Loading
Update dependency uv_build to >=0.11.25,<0.12.0
This MR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
| uv_build (source, changelog) | >=0.11.24,<0.12.0 -> >=0.11.25,<0.12.0 |
Release Notes
astral-sh/uv (uv_build)
v0.11.25
Released on 2026-06-26.
Security
This release updates our tar library, astral-tokio-tar, to v0.6.3, which includes over 20 changes that harden our tar handling against parser differentials. uv may reject source distributions with malformed or ambiguous content that were previously accepted.
See the upstream commits for a full list of changes.
Enhancements
- Add a full "lockfile" to tool receipts (#18937)
- Allow scoped overrides to add dependencies (#19974)
- Avoid writing redundant lockfile markers with
tool.uv.environments(#19933) - Factor supported environments out of lockfile markers (#19969)
- Recommend our own build backend in the build frontend (#19994)
- Reject wheels with multiple .dist-info directories (#19986)
- Simplify dependency markers under parent reachability (#19971)
- Support scoped dependency exclusions (#19977)
- Support scoped dependency overrides (#19970)
- Explain why files are skipped in registry index parsing (#19983)
Preview features
- Add
uv workspace list --scripts(#20009) - Support centralised environments in
uv venv(#19912) - Use locked ty versions in
uv check(#19884) - Add centralized storage of project environments (#18214)
- Verify lockfile hashes before reusing a cached ty in
uv check(#19995) - Use locked dependency selection for
uv check --script(#19989)
Bug fixes
Configuration
- If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.