build(deps): bump astral-sh/uv from 0.12.16 to 0.12.19 in the docker-base-image-digests group across 1 directory (#1392)

> [!WARNING]
> Cooldown could not be applied because no publication date was
available from the registry.
>

Bumps the docker-base-image-digests group with 1 update in the /
directory: [astral-sh/uv](https://github.com/astral-sh/uv).

Updates `astral-sh/uv` from 0.12.16 to 0.12.19
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/releases">astral-sh/uv's
releases</a>.</em></p>
<blockquote>
<h2>0.12.19</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Python</h3>
<ul>
<li>Add PyPy 3.11.16 and 3.12.14 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
<li>Update GraalPy 3.13.0 to build 25.4.4 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Format upload URLs with backticks in <code>uv publish</code> errors
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Run build-backend hooks with lazy imports on CPython 3.15 and later
using the <code>build-lazy-imports</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li>
<li>Omit unused resolution settings from <code>uv.lock</code> and ignore
changes to them when checking lockfile freshness with the
<code>resolution-inputs</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Preserve signed and encoded query parameters in direct-URL metadata
to avoid reinstalling unchanged packages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li>
<li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during
installed-package checks, matching resolution (<a
href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li>
<li>Avoid collisions between Git checkout readiness markers and
<code>.ok</code> files in dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li>
<li>Preserve always-false <code>python_version</code> markers when
parsing their serialized form (<a
href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li>
</ul>
<h3>Rust API</h3>
<ul>
<li>Restore the public <code>FlatDistributions</code> export and its
<code>BTreeMap</code> conversion for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Make individual preview-feature reference entries linkable by name
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li>
</ul>
<h2>Install uv 0.12.19</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1
| iex&quot;
</code></pre>
<h2>Download uv 0.12.19</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's
changelog</a>.</em></p>
<blockquote>
<h2>0.12.19</h2>
<p>Released on 2026-09-24.</p>
<h3>Python</h3>
<ul>
<li>Add PyPy 3.11.16 and 3.12.14 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
<li>Update GraalPy 3.13.0 to build 25.4.4 (<a
href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li>
</ul>
<h3>Enhancements</h3>
<ul>
<li>Format upload URLs with backticks in <code>uv publish</code> errors
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Run build-backend hooks with lazy imports on CPython 3.15 and later
using the <code>build-lazy-imports</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li>
<li>Omit unused resolution settings from <code>uv.lock</code> and ignore
changes to them when checking lockfile freshness with the
<code>resolution-inputs</code> preview feature (<a
href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Preserve signed and encoded query parameters in direct-URL metadata
to avoid reinstalling unchanged packages (<a
href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li>
<li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during
installed-package checks, matching resolution (<a
href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li>
<li>Avoid collisions between Git checkout readiness markers and
<code>.ok</code> files in dependencies (<a
href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li>
<li>Preserve always-false <code>python_version</code> markers when
parsing their serialized form (<a
href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li>
</ul>
<h3>Rust API</h3>
<ul>
<li>Restore the public <code>FlatDistributions</code> export and its
<code>BTreeMap</code> conversion for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Make individual preview-feature reference entries linkable by name
(<a
href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li>
</ul>
<h2>0.12.18</h2>
<p>Released on 2026-09-22.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7">GHSA-2cv4-cqwr-gwf7</a>,
which is a path traversal weakness during wheel installation on Windows.
No other platforms are affected by this advisory.</p>
<h3>Enhancements</h3>
<ul>
<li>Add <code>--output-format json</code> to <code>uv pip install</code>
and <code>uv pip sync</code>, including for <code>--dry-run</code> and
<code>--check</code> (<a
href="https://redirect.github.com/astral-sh/uv/pull/21893">#21893</a>)</li>
<li>Add <code>--check</code> to <code>uv pip install</code> and <code>uv
pip sync</code> to report planned changes without modifying the
environment (<a
href="https://redirect.github.com/astral-sh/uv/pull/21844">#21844</a>)</li>
<li>Identify failures from <code>get_requires_for_build_*</code> hooks
correctly in build errors (<a
href="https://redirect.github.com/astral-sh/uv/pull/21881">#21881</a>)</li>
</ul>
<h3>Preview features</h3>
<ul>
<li>Validate build requirements for <code>uv build
--no-build-isolation</code> with <code>--preview-features
build-dependency-check</code>; use <code>--skip-dependency-check</code>
to opt out (<a
href="https://redirect.github.com/astral-sh/uv/pull/21880">#21880</a>)</li>
</ul>
<h3>Performance</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/uv/commit/bea138450f0e620a4ce5765b0e38cff7b9f0799f"><code>bea1384</code></a>
Bump version to 0.12.19 (<a
href="https://redirect.github.com/astral-sh/uv/issues/21975">#21975</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/299a93de4b94e754f260c673d2de456afbdd4fb7"><code>299a93d</code></a>
Sync latest Python releases (<a
href="https://redirect.github.com/astral-sh/uv/issues/21970">#21970</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/30de9e2cc92018c7c16a1ab66bb9b8341fbf0eff"><code>30de9e2</code></a>
Preserve query parameters in direct URL metadata (<a
href="https://redirect.github.com/astral-sh/uv/issues/21971">#21971</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/0e7433eee906fe81709c95c5bde556263367f21f"><code>0e7433e</code></a>
Filter distribution hashes in tests (<a
href="https://redirect.github.com/astral-sh/uv/issues/21941">#21941</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/c73db78f0b00580b3c67279b59b85153a9d0264d"><code>c73db78</code></a>
Omit unused runtime settings from lockfiles (<a
href="https://redirect.github.com/astral-sh/uv/issues/21913">#21913</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/ad123420aaa75b3bdbccf81496aaece8b9045b30"><code>ad12342</code></a>
Add a preview feature for lazy build backend imports (<a
href="https://redirect.github.com/astral-sh/uv/issues/21967">#21967</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/dd965a276182e2d46d80439feecd03216cc6643a"><code>dd965a2</code></a>
Restore <code>FlatDistributions</code> for downstream resolvers (<a
href="https://redirect.github.com/astral-sh/uv/issues/21965">#21965</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/214d7f677585fbb0bb46fadef890335e388641c0"><code>214d7f6</code></a>
Use Astra for PR security reviews (<a
href="https://redirect.github.com/astral-sh/uv/issues/21959">#21959</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/3db665232544183edcb80dd7077b8051b365e236"><code>3db6652</code></a>
Disable incremental compilation when publishing docs (<a
href="https://redirect.github.com/astral-sh/uv/issues/21955">#21955</a>)</li>
<li><a
href="https://github.com/astral-sh/uv/commit/e18f413b23bfe5f33bcc1a3a3de330e4716aedcf"><code>e18f413</code></a>
Reproduce editable project relocation failure (<a
href="https://redirect.github.com/astral-sh/uv/issues/21948">#21948</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/uv/compare/0.12.16...0.12.19">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: CaliBrain <calibrain@l4n.xyz>
This commit is contained in:
dependabot[bot]
2026-09-25 19:18:30 -04:00
committed by GitHub
co-authored by CaliBrain
parent a05e002305
commit efb1f66bc3
+1 -1
View File
@@ -28,7 +28,7 @@ RUN npm run build
# than copied into the image. A COPY here would land ~24 MB in a `base` layer that
# every published image inherits, and a later `rm` cannot take it back out again --
# a RUN adds a layer, it does not rewrite the one underneath.
FROM ghcr.io/astral-sh/uv:0.12.16@sha256:adc68cd785ca65ea25c0611043b0a00b4ea3a22e1b54102fc084406d888082ee AS uv
FROM ghcr.io/astral-sh/uv:0.12.19@sha256:04d046b13e60d6bcec73cbc5e1cad25d680dea90c8573340950a0ac2d1aef424 AS uv
# Use python-slim as the base image
FROM python:3.14.7-slim@sha256:cad9a2c871761c413caa6fdd6441c783451e740a48aaeba60ae62a8b53525ef6 AS base