build(deps): bump the docker-base-image-digests group with 2 updates (#1328)

> [!WARNING]
> Cooldown could not be applied because no publication date was
available from the registry.
>

Bumps the docker-base-image-digests group with 2 updates: node and
[astral-sh/uv](https://github.com/astral-sh/uv).

Updates `node` from `e67514e` to `50c8e8c`

Updates `astral-sh/uv` from 0.12.9 to 0.12.13
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/releases">astral-sh/uv's
releases</a>.</em></p>
<blockquote>
<h2>0.12.13</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-10.</p>
<h3>Python</h3>
<ul>
<li>Add GraalPy 3.13.0 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21431">#21431</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Verify hashes when downloading PEP 658 metadata sidecars (<a
href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Respect <code>ty</code> exclusions when <code>uv check</code>
automatically selects members of a virtual workspace (<a
href="https://redirect.github.com/astral-sh/uv/pull/21555">#21555</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid full wheel downloads during resolution by reusing supported
hashes from direct URL fragments when metadata is available separately
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21279">#21279</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Edit Windows entry-point launcher resources in memory to support
Nano Server and reduce antivirus contention (<a
href="https://redirect.github.com/astral-sh/uv/pull/18713">#18713</a>)</li>
<li>Prefer <code>core-metadata</code> over legacy aliases in JSON index
responses (<a
href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li>
</ul>
<h2>Install uv 0.12.13</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1
| iex&quot;
</code></pre>
<h2>Download uv 0.12.13</h2>
<table>
<thead>
<tr>
<th>File</th>
<th>Platform</th>
<th>Checksum</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz">uv-aarch64-apple-darwin.tar.gz</a></td>
<td>Apple Silicon macOS</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
</tr>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz">uv-x86_64-apple-darwin.tar.gz</a></td>
<td>Intel macOS</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
</tr>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-pc-windows-msvc.zip">uv-aarch64-pc-windows-msvc.zip</a></td>
<td>ARM64 Windows</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-pc-windows-msvc.zip.sha256">checksum</a></td>
</tr>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-i686-pc-windows-msvc.zip">uv-i686-pc-windows-msvc.zip</a></td>
<td>x86 Windows</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-i686-pc-windows-msvc.zip.sha256">checksum</a></td>
</tr>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-pc-windows-msvc.zip">uv-x86_64-pc-windows-msvc.zip</a></td>
<td>x64 Windows</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
</tr>
<tr>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-unknown-linux-gnu.tar.gz">uv-aarch64-unknown-linux-gnu.tar.gz</a></td>
<td>ARM64 Linux</td>
<td><a
href="https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's
changelog</a>.</em></p>
<blockquote>
<h2>0.12.13</h2>
<p>Released on 2026-09-10.</p>
<h3>Python</h3>
<ul>
<li>Add GraalPy 3.13.0 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21431">#21431</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Verify hashes when downloading PEP 658 metadata sidecars (<a
href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Respect <code>ty</code> exclusions when <code>uv check</code>
automatically selects members of a virtual workspace (<a
href="https://redirect.github.com/astral-sh/uv/pull/21555">#21555</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid full wheel downloads during resolution by reusing supported
hashes from direct URL fragments when metadata is available separately
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21279">#21279</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Edit Windows entry-point launcher resources in memory to support
Nano Server and reduce antivirus contention (<a
href="https://redirect.github.com/astral-sh/uv/pull/18713">#18713</a>)</li>
<li>Prefer <code>core-metadata</code> over legacy aliases in JSON index
responses (<a
href="https://redirect.github.com/astral-sh/uv/pull/21563">#21563</a>)</li>
</ul>
<h2>0.12.12</h2>
<p>Released on 2026-09-09.</p>
<p>The executables in our macOS and Windows release archives and
<code>uv</code> and <code>uv_build</code> wheels are now code-signed.
macOS executables are signed with an Apple Developer ID certificate and
notarized by Apple. Windows executables have timestamped Authenticode
signatures from Azure Artifact Signing. This enables verification of the
release publisher and binary integrity, supports publisher-based
allowlisting, and should reduce security warnings and antivirus false
positives.</p>
<h3>Bug fixes</h3>
<ul>
<li>Exclude distributions uploaded after the <code>exclude-newer</code>
cutoff from lockfiles and generated requirement hashes (<a
href="https://redirect.github.com/astral-sh/uv/pull/21539">#21539</a>)</li>
</ul>
<h2>0.12.11</h2>
<p>Released on 2026-09-08.</p>
<h3>Preview features</h3>
<ul>
<li>Generate missing artifact hashes when exporting
<code>pylock.toml</code> files to ensure they conform to PEP 751 (<a
href="https://redirect.github.com/astral-sh/uv/pull/20146">#20146</a>)</li>
<li>Warn when <code>pylock.toml</code> artifact hash tables are empty,
which will be rejected in a future uv release (<a
href="https://redirect.github.com/astral-sh/uv/pull/21462">#21462</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Speed up installs that overwrite existing files by eliminating
per-file temporary directories for atomic hard-link, symlink, and
reflink replacements (<a
href="https://redirect.github.com/astral-sh/uv/pull/21478">#21478</a>)</li>
<li>Speed up installs that merge copied wheels into existing
environments by replacing per-file temporary directories with adjacent
temporary files (<a
href="https://redirect.github.com/astral-sh/uv/pull/21468">#21468</a>)</li>
<li>Speed up local wheel installs by replacing the shared ZIP cursor
lock with positioned reads (<a
href="https://redirect.github.com/astral-sh/uv/pull/21500">#21500</a>)</li>
<li>Speed up local wheel installs by reusing ZIP readers and buffers
across extracted files (<a
href="https://redirect.github.com/astral-sh/uv/pull/21499">#21499</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/uv/commit/0ebbd9274a55a8a53a13970be3b97e4209598e17"><code>0ebbd92</code></a>
Bump version to 0.12.13 (<a
href="https://redirect.github.com/astral-sh/uv/issues/21594">#21594</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/17ccae34815e249c66e53abe21916c3c0b6413e5"><code>17ccae3</code></a>
Use separate Depot projects for Docker development builds (<a
href="https://redirect.github.com/astral-sh/uv/issues/21591">#21591</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/8c18e15bd36dff0e17509cc68c3721798ae1ec2b"><code>8c18e15</code></a>
Use the workflow revision for PR security review configuration (<a
href="https://redirect.github.com/astral-sh/uv/issues/21592">#21592</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/9ebb1f6a72db257a689049ee060b7cf93638aada"><code>9ebb1f6</code></a>
Clarify release pipeline job names (<a
href="https://redirect.github.com/astral-sh/uv/issues/21561">#21561</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/d87450d82b3941507e48ac8b57f72a9d00709289"><code>d87450d</code></a>
Omit unused <code>exclude-newer-package</code> entries from script locks
(<a
href="https://redirect.github.com/astral-sh/uv/issues/21589">#21589</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/911f3a208c104b07b2f4da3a2283564d9a95c403"><code>911f3a2</code></a>
Refactor release artifact handling (<a
href="https://redirect.github.com/astral-sh/uv/issues/21556">#21556</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/a712e811024933ec441667659d6df73c04f5b678"><code>a712e81</code></a>
Separate Docker release builds from publishing (<a
href="https://redirect.github.com/astral-sh/uv/issues/21586">#21586</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/4196dae60a0cc542bd43c0188f8b4c6dbfa0df98"><code>4196dae</code></a>
Use xhigh effort for PR security review (<a
href="https://redirect.github.com/astral-sh/uv/issues/21530">#21530</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/a51624b4791456260f72068ae878796233f72809"><code>a51624b</code></a>
Reduce PR security review reporting work (<a
href="https://redirect.github.com/astral-sh/uv/issues/21528">#21528</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/63e28b69821b4b55b90287d799cbf97ff6ba0f74"><code>63e28b6</code></a>
Use <code>editpe</code> for trampoline resource edits (<a
href="https://redirect.github.com/astral-sh/uv/issues/18713">#18713</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/uv/compare/0.12.9...0.12.13">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
dependabot[bot]
2026-09-11 02:07:12 -04:00
committed by GitHub
parent 99e0cfde3d
commit 9eb47989ec
+2 -2
View File
@@ -4,7 +4,7 @@ ARG BUILDPLATFORM
ARG BUILDARCH
# Frontend build stage.
FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf AS frontend-builder
FROM --platform=$BUILDPLATFORM node:24-alpine@sha256:50c8e8ca1d27439048670df5883f32d57cf81cff6233222c893fd0d9884cbd81 AS frontend-builder
# Helpful debug output to see what platforms BuildKit thinks it's using
RUN echo "BUILDPLATFORM=$BUILDPLATFORM BUILDARCH=$BUILDARCH TARGETPLATFORM=$TARGETPLATFORM TARGETARCH=$TARGETARCH"
@@ -28,7 +28,7 @@ RUN npm run build
# than copied into the image. A COPY here would land ~24 MB in a `base` layer that
# every published image inherits, and a later `rm` cannot take it back out again --
# a RUN adds a layer, it does not rewrite the one underneath.
FROM ghcr.io/astral-sh/uv:0.12.9@sha256:8b940d3a9d65bed080436972241af2e21c84b5e8c9193f7014ed71479ee795ff AS uv
FROM ghcr.io/astral-sh/uv:0.12.13@sha256:b485bd65cc2cf1c9a93b3554012c9c3778cf7b1b5fd3d3096ce9e1226c97e1e6 AS uv
# Use python-slim as the base image
FROM python:3.14.7-slim@sha256:cad9a2c871761c413caa6fdd6441c783451e740a48aaeba60ae62a8b53525ef6 AS base