mirror of
https://github.com/calibrain/shelfmark.git
synced 2026-10-04 07:31:12 +01:00
build(deps): bump astral-sh/uv from 0.12.16 to 0.12.19 in the docker-base-image-digests group across 1 directory (#1392)
> [!WARNING] > Cooldown could not be applied because no publication date was available from the registry. > Bumps the docker-base-image-digests group with 1 update in the / directory: [astral-sh/uv](https://github.com/astral-sh/uv). Updates `astral-sh/uv` from 0.12.16 to 0.12.19 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/uv/releases">astral-sh/uv's releases</a>.</em></p> <blockquote> <h2>0.12.19</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Python</h3> <ul> <li>Add PyPy 3.11.16 and 3.12.14 (<a href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li> <li>Update GraalPy 3.13.0 to build 25.4.4 (<a href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li> </ul> <h3>Enhancements</h3> <ul> <li>Format upload URLs with backticks in <code>uv publish</code> errors (<a href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li> </ul> <h3>Preview features</h3> <ul> <li>Run build-backend hooks with lazy imports on CPython 3.15 and later using the <code>build-lazy-imports</code> preview feature (<a href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li> <li>Omit unused resolution settings from <code>uv.lock</code> and ignore changes to them when checking lockfile freshness with the <code>resolution-inputs</code> preview feature (<a href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (<a href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li> <li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during installed-package checks, matching resolution (<a href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li> <li>Avoid collisions between Git checkout readiness markers and <code>.ok</code> files in dependencies (<a href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li> <li>Preserve always-false <code>python_version</code> markers when parsing their serialized form (<a href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li> </ul> <h3>Rust API</h3> <ul> <li>Restore the public <code>FlatDistributions</code> export and its <code>BTreeMap</code> conversion for downstream resolvers (<a href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Make individual preview-feature reference entries linkable by name (<a href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li> </ul> <h2>Install uv 0.12.19</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1 | iex" </code></pre> <h2>Download uv 0.12.19</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/uv/blob/main/CHANGELOG.md">astral-sh/uv's changelog</a>.</em></p> <blockquote> <h2>0.12.19</h2> <p>Released on 2026-09-24.</p> <h3>Python</h3> <ul> <li>Add PyPy 3.11.16 and 3.12.14 (<a href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li> <li>Update GraalPy 3.13.0 to build 25.4.4 (<a href="https://redirect.github.com/astral-sh/uv/pull/21847">#21847</a>)</li> </ul> <h3>Enhancements</h3> <ul> <li>Format upload URLs with backticks in <code>uv publish</code> errors (<a href="https://redirect.github.com/astral-sh/uv/pull/21934">#21934</a>)</li> </ul> <h3>Preview features</h3> <ul> <li>Run build-backend hooks with lazy imports on CPython 3.15 and later using the <code>build-lazy-imports</code> preview feature (<a href="https://redirect.github.com/astral-sh/uv/pull/21967">#21967</a>)</li> <li>Omit unused resolution settings from <code>uv.lock</code> and ignore changes to them when checking lockfile freshness with the <code>resolution-inputs</code> preview feature (<a href="https://redirect.github.com/astral-sh/uv/pull/21913">#21913</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (<a href="https://redirect.github.com/astral-sh/uv/pull/21971">#21971</a>)</li> <li>Recognize <code>1.0.0</code> as satisfying <code>===1</code> during installed-package checks, matching resolution (<a href="https://redirect.github.com/astral-sh/uv/pull/21931">#21931</a>)</li> <li>Avoid collisions between Git checkout readiness markers and <code>.ok</code> files in dependencies (<a href="https://redirect.github.com/astral-sh/uv/pull/21891">#21891</a>)</li> <li>Preserve always-false <code>python_version</code> markers when parsing their serialized form (<a href="https://redirect.github.com/astral-sh/uv/pull/21939">#21939</a>)</li> </ul> <h3>Rust API</h3> <ul> <li>Restore the public <code>FlatDistributions</code> export and its <code>BTreeMap</code> conversion for downstream resolvers (<a href="https://redirect.github.com/astral-sh/uv/pull/21965">#21965</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Make individual preview-feature reference entries linkable by name (<a href="https://redirect.github.com/astral-sh/uv/pull/21950">#21950</a>)</li> </ul> <h2>0.12.18</h2> <p>Released on 2026-09-22.</p> <p>This release addresses <a href="https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7">GHSA-2cv4-cqwr-gwf7</a>, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.</p> <h3>Enhancements</h3> <ul> <li>Add <code>--output-format json</code> to <code>uv pip install</code> and <code>uv pip sync</code>, including for <code>--dry-run</code> and <code>--check</code> (<a href="https://redirect.github.com/astral-sh/uv/pull/21893">#21893</a>)</li> <li>Add <code>--check</code> to <code>uv pip install</code> and <code>uv pip sync</code> to report planned changes without modifying the environment (<a href="https://redirect.github.com/astral-sh/uv/pull/21844">#21844</a>)</li> <li>Identify failures from <code>get_requires_for_build_*</code> hooks correctly in build errors (<a href="https://redirect.github.com/astral-sh/uv/pull/21881">#21881</a>)</li> </ul> <h3>Preview features</h3> <ul> <li>Validate build requirements for <code>uv build --no-build-isolation</code> with <code>--preview-features build-dependency-check</code>; use <code>--skip-dependency-check</code> to opt out (<a href="https://redirect.github.com/astral-sh/uv/pull/21880">#21880</a>)</li> </ul> <h3>Performance</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/uv/commit/bea138450f0e620a4ce5765b0e38cff7b9f0799f"><code>bea1384</code></a> Bump version to 0.12.19 (<a href="https://redirect.github.com/astral-sh/uv/issues/21975">#21975</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/299a93de4b94e754f260c673d2de456afbdd4fb7"><code>299a93d</code></a> Sync latest Python releases (<a href="https://redirect.github.com/astral-sh/uv/issues/21970">#21970</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/30de9e2cc92018c7c16a1ab66bb9b8341fbf0eff"><code>30de9e2</code></a> Preserve query parameters in direct URL metadata (<a href="https://redirect.github.com/astral-sh/uv/issues/21971">#21971</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/0e7433eee906fe81709c95c5bde556263367f21f"><code>0e7433e</code></a> Filter distribution hashes in tests (<a href="https://redirect.github.com/astral-sh/uv/issues/21941">#21941</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/c73db78f0b00580b3c67279b59b85153a9d0264d"><code>c73db78</code></a> Omit unused runtime settings from lockfiles (<a href="https://redirect.github.com/astral-sh/uv/issues/21913">#21913</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/ad123420aaa75b3bdbccf81496aaece8b9045b30"><code>ad12342</code></a> Add a preview feature for lazy build backend imports (<a href="https://redirect.github.com/astral-sh/uv/issues/21967">#21967</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/dd965a276182e2d46d80439feecd03216cc6643a"><code>dd965a2</code></a> Restore <code>FlatDistributions</code> for downstream resolvers (<a href="https://redirect.github.com/astral-sh/uv/issues/21965">#21965</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/214d7f677585fbb0bb46fadef890335e388641c0"><code>214d7f6</code></a> Use Astra for PR security reviews (<a href="https://redirect.github.com/astral-sh/uv/issues/21959">#21959</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/3db665232544183edcb80dd7077b8051b365e236"><code>3db6652</code></a> Disable incremental compilation when publishing docs (<a href="https://redirect.github.com/astral-sh/uv/issues/21955">#21955</a>)</li> <li><a href="https://github.com/astral-sh/uv/commit/e18f413b23bfe5f33bcc1a3a3de330e4716aedcf"><code>e18f413</code></a> Reproduce editable project relocation failure (<a href="https://redirect.github.com/astral-sh/uv/issues/21948">#21948</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/uv/compare/0.12.16...0.12.19">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: CaliBrain <calibrain@l4n.xyz>
This commit is contained in:
co-authored by
CaliBrain
parent
a05e002305
commit
efb1f66bc3
+1
-1
@@ -28,7 +28,7 @@ RUN npm run build
|
||||
# than copied into the image. A COPY here would land ~24 MB in a `base` layer that
|
||||
# every published image inherits, and a later `rm` cannot take it back out again --
|
||||
# a RUN adds a layer, it does not rewrite the one underneath.
|
||||
FROM ghcr.io/astral-sh/uv:0.12.16@sha256:adc68cd785ca65ea25c0611043b0a00b4ea3a22e1b54102fc084406d888082ee AS uv
|
||||
FROM ghcr.io/astral-sh/uv:0.12.19@sha256:04d046b13e60d6bcec73cbc5e1cad25d680dea90c8573340950a0ac2d1aef424 AS uv
|
||||
|
||||
# Use python-slim as the base image
|
||||
FROM python:3.14.7-slim@sha256:cad9a2c871761c413caa6fdd6441c783451e740a48aaeba60ae62a8b53525ef6 AS base
|
||||
|
||||
Reference in New Issue
Block a user