Skip to content

chore(actions)(deps): bump astral-sh/setup-uv from 8.2.0 to 10.0.0 - #40

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0
Open

chore(actions)(deps): bump astral-sh/setup-uv from 8.2.0 to 10.0.0#40
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown

Bumps astral-sh/setup-uv from 8.2.0 to 10.0.0.

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features

Changes

Another breaking release, directly after v9.0.0 but we think the added security justifies that.

Extra security by default

If you use the default enable-cache: auto this will now DISABLE THE CACHE to protect against cache poisoning for the following events:

  • pull_request_target
  • workflow_run
  • release

You can read the full reasoning in astral-sh/setup-uv#984

version: latest-known

- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"

This will now install the latest version with a checksum that is known by this action. The known uv checksums are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.

Read python version from .tool-versions

- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"

Will now also set the python version if it is defined in .tool-versions. You can read the details in the docs

🚨 Breaking changes

🐛 Bug fixes

🚀 Enhancements

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 10, 2026
@github-actions

github-actions Bot commented Aug 10, 2026

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 4089668 — chore(actions)(deps): bump astral-sh/setup-uv from 8.2.0 to

❌ Job failures

JS & TS checks / apps/desktop / check:lint · View job

Job JS & TS checks / apps/desktop / check:lint failed.


Python tests / Run tests slice 9/12 · View job

Job Python tests / Run tests slice 9/12 failed.


⚠️ Action required

CI-sensitive file review · View job

This PR changes CI-sensitive files (eslint config, workflow YAMLs, or composite actions). These influence what the js-autofix job executes and pushes to main.

Sensitive files changed:

How to fix:

Add the ci-reviewed label after verifying:

  • no new eslint rules with custom fix functions that write outside linted paths,
  • no workflow changes that widen permissions or remove guards,
  • no composite action changes that alter what gets executed.

⚠️ Warnings

CI timings · View report · View job

Wall time 17m21s vs 8m30s (+104.1%). 15 job(s) slower, 22 faster, 2 unchanged.

  • Python tests / Run tests slice 4/12: -75.0s
  • Python tests / Run tests slice 3/12: -60.0s
  • Python tests / Run tests slice 2/12: -50.0s
  • Python tests / Run tests slice 1/12: -48.0s
  • Python tests / Run tests slice 11/12: -43.0s

OSV vulnerability scan · View job

4 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.

@bbasketballer75 bbasketballer75 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 hermes automated review

  • 6 files changed, 9 additions, 9 deletions
  • ⚠️ tests not run (no test command detected)

No heuristic issues detected.


Review generated by hermes pr-reviewer. Trust but verify.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-9.0.0 branch 3 times, most recently from 4fdb9db to cbc8cab Compare August 11, 2026 17:38
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.2.0 to 10.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@fac544c...ae62891)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(actions)(deps): bump astral-sh/setup-uv from 8.2.0 to 9.0.0 chore(actions)(deps): bump astral-sh/setup-uv from 8.2.0 to 10.0.0 Aug 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-9.0.0 branch from cbc8cab to 4089668 Compare August 15, 2026 19:46

@bbasketballer75 bbasketballer75 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 hermes automated review

  • 6 files changed, 9 additions, 9 deletions
  • ⚠️ tests not run (no test command detected)

No heuristic issues detected.


Review generated by hermes pr-reviewer. Trust but verify.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant