the system config with
UV_NO_SYSTEM_CONFIG(#19476)
Bug fixes
- Allow environment variables that take a list to be empty (#19503)
- Ensure that incompatible wheel hints do not leak secrets (#19504)
- Reject unsafe entry points in
uv-build(#19495) - Restrict delimiters in entry point parsing (#19471)
- uv-netrc: fix multi-word no-space comment lines causing parse errors (#19494)
Documentation
- Document and test relative exclude-newer support for uv pip (#19475)
v0.11.0
Released on 2026-03-23.
Breaking changes
This release includes changes to the networking stack used by uv. While we think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so we have marked the change as breaking out of an abundance of caution.
The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13 which included some breaking changes to TLS certificate verification.
The following changes are included:
-
rustls-platform-verifieris used instead ofrustls-native-certsandwebpkifor certificate verificationThis change should have no effect unless you are using the
native-tlsoption to enable reading system certificates.rustls-platform-verifierdelegates to the system for certificate validation (e.g.,Security.frameworkon macOS) instead of eagerly loading certificates from the system and verifying them viawebpki. The effects of this change will vary based on the operating system. In general, uv's certificate validation should now be more consistent with browsers and other native applications. However, this is the most likely cause of breaking changes in this release. Some previously failing certificate chains may succeed, and some previously accepted certificate chains may fail. In either case, we expect the validation to be more correct and welcome reports of regressions.In particular, because more responsibility for validating the certificate is transferred to your system's security library, some features like CA constraints or revocation of certificates via OCSP and CRLs may now be used.
This change should improve performance when using system certificate on macOS, as uv no longer needs to load all certificates from the keychain at startup.
-
aws-lcis used instead ofringfor a cryptography backendThere should not be breaking changes from this change. We expect this to expand support for certificate signature algorithms.
-
--native-tlsis deprecated in favor of a new--system-certsflagThe
--native-tlsflag is still usable and has identical behavior to--system-certs.This change was made to reduce confusion about the TLS implementation uv uses. uv always uses
rustlsnotnative-tls. -
Building uv on x86-64 and i686 Windows requires NASM
NASM is required by
aws-lc. If not found on the system, a prebuilt blob provided byaws-lc-syswill be used.If you are not building uv from source, this change has no effect.
See the CONTRIBUTING guide for details.
-
Empty
SSL_CERT_FILEvalues are ignored (for consistency withSSL_CERT_DIR)
See #18550 for details.
Python
- Enable frame pointers for improved profiling on Linux x86-64 and aarch64
See the python-build-standalone release notes for details.
Enhancements
- Treat 'Dynamic' values as case-insensitive (#18669)
- Use a dedicated error for invalid cache control headers (#18657)
- Enable checksum verification in the generated installer script (#18625)
Preview features
- Add
--service-formatand--service-urltouv audit(#18571)
Performance
- Avoid holding flat index lock across indexes (#18659)
Bug fixes
- Find the dynamic linker on the file system when sniffing binaries fails (#18457)
- Fix export of conflicting workspace members with dependencies (#18666)
- Respect installed settings in
uv tool list --outdated(#18586) - Treat paths originating as PEP 508 URLs which contain expanded variables as relative (#18680)
- Fix
uv exportfor workspace member packages with conflicts (#18635) - Continue to alternative authentication providers when the pyx store has no token (#18425)
- Use redacted URLs for log messages in cached client (#18599)
Documentation
Configuration
- If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.