Skip to content

Update dev tools - #55

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dev-tools
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dev-tools

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
go:golang.org/x/tools/cmd/goimports 0.49.0 → v0.51.0 age confidence tools minor
go:golang.org/x/vuln/cmd/govulncheck 1.7.0 → v1.8.0 age confidence tools minor
golangci-lint 2.13.2 → 2.14.0 age confidence tools minor
ruff 0.16.5 → 0.16.10 age confidence tools patch
uv 0.12.7 → 0.12.23 age confidence tools patch

Release Notes

golangci/golangci-lint (golangci-lint)

v2.14.0

Compare Source

Released on 2026-09-24

  1. Bug fixes
    • fix: cache of facts reloading
  2. Linters new features or changes
    • bodyclose: from 73d1f95 to 857993a (new directive handled)
    • exhaustive: from 0.12.0 to 0.13.0
    • exhaustruct_v5: from 5.0.3 to 5.2.0 (new option: allow-empty-blank-assignments)
    • go-check-sumtype: from 0.3.1 to ae6904d
    • gocritic: from 0.14.4 to 0.15.0
    • gofumpt: from 0.11.0 to 0.12.0
    • gomoddirectives: from 0.9.0 to 0.10.0
    • gosec: from 2.28.0 to 2.29.0 (re-enable G407)
    • govet-modernize: from 0.49.0 to 0.50.0
    • loggercheck: from 0.11.0 to 0.12.0
    • revive: from 1.15.0 to 1.17.0 (new rules: marshal-receiver, multiline-if-init, use-slices-concat)
    • tagliatelle: from 0.7.2 to 0.8.0
  3. Linters bug fixes
    • fatcontext: from 0.10.0 to 0.10.1
    • flock: from 0.13.0 to 0.13.1
    • godoclint: from 0.11.2 to 0.11.4
    • protogetter: from 0.3.21 to 1.0.1
    • recvcheck: from 0.3.0 to 0.3.1
    • tagalign: from 1.4.3 to 1.4.4
astral-sh/ruff (ruff)

v0.16.10

Compare Source

Released on 2026-10-01.

Preview features
  • Add a migration guide for categories (#​28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#​29000)
Performance
  • Reduce memory used by diagnostics (#​28951)
Server
  • Avoid running uv format in untrusted workspaces (#​28873)
Documentation
  • Fix links to moved changelog sections and renamed mdtests (#​28941)
  • Add Python 3.15 as a supported version (#​28907)
  • Add ty as a type checker example (#​28906)
Other changes
  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#​29047)
Contributors

v0.16.9

Compare Source

Released on 2026-09-24.

Preview features
  • [ruff] Avoid false positives for overloaded division (RUF069) (#​28309)
Bug fixes
  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#​28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#​28767)
Rule changes
  • Update LibCST-based fixes for Python 3.15 (#​28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#​28542)
Documentation
  • Fix horizontal overflow on the rules documentation page (#​28699)
  • Update rules table with category information (#​28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#​28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#​28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#​27794)
  • [ruff] Mention related isort settings (RUF022) (#​28719)
Contributors

v0.16.8

Compare Source

Released on 2026-09-16.

Bug fixes
  • Visit functional TypedDict keyword arguments correctly (#​28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#​27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#​27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#​28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#​28505)
Rule changes
  • Add support for __lazy_modules__ (#​28459)
  • Recognize PEP-728 TypedDict class keywords (#​28533)
  • Recognize quoted types in typing.TypeForm (#​28507)
  • Support conditional assignment to __lazy_modules__ (#​28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#​28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#​28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#​28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#​28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#​28598)
CLI
  • Use rule name and code in formatter incompatibility warnings (#​28571)
Configuration
  • [flake8-tidy-imports] Add extend-banned-api (#​28644)
Contributors

v0.16.7

Compare Source

Released on 2026-09-10.

Preview features
  • [ruff] Add rule for default values on method receivers (RUF077) (#​26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#​28311)
Bug fixes
  • Alternate nested quotes inside format spec interpolations (#​28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#​27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#​26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#​28310)
Rule changes
  • Correct D211 and D203 rule conflict diagnostic (#​28444)
  • Recognize slice and frozendict generics (#​28477)
  • Stop defining __cached__ for Python 3.15 (#​28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#​28475)
Performance
  • Reuse parser name lookups when interning (#​28399)
  • Speed up inherited configuration resolution (#​28299)
Documentation
  • Fix line-length path in --config example (#​28392)
  • Remove the "Who’s Using Ruff?" list (#​28455)
Other changes
  • Embed archive checksums in the shell installer (#​28281)
Contributors

v0.16.6

Compare Source

Released on 2026-09-03.

Preview features
  • Move pytest-fixture-autouse to the restriction category (#​28219)
  • [flake8-pytest-style] Add an autofix for PT020 (#​27993)
  • [flake8-tidy-imports] Prevent fix loop between TID254 and TID255 (#​28262)
  • [isort] Exclude pragma comments from line length calculation (I001) (#​27313)
Bug fixes
  • Validate unary expressions when parsing (#​28233)
  • [flake8-async, pylint] Recognize builtins.open (ASYNC230, PLW1514) (#​28021)
  • [flake8-bugbear] Fix panic on match subjects (B031) (#​27781)
  • [flake8-datetimez] Reject tzinfo=None for datetime bounds (DTZ901) (#​28022)
  • [flake8-pytest-style] Avoid duplicate PT017 diagnostics (#​27918)
  • [ruff] Remove lint.external hint for Ruff-specific suppressions (RUF102) (#​27923)
Rule changes
  • [flake8-use-pathlib] Add display-only fix for os.listdir (PTH208) (#​28027)
Documentation
  • Add another example and glob reference for lint.per-file-ignores (#​28106)
  • Add duplicate work guidance (#​28229)
  • [flake8-async] Document thread offloading (ASYNC240) (#​28008)
  • [pyupgrade] Clarify default encoding argument handling (UP012) (#​27315)
Other changes
  • Allow unary plus in match patterns on Python 3.15 (#​28231)
Contributors
astral-sh/uv (uv)

v0.12.23

Compare Source

Released on 2026-10-03.

Python
Preview features
  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#​22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#​22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#​22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#​22017, #​22018)
Bug fixes
  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#​22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#​22099)

v0.12.22

Compare Source

Released on 2026-10-01.

Python
  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#​22147)
Enhancements
  • Accept uppercase release suffixes in wheel platform tags (#​22113)
  • Record workspace-member default groups in lockfiles (#​22010, #​22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#​22044, #​22103)
  • Record default groups for non-project workspace roots in lockfiles (#​22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#​22104)
  • Format URLs and paths consistently in CLI messages (#​21937)
  • Hide the unsupported --offline option from uv publish help (#​22124)
Preview features
  • Honor --no-default-groups in uv audit (#​22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#​22114)
Configuration
  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#​22098)
Performance
  • Reduce uv's binary size by compressing embedded Python download metadata (#​22126)
Bug fixes
  • Verify unchanged requirements against existing lockfile hashes when relocking (#​22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#​22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#​22015)
  • Avoid false entry-point warnings for required workspace members (#​22112)
Other changes
  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#​22121)

v0.12.21

Compare Source

Released on 2026-09-29.

Python
  • Update CPython to use OpenSSL 3.5.9 (#​22076)
Enhancements
  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#​22070)
Preview features
  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#​22004, #​22068)
Bug fixes
  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#​21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#​22049)

v0.12.20

Compare Source

Released on 2026-09-28.

Enhancements
  • Reuse lockfiles when dependency declarations are semantically equivalent (#​21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#​21990)
Preview features
  • Write normalized requirement declarations with the lockfile-normalization preview feature (#​21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#​22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#​22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#​22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#​22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#​22050)
Configuration
  • Continue searching XDG_CONFIG_DIRS after empty entries (#​21987)
Performance
  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#​22051)
Bug fixes
  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#​21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#​21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#​21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#​21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#​21979)
  • Prevent commands from running and changing state after displaying --show-settings (#​21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#​21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#​22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#​22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#​22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#​22034)

v0.12.19

Compare Source

Released on 2026-09-24.

Python
  • Add PyPy 3.11.16 and 3.12.14 (#​21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#​21847)
Enhancements
  • Format upload URLs with backticks in uv publish errors (#​21934)
Preview features
  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#​21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#​21913)
Bug fixes
  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#​21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#​21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#​21891)
  • Preserve always-false python_version markers when parsing their serialized form (#​21939)
Rust API
  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#​21965)
Documentation
  • Make individual preview-feature reference entries linkable by name (#​21950)

v0.12.18

Compare Source

Released on 2026-09-22.

Enhancements
  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#​21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#​21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#​21881)
Preview features
  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#​21880)
Performance
  • Speed up uv_build editable wheel creation by omitting compression from temporary wheels (#​21918)
Bug fixes
  • Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#​21835, #​21836)
  • Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#​21860, #​21856)
  • Use configured dependency-metadata when checking whether installed requirements are satisfied (#​21843)
  • Reject archive entries that normalize to absolute Windows paths (#​21923)
  • Recognize distribution filenames and archive extensions when URL fragments contain ? (#​21920)
  • Generate correctly lowercased platform tags for BSD and Haiku releases (#​21853)
  • Avoid rebuilding a Windows relative path into an absolute form (#​21923)

v0.12.17

Compare Source

Released on 2026-09-18.

Enhancements
  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#​21780)
Preview features
  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#​21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#​20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#​21821)
  • Apply uv check lock modes when retrieving workspace metadata (#​21821)
Performance
  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#​21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#​21810)
Bug fixes
  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#​21825)
Documentation
  • Clarify the 0.12.14 and 0.12.15 release notes (#​21817)

v0.12.16

Compare Source

Released on 2026-09-17.

Python
  • Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#​21741)
Enhancements
  • Verify downloaded wheels and source distributions against hashes supplied by package indexes (#​21562)
  • Allow build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#​21467)
  • Honor Darwin platform_release markers in required-environments using macOS wheel deployment targets (#​21766)
  • Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#​21779)
Preview features
  • Support lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#​21163)
  • Honor configured and command-line index settings, including credentials, in uv upgrade (#​21776)
  • Allow uv check to run in projects that are not managed by uv and outside workspaces (#​21777)
  • Respect --python and UV_PYTHON when selecting the Python version for uv check (#​21744)
Bug fixes
  • Redact Azure shared access signatures from displayed and logged URLs (#​21755)
  • Check archive sizes from pylock.toml before reusing cached distributions (#​21609)
  • Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths (#​20631)
  • Use the bundled uv_build backend only when its version matches active version pins (#​21742)
  • Handle malformed index URLs without panicking when credentials are configured (#​21784)
  • Report a configuration error instead of panicking for proxy URLs without a host (#​21781)
  • Return a credential-redacted error instead of panicking when a URL cannot be converted to a path (#​21783)

v0.12.15

Compare Source

Released on 2026-09-15.

This release fixes a regression in 0.12.14 that lead to rejecting valid installation commands such as using
uv pip install --system in python:* docker images or when using uv pip install --target .. (#​21699)

Performance
  • Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes (#​21675)
Bug fixes
  • Revert "Reject symlinked wheel installation destinations" (#​21699)

v0.12.14

Compare Source

Released on 2026-09-15.

Package-operation errors now use uv's standard diagnostics, with consistent hints and compact, labeled cause chains. (#​17110, #​21599, #​21603)

Package-operation exit codes now reflect the underlying cause: expected failures return 1, while recognized operational and internal failures return 2. (#​17110)

Enhancements
  • Resume interrupted downloads with HTTP Range requests when supported (#​21570)
  • Show underlying causes and hints in user warnings (#​21565)
  • Show resolver hints for failed uv tool upgrade operations (#​21566)
Preview features
  • Export multiple dependency selections from a shared lockfile in one uv export --batch invocation with the batch-export preview feature (#​21618)
Performance
  • Speed up dependency resolution from local wheelhouses by reading wheel metadata in a single blocking task (#​21619)
  • Speed up cold resolution against large package indexes by parsing Simple API responses in bounded background workers (#​21593)
  • Speed up warm-cache resolution by decoding fresh HTTP cache entries in the cache-read task (#​21621)
Bug fixes
  • Select releases that satisfy required-environments within each resolver fork instead of combining incompatible wheel coverage across forks (#​21672)
  • Install packages with paths longer than MAX_PATH on Windows systems without long-path support enabled (#​21625)
  • Prevent uv python install from overwriting valid unmanaged Python symlinks with relative targets on Unix (#​21639)
  • Redact credentials and signatures from missing-path-segment URL errors (#​21616)
  • Avoid exceeding the configured retry budget when cached HTTP responses fail revalidation (#​21640)
  • Prefer bin/python over bin/python3 when discovering interpreters in Unix environments (#​21559)
  • Suppress managed-Python fallback warnings under --quiet (#​21565)
  • Keep failed uv tool upgrade errors visible with -q while suppressing them with -qq (#​21566)

v0.12.13

Compare Source

Released on 2026-09-10.

Python
Enhancements
  • Verify hashes when downloading PEP 658 metadata sidecars (#​21563)
Preview features
  • Respect ty exclusions when uv check automatically selects members of a virtual workspace (#​21555)
Performance
  • Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately (#​21279)
Bug fixes
  • Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention (#​18713)
  • Prefer core-metadata over legacy aliases in JSON index responses (#​21563)

v0.12.12

Compare Source

Released on 2026-09-09.

The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

Bug fixes
  • Exclude distributions uploaded after the exclude-newer cutoff from lockfiles and generated requirement hashes (#​21539)

v0.12.11

Compare Source

Released on 2026-09-08.

Preview features
  • Generate missing artifact hashes when exporting pylock.toml files to ensure they conform to PEP 751 (#​20146)
  • Warn when pylock.toml artifact hash tables are empty, which will be rejected in a future uv release (#​21462)
Performance
  • Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements (#​21478)
  • Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files (#​21468)
  • Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads (#​21500)
  • Speed up local wheel installs by reusing ZIP readers and buffers across extracted files (#​21499)
  • Avoid transitive dependency checks and unnecessary resolution when uv pip install --no-deps finds the requested packages already installed (#​21523)
Bug fixes
  • Verify source archives against hashes recorded in uv.lock before reading their metadata or running their build backends (#​21223)
  • Verify supplied hashes for registry requirements pinned with === under both --verify-hashes and --require-hashes (#​21543)
  • Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided (#​21544)
  • Support PowerShell virtual environment activation from UNC paths, including WSL paths (#​19159)
  • Trim surrounding whitespace from entries in .python-version and .python-versions files (#​21529)
  • Suppress VIRTUAL_ENV mismatch warnings for uv add --no-sync, uv remove --no-sync, and uv add --frozen (#​21496)
  • Warn and continue when uv python list cannot query an interpreter (#​21498)
Documentation
  • Restore TOML syntax highlighting for exclude-newer examples (#​21534)

v0.12.10

Compare Source

Released on 2026-09-04.

Enhancements
  • Attempt to revoke short-lived PyPI trusted-publishing tokens after uv publish completes, including when publishing fails (#​21423)
Preview features
  • Omit exclude-newer-package settings for packages outside the resolution from uv.lock with the missing-exclude-newer-package-lock preview feature (#​21455)
  • Show terminal dependency cycles in uv tree --invert output (#​21404)
Performance
  • Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification (#​21399)
  • Speed up uv publish by hashing each artifact in a single blocking task and reusing the buffer across reads (#​21389)
Bug fixes
  • Prevent --locked from failing when exclude-newer-package settings differ only for packages outside the resolution (#​21454)
  • Allow uv lock --check to reuse a lockfile when an absolute exclude-newer cutoff is moved later (#​19571)
  • Allow uv lock --check to reuse a lockfile when a package-specific exclude-newer cutoff is disabled (#​21450)
  • Require an explicit --name when uv init would infer a project name reserved for a Python interpreter (#​21395)
  • Write package-specific exclude-newer cutoffs to uv.lock in a deterministic order (#​21453)

v0.12.9

Compare Source

Released on 2026-09-01.

Python
Enhancements
  • Add --no-locked and --no-frozen to disable lock modes enabled by UV_LOCKED and UV_FROZEN for a single invocation (#​21408)
  • Report the exact command-line lock-mode flag in warnings and errors (#​21402)
Performance
  • Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#​21372)
Bug fixes
  • Update async_http_range_reader to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#​21401)
  • Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#​21382)
  • Redact secrets in signed URLs from retry diagnostics, including nested request errors (#​21381)
  • Give --locked, --frozen, --check, and --check-exists precedence over conflicting UV_LOCKED and UV_FROZEN values (#​21396)
  • Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#​21400)

v0.12.8

Compare Source

Released on 2026-08-31.

Enhancements
  • Warn about invalid tool directories and continue upgrading valid tools with uv tool upgrade --all (#​21368)
Preview features
  • Deduplicate identical files within and across cached wheels with the content-addressed-cache preview feature (#​21327)
  • Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files (#​21340)
  • Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk (#​21344)
Performance
  • Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once (#​21379)
  • Speed up dependency graph construction from large lockfiles by indexing packages during traversal (#​21373)
  • Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks (#​21377)
  • Speed up warm resolutions by reducing repeated marker interner work (#​21300)
Bug fixes
  • Do not trust hashes from direct URLs discovered only in wheel metadata when installing with --require-hashes (#​21348)
  • Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled (#​21366)
  • Redact Azure shared access signature (sig) query parameters from displayed URLs (#​21360)
  • Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery (#​21341)
Other changes
  • Update astral-tokio-tar to 0.7.0 and use effective sizes when tracking extracted hard links (#​21346)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team September 1, 2026 09:08
@renovate renovate Bot added the tooling label Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Code coverage report

Total coverage: ██████████████████░░ 89.8% 🟢

Detailed report
go test -race -coverprofile=coverage.raw.out ./...
ok  	github.com/supermetrics-public/supermetrics-cli/cmd	1.061s	coverage: 57.7% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/cmd/generated	2.150s	coverage: 86.4% of statements
	github.com/supermetrics-public/supermetrics-cli/cmd/supermetrics		coverage: 0.0% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/auth	2.210s	coverage: 92.0% of statements
?   	github.com/supermetrics-public/supermetrics-cli/internal/buildcfg	[no test files]
	github.com/supermetrics-public/supermetrics-cli/internal/cli		coverage: 0.0% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/config	1.028s	coverage: 89.7% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/exitcode	1.011s	coverage: 100.0% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/httpclient	6.849s	coverage: 91.3% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/output	1.023s	coverage: 93.4% of statements
ok  	github.com/supermetrics-public/supermetrics-cli/internal/update	1.083s	coverage: 89.5% of statements
cp coverage.raw.out coverage.out
while IFS= read -r pattern || [ -n "$pattern" ]; do \
	grep -v "$pattern" coverage.out > coverage.out.tmp && mv coverage.out.tmp coverage.out; \
done < .covignore
rm coverage.raw.out
go tool cover -func=coverage.out
github.com/supermetrics-public/supermetrics-cli/cmd/completion.go:60:			init				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/configure.go:76:			readLine			75.0%
github.com/supermetrics-public/supermetrics-cli/cmd/configure.go:84:			maskKey				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/configure.go:94:			init				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/help.go:31:				shouldColorHelp			66.7%
github.com/supermetrics-public/supermetrics-cli/cmd/help.go:39:				colorizeHelp			100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/help.go:81:				colorizeCommandLine		90.9%
github.com/supermetrics-public/supermetrics-cli/cmd/help.go:100:			colorizeFlagLine		100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/help.go:110:			initHelpColorization		41.2%
github.com/supermetrics-public/supermetrics-cli/cmd/login.go:102:			printLoginStatus		88.0%
github.com/supermetrics-public/supermetrics-cli/cmd/login.go:139:			formatDuration			100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/login.go:147:			init				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/man.go:31:				init				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/profile.go:178:			init				100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:67:				init				89.4%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:120:			Execute				0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:142:			classifyError			100.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:169:			isStderrTerminal		0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:174:			GetOutputFormat			0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:179:			GetAPIKeyFlag			0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:185:			GetProfile			87.5%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:200:			getDomain			0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/root.go:208:			IsVerbose			0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/supermetrics/main.go:10:		main				0.0%
github.com/supermetrics-public/supermetrics-cli/cmd/version.go:46:			init				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/auth.go:23:		ResolveToken			96.4%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:35:		getOAuthHTTPClient		66.7%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:56:		LoadOAuthConfig			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:81:		ResetOAuthConfigCache		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:96:		Expiry				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:105:		Login				95.9%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:192:		Refresh				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:206:		Revoke				93.5%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:234:		exchangeCode			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:246:		postTokenRequest		89.7%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:295:		generatePKCE			93.3%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:309:		generateState			75.0%
github.com/supermetrics-public/supermetrics-cli/internal/auth/oauth.go:330:		htmlPage			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/cli/writer.go:11:		IsQuiet				0.0%
github.com/supermetrics-public/supermetrics-cli/internal/cli/writer.go:23:		InfoWriter			0.0%
github.com/supermetrics-public/supermetrics-cli/internal/cli/writer.go:32:		InfoWriterErr			0.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:42:		Dir				75.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:51:		Path				75.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:60:		Load				83.3%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:82:		Save				70.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:101:		ActiveOrDefault			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:109:		GetProfile			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:122:		Validate			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:146:		Validate			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:159:		IsTokenExpired			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:172:		ClearOAuthTokens		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/config/config.go:179:		UpdateCheckInterval		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/exitcode/exitcode.go:18:	Error				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/exitcode/exitcode.go:19:	Unwrap				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/exitcode/exitcode.go:23:	Wrap				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/exitcode/exitcode.go:32:	Of				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:48:	Do				94.2%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:141:	ParseJSON			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:149:	ParseJSONWithMeta		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:154:	parseEnvelope			87.5%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:194:	Error				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:198:	envelopeError			90.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:215:	apiError			85.7%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/client.go:247:	extractRequestID		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/middleware.go:15:	RoundTrip			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/middleware.go:20:	chain				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:24:	withDefaults			57.1%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:40:	Retry				90.7%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:104:	isRetryableStatus		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:112:	isRetryableError		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:121:	retryDelay			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:134:	backoff				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:141:	parseRetryAfter			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/httpclient/retry.go:158:	sleep				80.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/csv.go:8:		printCSV			93.5%
github.com/supermetrics-public/supermetrics-cli/internal/output/fields.go:9:		FilterFields			93.8%
github.com/supermetrics-public/supermetrics-cli/internal/output/fields.go:40:		filterMap			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/fields.go:51:		extractField			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/json.go:9:		printJSON			91.7%
github.com/supermetrics-public/supermetrics-cli/internal/output/json.go:32:		colorizeJSON			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/json.go:95:		readJSONString			90.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:39:		Print				100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:66:		PrintError			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:74:		printErrorJSON			81.8%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:92:		printErrorText			94.1%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:130:		wrapText			75.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:150:		toSliceOfMaps			93.8%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:180:		arrayOfArraysToMaps		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:213:		structToMap			66.7%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:228:		formatValue			94.4%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:263:		flattenItems			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:285:		flattenNestedObjects		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:303:		findExpandableArrayField	92.9%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:332:		expandArrayField		72.7%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:369:		joinArrayValues			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:411:		sortedKeys			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/output.go:420:		sortedKeysFromSet		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/table.go:9:		printTable			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/output/table.go:26:		printVerticalTable		89.7%
github.com/supermetrics-public/supermetrics-cli/internal/output/table.go:70:		printHorizontalTable		94.3%
github.com/supermetrics-public/supermetrics-cli/internal/output/table.go:141:		printHorizontalBorder		100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:26:		applyUpdate			91.7%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:49:		download			86.7%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:70:		verifyChecksum			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:92:		extractBinary			90.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:113:		extractFromTarGz		85.7%
github.com/supermetrics-public/supermetrics-cli/internal/update/apply.go:135:		extractFromZip			76.9%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:38:		userAgent			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:42:		newHTTPClient			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:51:		fetchRelease			92.9%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:84:		isRateLimited			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:91:		rateLimitResetHint		75.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:100:		releaseInfo			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/github.go:123:		assetSuffix			75.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/selfupdate.go:38:	NewUpdater			80.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/selfupdate.go:68:	Upgrade				88.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/selfupdate.go:107:	ForceReinstall			85.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/selfupdate.go:138:	CheckOnly			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/selfupdate.go:161:	isHomebrew			66.7%
github.com/supermetrics-public/supermetrics-cli/internal/update/updatecheck.go:26:	ShouldCheck			92.3%
github.com/supermetrics-public/supermetrics-cli/internal/update/updatecheck.go:58:	RunBackgroundCheck		0.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/updatecheck.go:64:	runBackgroundCheckSync		95.8%
github.com/supermetrics-public/supermetrics-cli/internal/update/updatecheck.go:93:	PrintUpdateHint			100.0%
github.com/supermetrics-public/supermetrics-cli/internal/update/updatecheck.go:114:	printUpdateHintFormatted	100.0%
total:											(statements)			89.8%

@renovate renovate Bot changed the title Update dependency uv to v0.12.8 Update dependency uv to v0.12.9 Sep 1, 2026
@renovate
renovate Bot force-pushed the renovate/dev-tools branch 2 times, most recently from c61a53c to d1c5bdf Compare September 3, 2026 19:16
@renovate renovate Bot changed the title Update dependency uv to v0.12.9 Update dev tools Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/dev-tools branch 4 times, most recently from daf6c12 to 403d92e Compare September 10, 2026 20:23
@renovate
renovate Bot force-pushed the renovate/dev-tools branch 5 times, most recently from 3fff7dd to e9c6a9a Compare September 18, 2026 21:25
@renovate
renovate Bot force-pushed the renovate/dev-tools branch 5 times, most recently from b7e33f5 to 57e5dc7 Compare September 30, 2026 00:13
@renovate
renovate Bot force-pushed the renovate/dev-tools branch 3 times, most recently from 459b3aa to d81147d Compare October 2, 2026 22:06
@renovate
renovate Bot force-pushed the renovate/dev-tools branch from d81147d to 69b6dd1 Compare October 3, 2026 20:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants