mirror of
https://github.com/calibrain/shelfmark.git
synced 2026-10-06 09:24:40 +01:00
build(deps): bump the docker-base-image-digests group with 2 updates (#1328)
> [!WARNING] > Cooldown could not be applied because no publication date was available from the registry. > Bumps the docker-base-image-digests group with 2 updates: node and [astral-sh/uv](https://github.com/astral-sh/uv). Updates `node` from `e67514e` to `50c8e8c` Updates `astral-sh/uv` from 0.12.9 to 0.12.13 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/uv/releases">astral-sh/uv's releases</a>.</em></p> <blockquote> <h2>0.12.13</h2> <h2>Release Notes</h2> <p>Released on 2026-09-10.</p> <h3>Python</h3> <ul> <li>Add GraalPy 3.13.0 (<a href="https://redirect.github.com/astral-sh/uv/pull/21431">#21431</a>)</li> </ul> <h3>Enhancements</h3> <ul> <li>Verify hashes when downloading PEP 658 metadata sidecars (<a href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li> </ul> <h3>Preview features</h3> <ul> <li>Respect <code>ty</code> exclusions when <code>uv check</code> automatically selects members of a virtual workspace (<a href="https://redirect.github.com/astral-sh/uv/pull/21555">#21555</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately (<a href="https://redirect.github.com/astral-sh/uv/pull/21279">#21279</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention (<a href="https://redirect.github.com/astral-sh/uv/pull/18713">#18713</a>)</li> <li>Prefer <code>core-metadata</code> over legacy aliases in JSON index responses (<a href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li> </ul> <h2>Install uv 0.12.13</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1 | iex" </code></pre> <h2>Download uv 0.12.13</h2> <table> <thead> <tr> <th>File</th> <th>Platform</th> <th>Checksum</th> </tr> </thead> <tbody> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz">uv-aarch64-apple-darwin.tar.gz</a></td> <td>Apple Silicon macOS</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz">uv-x86_64-apple-darwin.tar.gz</a></td> <td>Intel macOS</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-pc-windows-msvc.zip">uv-aarch64-pc-windows-msvc.zip</a></td> <td>ARM64 Windows</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-i686-pc-windows-msvc.zip">uv-i686-pc-windows-msvc.zip</a></td> <td>x86 Windows</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-i686-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-pc-windows-msvc.zip">uv-x86_64-pc-windows-msvc.zip</a></td> <td>x64 Windows</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> <tr> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-unknown-linux-gnu.tar.gz">uv-aarch64-unknown-linux-gnu.tar.gz</a></td> <td>ARM64 Linux</td> <td><a href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td> </tr> </tbody> </table> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's changelog</a>.</em></p> <blockquote> <h2>0.12.13</h2> <p>Released on 2026-09-10.</p> <h3>Python</h3> <ul> <li>Add GraalPy 3.13.0 (<a href="https://redirect.github.com/astral-sh/uv/pull/21431">#21431</a>)</li> </ul> <h3>Enhancements</h3> <ul> <li>Verify hashes when downloading PEP 658 metadata sidecars (<a href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li> </ul> <h3>Preview features</h3> <ul> <li>Respect <code>ty</code> exclusions when <code>uv check</code> automatically selects members of a virtual workspace (<a href="https://redirect.github.com/astral-sh/uv/pull/21555">#21555</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately (<a href="https://redirect.github.com/astral-sh/uv/pull/21279">#21279</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention (<a href="https://redirect.github.com/astral-sh/uv/pull/18713">#18713</a>)</li> <li>Prefer <code>core-metadata</code> over legacy aliases in JSON index responses (<a href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li> </ul> <h2>0.12.12</h2> <p>Released on 2026-09-09.</p> <p>The executables in our macOS and Windows release archives and <code>uv</code> and <code>uv_build</code> wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.</p> <h3>Bug fixes</h3> <ul> <li>Exclude distributions uploaded after the <code>exclude-newer</code> cutoff from lockfiles and generated requirement hashes (<a href="https://redirect.github.com/astral-sh/uv/pull/21539">#21539</a>)</li> </ul> <h2>0.12.11</h2> <p>Released on 2026-09-08.</p> <h3>Preview features</h3> <ul> <li>Generate missing artifact hashes when exporting <code>pylock.toml</code> files to ensure they conform to PEP 751 (<a href="https://redirect.github.com/astral-sh/uv/pull/20146">#20146</a>)</li> <li>Warn when <code>pylock.toml</code> artifact hash tables are empty, which will be rejected in a future uv release (<a href="https://redirect.github.com/astral-sh/uv/pull/21462">#21462</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements (<a href="https://redirect.github.com/astral-sh/uv/pull/21478">#21478</a>)</li> <li>Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files (<a href="https://redirect.github.com/astral-sh/uv/pull/21468">#21468</a>)</li> <li>Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads (<a href="https://redirect.github.com/astral-sh/uv/pull/21500">#21500</a>)</li> <li>Speed up local wheel installs by reusing ZIP readers and buffers across extracted files (<a href="https://redirect.github.com/astral-sh/uv/pull/21499">#21499</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/uv/commit/0ebbd9274a55a8a53a13970be3b97e4209598e17"><code>0ebbd92</code></a> Bump version to 0.12.13 (<a href="https://redirect.github.com/astral-sh/uv/issues/21594">#21594</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/17ccae34815e249c66e53abe21916c3c0b6413e5"><code>17ccae3</code></a> Use separate Depot projects for Docker development builds (<a href="https://redirect.github.com/astral-sh/uv/issues/21591">#21591</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/8c18e15bd36dff0e17509cc68c3721798ae1ec2b"><code>8c18e15</code></a> Use the workflow revision for PR security review configuration (<a href="https://redirect.github.com/astral-sh/uv/issues/21592">#21592</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/9ebb1f6a72db257a689049ee060b7cf93638aada"><code>9ebb1f6</code></a> Clarify release pipeline job names (<a href="https://redirect.github.com/astral-sh/uv/issues/21561">#21561</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/d87450d82b3941507e48ac8b57f72a9d00709289"><code>d87450d</code></a> Omit unused <code>exclude-newer-package</code> entries from script locks (<a href="https://redirect.github.com/astral-sh/uv/issues/21589">#21589</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/911f3a208c104b07b2f4da3a2283564d9a95c403"><code>911f3a2</code></a> Refactor release artifact handling (<a href="https://redirect.github.com/astral-sh/uv/issues/21556">#21556</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/a712e811024933ec441667659d6df73c04f5b678"><code>a712e81</code></a> Separate Docker release builds from publishing (<a href="https://redirect.github.com/astral-sh/uv/issues/21586">#21586</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/4196dae60a0cc542bd43c0188f8b4c6dbfa0df98"><code>4196dae</code></a> Use xhigh effort for PR security review (<a href="https://redirect.github.com/astral-sh/uv/issues/21530">#21530</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/a51624b4791456260f72068ae878796233f72809"><code>a51624b</code></a> Reduce PR security review reporting work (<a href="https://redirect.github.com/astral-sh/uv/issues/21528">#21528</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/63e28b69821b4b55b90287d799cbf97ff6ba0f74"><code>63e28b6</code></a> Use <code>editpe</code> for trampoline resource edits (<a href="https://redirect.github.com/astral-sh/uv/issues/18713">#18713</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/uv/compare/0.12.9...0.12.13">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
+2
-2
@@ -4,7 +4,7 @@ ARG BUILDPLATFORM
|
||||
ARG BUILDARCH
|
||||
|
||||
# Frontend build stage.
|
||||
FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf AS frontend-builder
|
||||
FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:50c8e8ca1d27439048670df5883f32d57cf81cff6233222c893fd0d9884cbd81 AS frontend-builder
|
||||
|
||||
# Helpful debug output to see what platforms BuildKit thinks it's using
|
||||
RUN echo "BUILDPLATFORM=$BUILDPLATFORM BUILDARCH=$BUILDARCH TARGETPLATFORM=$TARGETPLATFORM TARGETARCH=$TARGETARCH"
|
||||
@@ -28,7 +28,7 @@ RUN npm run build
|
||||
# than copied into the image. A COPY here would land ~24 MB in a `base` layer that
|
||||
# every published image inherits, and a later `rm` cannot take it back out again --
|
||||
# a RUN adds a layer, it does not rewrite the one underneath.
|
||||
FROM ghcr.io/astral-sh/uv:0.12.9@sha256:8b940d3a9d65bed080436972241af2e21c84b5e8c9193f7014ed71479ee795ff AS uv
|
||||
FROM ghcr.io/astral-sh/uv:0.12.13@sha256:b485bd65cc2cf1c9a93b3554012c9c3778cf7b1b5fd3d3096ce9e1226c97e1e6 AS uv
|
||||
|
||||
# Use python-slim as the base image
|
||||
FROM python:3.14.7-slim@sha256:cad9a2c871761c413caa6fdd6441c783451e740a48aaeba60ae62a8b53525ef6 AS base
|
||||
|
||||
Reference in New Issue
Block a user