Skip to content

Enable PGO for Linux x86-64 uv releases - #21001

Merged
charliermarsh merged 22 commits into
mainfrom
charlie/uv-linux-pgo-prototype
Aug 17, 2026
Merged

charliermarsh merged 22 commits into
mainfrom
charlie/uv-linux-pgo-prototype

Conversation

@charliermarsh

@charliermarsh charliermarsh commented Aug 7, 2026 •

Copy link
Copy Markdown
Member

Summary

This PR enables PGO for uv releases, starting with Linux x86-64.

Design

The release pipeline is modified as follows:

  • We build instrumented uv and uvx release binaries inside the existing manylinux container.
  • We train directly on eleven shared test/ecosystem fixtures: cibuildwheel, Cookiecutter, Flask, HTTPX, LLM, the OpenAI Python SDK, Poetry, pytest-cov, Sentry, Zulip, and the 38-project pyx workspace.
  • Every project exercises cold and warm uv pip compile resolution, cold and warm uv lock resolution, uv export, uv pip installation, and uv sync installation on every release platform.
  • Per-project exclude-dependencies settings omit packages without compatible release-platform wheels while preserving the rest of each real dependency graph.
  • Raw profiles are merged online by workload family, then merged with llvm-profdata and fed back into the existing maturin build.
  • JupyterLab, Saleor, Semantic Kernel, Transformers, and Warehouse remain separate, held-out evaluation projects.

Results

We benchmarked the builds on Linux x86-64 using the expanded corpus for training and five separate held-out ecosystem projects for evaluation.

Held-out project Dependency resolution Wheel installation Project locking Lockfile export
JupyterLab 11.2% faster 0.0% 10.1% faster 10.6% faster
Semantic Kernel 9.3% faster 7.1% faster 12.5% faster 8.7% faster
Transformers 11.7% faster 4.1% faster 9.5% faster 11.0% faster
Saleor — — 9.7% faster 10.0% faster
Warehouse — — 9.7% faster 7.6% faster
Geometric mean 10.7% faster 3.7% faster 10.3% faster 9.6% faster

Across all sixteen held-out workloads, wall time decreased by 8.9% (95% CI: 8.4–9.8%) and CPU time decreased by 8.4% (95% CI: 7.9–9.0%). The matched Linux executable was 13.3% smaller (58.91 MB to 51.05 MB), or 12.3% smaller after gzip compression (22.68 MB to 19.90 MB).

(Saleor and Warehouse include source-only dependencies, so they are benchmarked on locking and export rather than wheel-only installation.)

Stack

Additional platforms are covered in subsequent PRs in the stack: macOS ARM64, Windows x86-64, and Linux ARM64.

Ruff and ty follow the same approach; see the stacks here:

@charliermarsh charliermarsh changed the title Add profile-guided optimization for Linux x86-64 releases Enable PGO for Linux x86-64 uv releases Aug 7, 2026
charliermarsh added a commit to astral-sh/ruff that referenced this pull request Aug 10, 2026
## Summary

This PR enables PGO for Ruff releases, starting with Linux x86-64.

### Design

The release pipeline is modified as follows:

- We build an instrumented, stripped release binary.
- We run `check` and `format` on a corpus of projects from our ecosystem
reports -- specifically, eight of the pinned ecosystem projects that we
use in the ty CI. (In total, it's 502 Python and stub files.)
- We merge the profiles via `llvm-profdata`.
- We feed the result back into the existing `maturin` build.

### Results

We evaluate performance on a held-out corpus: Prefect, Django, Pandas,
scikit-learn, SciPy, and SymPy.

Results are as follows:

| Held-out project | `ruff check` | `ruff format` |
| --- | ---: | ---: |
| Django | 10.9% faster | 6.6% faster |
| pandas | 16.3% faster | 9.7% faster |
| scikit-learn | 10.8% faster | 7.9% faster |
| SciPy | 14.7% faster | 5.6% faster |
| SymPy | 17.1% faster | 11.4% faster |
| Geometric mean | **14.0% faster** | **8.3% faster** |

Beyond runtime:

- **Binary size decreased by 6.2%** (27.96 MB to 26.23 MB).
- **Release pipeline gets about 2x longer** (non-PGO release build took
7m22s; PGO pipeline took 15m14s (8m35s instrumented training plus 6m39s
optimized wheel).

### Stack

Additional platforms are covered in subsequent PRs in the stacked;
platforms that are lower-priority at at-all difficult to run on natively
are omitted. In the end, I'm targeting Linux x86-64, Linux ARM, macOS
ARM, and Windows x86-64.

I also attempted BOLT in #27588,
but I've decided against pursuing that for now; see the results in that
PR which speak for themselves.

ty and uv will follow the same approach; see the stacks here:

- astral-sh/ty#4213
- astral-sh/uv#21001

See: #7055.
@charliermarsh
charliermarsh marked this pull request as ready for review August 10, 2026 20:23
@charliermarsh charliermarsh added the internal:releases Related to building and distributing release artifacts of uv label Aug 10, 2026
@charliermarsh
charliermarsh marked this pull request as draft August 10, 2026 20:30
@codspeed

codspeed Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 31 untouched benchmarks
⏩ 6 skipped benchmarks1


Comparing charlie/uv-linux-pgo-prototype (993b31d) with main (4d4f3e3)

Open in CodSpeed

Footnotes

  1. 6 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@charliermarsh
charliermarsh marked this pull request as ready for review August 10, 2026 21:13
@charliermarsh
charliermarsh marked this pull request as draft August 11, 2026 11:10
Comment thread .github/workflows/build-release-binaries.yml Outdated
Comment thread scripts/build_uv_pgo.py Outdated
Comment thread scripts/build_uv_pgo.py Outdated
charliermarsh added a commit to astral-sh/ty that referenced this pull request Aug 11, 2026
## Summary

This PR enables PGO for ty releases, starting with Linux x86-64. The
approach follows that outlined in
astral-sh/ruff#27570.

### Design

The release pipeline is modified as follows:

- We build an instrumented release binary using the Rust toolchain
pinned by the Ruff submodule.
- We run `ty check` on the same ten pinned ecosystem projects used by
Ruff. In total, the corpus contains 618 Python and stub files.
- We also exercise `ty server` against a temporary project, covering
diagnostics, hover, go-to-definition, completion, and incremental
cross-file edits.
- We merge the profiles via `llvm-profdata`.
- We derive LLVM's hot-code threshold from the profile's 95th
percentile, matching its size-optimization threshold and avoiding
unnecessary expansion of moderately hot functions. (Without this,
performance was marginally better, but wheel size _increased_ by 5-10%!)
- We feed the result back into the existing `maturin` build.

### Results

Here's the initial, untuned PGO performance on seven held-out projects
(and language-server performance on three held-out projects):

| Held-out project | `ty check` | Incremental edits |
| --- | ---: | ---: |
| Black | 7.1% faster | 17.1% faster |
| isort | 13.3% faster | 18.1% faster |
| Jinja | 5.5% faster | 13.7% faster |
| Django | 25.5% faster | — |
| pandas | 15.9% faster | — |
| scikit-learn | 19.6% faster | — |
| SymPy | 21.5% faster | — |
| Geometric mean | **15.8% faster** | **16.3% faster** |

As an aside, profiling the language server explicitly (i.e., including
the language server commands in the PGO training) improved
incremental-edit latency by another 7.6% over CLI-only PGO; without that
training, incremental edit performance was _still_ up (but not quite as
much).

Beyond raw performance, with the tuned PGO settings, we see the
following results:

- **Binary size decreased by 7.98%** (28.10 MB to 25.86 MB compared with
non-PGO).
- **Wheel size decreased by 1.32%** (12.71 MB to 12.54 MB compared with
non-PGO), and by 14.11% compared with untuned PGO.
- **Release archive size decreased by 1.53%** (12.35 MB to 12.16 MB
compared with non-PGO), and by 14.25% compared with untuned PGO.
- **Incremental language-server edits are 3.30% faster than untuned
PGO**.
- **Linux x86-64 release build finishes in 11m28s on eight-core Depot**,
compared with 12m59s on four-core Depot and 15m45s on the previous
GitHub runner. The full-stack bottleneck shifts to Windows at 12m24s;
other Linux targets retain their four-core runners.

### Stack

Additional platforms are covered in subsequent PRs:

- macOS ARM64: #4216
- Windows x86-64: #4217
- Linux ARM64: #4218

Ruff and uv follow the same approach; see
astral-sh/ruff#27570 and
astral-sh/uv#21001.
@charliermarsh
charliermarsh force-pushed the charlie/uv-linux-pgo-prototype branch from 6822ccc to aa0874f Compare August 17, 2026 19:31
@charliermarsh
charliermarsh merged commit b6beccc into main Aug 17, 2026
75 checks passed
@charliermarsh
charliermarsh deleted the charlie/uv-linux-pgo-prototype branch August 17, 2026 19:43
charliermarsh added a commit that referenced this pull request Aug 17, 2026
## Summary

This PR enables PGO for uv's macOS ARM64 releases, following the
approach outlined in #21001.
charliermarsh added a commit that referenced this pull request Aug 17, 2026
## Summary

This PR enables PGO for uv's Windows x86-64 releases, following the
approach outlined in #21001. The
existing static-CRT configuration is preserved.
charliermarsh added a commit that referenced this pull request Aug 17, 2026
## Summary

This PR enables PGO for uv's Linux ARM64 releases, following the
approach outlined in #21001. (To
enable PGO, we also move to a native ARM64 runner.)
luketainton pushed a commit to luketainton/repos_labmcp that referenced this pull request Aug 25, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | final | patch | `0.12.5` → `0.12.6` |

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.12.6`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0126)

[Compare Source](astral-sh/uv@0.12.5...0.12.6)

Released on 2026-08-25.

##### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#&#8203;21295](astral-sh/uv#21295))

##### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#&#8203;21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#&#8203;21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#&#8203;21237](astral-sh/uv#21237))

##### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#&#8203;21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#&#8203;21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#&#8203;21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#&#8203;21146](astral-sh/uv#21146))

##### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#&#8203;21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#&#8203;21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#&#8203;21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#&#8203;21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#&#8203;21148](astral-sh/uv#21148))

##### Bug fixes

- Allow explicit `uv build` and non-editable first-party workspace packages when `no-build` is enabled ([#&#8203;21294](astral-sh/uv#21294))
- Reuse configured index credentials during `uv tool upgrade` when the tool receipt references the same index ([#&#8203;21275](astral-sh/uv#21275))
- Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch ([#&#8203;21224](astral-sh/uv#21224))
- Prevent TLS segfaults in riscv64 musl release binaries ([#&#8203;21158](astral-sh/uv#21158))
- Preserve dependencies selected by recursive extras when markers mix production and extra conditions ([#&#8203;21181](astral-sh/uv#21181))
- Preserve version constraints from transitively referenced recursive extras ([#&#8203;21209](astral-sh/uv#21209))
- Resolve repository-relative Git archive dependencies inside the checkout during the initial `uv sync` ([#&#8203;21264](astral-sh/uv#21264))
- Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header ([#&#8203;21282](astral-sh/uv#21282))
- Do not misclassify package URLs ending in `.py` as local script paths ([#&#8203;21144](astral-sh/uv#21144))
- Use directory creation times consistently across libc implementations for directory `cache-keys` entries ([#&#8203;21137](astral-sh/uv#21137))
- Promote human-readable sizes to the next unit at rounding boundaries ([#&#8203;21136](astral-sh/uv#21136))

##### Other changes

- Add Python 3.15 release-candidate Docker images ([#&#8203;21293](astral-sh/uv#21293))
- Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 ([#&#8203;21258](astral-sh/uv#21258))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40NC4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://git.tainton.uk/repos/labmcp/pulls/38
Reviewed-by: Luke Tainton <luke@tainton.uk>
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
hbjydev pushed a commit to hbjydev/phoebe that referenced this pull request Aug 27, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [uv](https://github.com/astral-sh/uv) | tools | minor | `0.11.28` → `0.12.6` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/141) for more information.

---

### Release Notes

<details>
<summary>astral-sh/uv (uv)</summary>

### [`v0.12.6`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0126)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.5...0.12.6)

Released on 2026-08-25.

##### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#&#8203;21295](https://github.com/astral-sh/uv/pull/21295))

##### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#&#8203;21261](https://github.com/astral-sh/uv/pull/21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#&#8203;21078](https://github.com/astral-sh/uv/pull/21078))
- Display byte counts below 1 KiB without a fractional part ([#&#8203;21237](https://github.com/astral-sh/uv/pull/21237))

##### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#&#8203;21117](https://github.com/astral-sh/uv/pull/21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#&#8203;21235](https://github.com/astral-sh/uv/pull/21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#&#8203;21227](https://github.com/astral-sh/uv/pull/21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#&#8203;21146](https://github.com/astral-sh/uv/pull/21146))

##### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#&#8203;21001](https://github.com/astral-sh/uv/pull/21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#&#8203;21003](https://github.com/astral-sh/uv/pull/21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#&#8203;21002](https://github.com/astral-sh/uv/pull/21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#&#8203;21004](https://github.com/astral-sh/uv/pull/21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#&#8203;21148](https://github.com/astral-sh/uv/pull/21148))

##### Bug fixes

- Allow explicit `uv build` and non-editable first-party workspace packages when `no-build` is enabled ([#&#8203;21294](https://github.com/astral-sh/uv/pull/21294))
- Reuse configured index credentials during `uv tool upgrade` when the tool receipt references the same index ([#&#8203;21275](https://github.com/astral-sh/uv/pull/21275))
- Ensure full 40-character Git commit pins resolve to the requested object instead of a SHA-named branch ([#&#8203;21224](https://github.com/astral-sh/uv/pull/21224))
- Prevent TLS segfaults in riscv64 musl release binaries ([#&#8203;21158](https://github.com/astral-sh/uv/pull/21158))
- Preserve dependencies selected by recursive extras when markers mix production and extra conditions ([#&#8203;21181](https://github.com/astral-sh/uv/pull/21181))
- Preserve version constraints from transitively referenced recursive extras ([#&#8203;21209](https://github.com/astral-sh/uv/pull/21209))
- Resolve repository-relative Git archive dependencies inside the checkout during the initial `uv sync` ([#&#8203;21264](https://github.com/astral-sh/uv/pull/21264))
- Return an error instead of panicking when a bearer token cannot be encoded as an HTTP header ([#&#8203;21282](https://github.com/astral-sh/uv/pull/21282))
- Do not misclassify package URLs ending in `.py` as local script paths ([#&#8203;21144](https://github.com/astral-sh/uv/pull/21144))
- Use directory creation times consistently across libc implementations for directory `cache-keys` entries ([#&#8203;21137](https://github.com/astral-sh/uv/pull/21137))
- Promote human-readable sizes to the next unit at rounding boundaries ([#&#8203;21136](https://github.com/astral-sh/uv/pull/21136))

##### Other changes

- Add Python 3.15 release-candidate Docker images ([#&#8203;21293](https://github.com/astral-sh/uv/pull/21293))
- Raise the minimum supported Rust version to 1.96 and update the repository toolchain to Rust 1.98 ([#&#8203;21258](https://github.com/astral-sh/uv/pull/21258))

### [`v0.12.5`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0125)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.4...0.12.5)

Released on 2026-08-14.

##### Python

- Add CPython 3.10.21, 3.11.16, and 3.12.14 ([#&#8203;21138](https://github.com/astral-sh/uv/pull/21138))
- Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters ([#&#8203;21134](https://github.com/astral-sh/uv/pull/21134))

##### Enhancements

- Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs ([#&#8203;21130](https://github.com/astral-sh/uv/pull/21130))

##### Preview features

- Allow `--index` and `--default-index` to select configured package indexes by name with the `index-by-name` preview feature ([#&#8203;17455](https://github.com/astral-sh/uv/pull/17455))
- Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default ([#&#8203;21131](https://github.com/astral-sh/uv/pull/21131))
- Fall back to logical file sizes when using `cache-physical-space` on filesystems that do not support physical-space accounting ([#&#8203;21133](https://github.com/astral-sh/uv/pull/21133))

##### Bug fixes

- Resolve relative package index paths in PEP 723 scripts against the script directory ([#&#8203;21097](https://github.com/astral-sh/uv/pull/21097))

### [`v0.12.4`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0124)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.3...0.12.4)

Released on 2026-08-13.

##### Enhancements

- Prefer post-quantum key exchange and enable opt-in TLS diagnostics ([#&#8203;21054](https://github.com/astral-sh/uv/pull/21054))
- Accept whitespace before versions in noncompliant wildcard comparisons such as `Requires-Python: >= 3.5.*` ([#&#8203;21012](https://github.com/astral-sh/uv/pull/21012))
- Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content ([#&#8203;20944](https://github.com/astral-sh/uv/pull/20944))
- Omit source-span carets from diagnostics for empty PEP 508 requirements ([#&#8203;21094](https://github.com/astral-sh/uv/pull/21094))

##### Preview features

- Add `uv check --no-install-project` and respect `UV_NO_INSTALL_PROJECT` to install dependencies without building or installing the project ([#&#8203;21085](https://github.com/astral-sh/uv/pull/21085))
- Make the ty subprocess invoked by `uv check` honor uv's color and progress settings, including quiet mode ([#&#8203;21086](https://github.com/astral-sh/uv/pull/21086))

##### Performance

- Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges ([#&#8203;20804](https://github.com/astral-sh/uv/pull/20804))
- Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly ([#&#8203;21041](https://github.com/astral-sh/uv/pull/21041))

##### Bug fixes

- Use windowed `pythonw.exe` launchers for virtual environments created from managed Python minor-version links ([#&#8203;19235](https://github.com/astral-sh/uv/pull/19235))
- Allow `uv lock` to proceed when `.venv` is an unusable project environment ([#&#8203;21068](https://github.com/astral-sh/uv/pull/21068))
- Respect `fork-strategy` when ordering forks created from `environments` or existing lockfile `resolution-markers` ([#&#8203;21000](https://github.com/astral-sh/uv/pull/21000))
- Preserve consecutive wildcard Python minor-version exclusions such as `!=3.11.*, !=3.12.*` in `uv.lock` ([#&#8203;21045](https://github.com/astral-sh/uv/pull/21045))
- Preserve inline comments on the final item in dependency arrays when `uv add` updates it ([#&#8203;21008](https://github.com/astral-sh/uv/pull/21008))
- Recover from stale base-interpreter cache metadata when an existing virtual environment exposes a version mismatch ([#&#8203;21073](https://github.com/astral-sh/uv/pull/21073))
- Prevent interpreter cache reuse across different `PYTHONEXECUTABLE` and `__PYVENV_LAUNCHER__` overrides ([#&#8203;21075](https://github.com/astral-sh/uv/pull/21075))
- Show standard styling, usage guidance, and line termination for invalid `uv version --bump` values ([#&#8203;21076](https://github.com/astral-sh/uv/pull/21076))

### [`v0.12.3`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0123)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.2...0.12.3)

Released on 2026-08-07.

##### Python

- Add CPython 3.13.15 ([#&#8203;20997](https://github.com/astral-sh/uv/pull/20997))

##### Preview features

- Add `--output-format` to select automatic, human-readable, or raw-byte output for `uv cache size` ([#&#8203;20992](https://github.com/astral-sh/uv/pull/20992))
- Preserve JSON output from `uv workspace metadata --quiet` while suppressing diagnostics ([#&#8203;20991](https://github.com/astral-sh/uv/pull/20991))
- Reduce memory usage for large workspaces by streaming `uv workspace metadata` JSON output ([#&#8203;20990](https://github.com/astral-sh/uv/pull/20990))

##### Performance

- Reduce Linux startup latency by initializing the workspace cache before spawning another thread ([#&#8203;20989](https://github.com/astral-sh/uv/pull/20989))
- Reuse compiled workspace exclusion patterns during workspace discovery ([#&#8203;20988](https://github.com/astral-sh/uv/pull/20988))
- Speed up conflict-heavy resolutions by avoiding materialized range complements ([#&#8203;20982](https://github.com/astral-sh/uv/pull/20982))
- Avoid slow procfs reads during Python interpreter discovery on Linux ([#&#8203;20987](https://github.com/astral-sh/uv/pull/20987))

##### Documentation

- Add PEP 740 attestations to the GitHub Actions publishing example ([#&#8203;20986](https://github.com/astral-sh/uv/pull/20986))
- Restrict the GitHub Actions publishing example to Python version tags ([#&#8203;20973](https://github.com/astral-sh/uv/pull/20973))
- Correct `--python-pin` to `--pin-python` in the `uv init --bare` example ([#&#8203;20876](https://github.com/astral-sh/uv/pull/20876))

### [`v0.12.2`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0122)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.1...0.12.2)

Released on 2026-08-05.

##### Python

- Add CPython 3.15.0rc1 ([#&#8203;20948](https://github.com/astral-sh/uv/pull/20948))
- Add CPython 3.14.7 ([#&#8203;20971](https://github.com/astral-sh/uv/pull/20971))

##### Enhancements

- Ensure diagnostic hints end with a newline to prevent malformed terminal output ([#&#8203;20959](https://github.com/astral-sh/uv/pull/20959))

##### Preview features

- Audit one or all installed tools with `uv tool audit` ([#&#8203;20921](https://github.com/astral-sh/uv/pull/20921))
- Report physically reclaimed disk space during cache cleanup with the `cache-physical-space` preview feature ([#&#8203;20925](https://github.com/astral-sh/uv/pull/20925))

##### Configuration

- Add `UV_RUN_RLIMIT_NOFILE` to set the open-file limit for commands launched by `uv run` ([#&#8203;20926](https://github.com/astral-sh/uv/pull/20926))

##### Performance

- Speed up `uv.lock` parsing for wheel entries ([#&#8203;20881](https://github.com/astral-sh/uv/pull/20881))
- Speed up `uv.lock` parsing for source distribution entries ([#&#8203;20882](https://github.com/astral-sh/uv/pull/20882))
- Speed up filename extraction from distribution URLs ([#&#8203;20879](https://github.com/astral-sh/uv/pull/20879))
- Reduce filesystem metadata lookups during bytecode compilation ([#&#8203;20928](https://github.com/astral-sh/uv/pull/20928))
- Reuse file metadata when building source distributions ([#&#8203;20927](https://github.com/astral-sh/uv/pull/20927))

##### Bug fixes

- Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions ([#&#8203;20963](https://github.com/astral-sh/uv/pull/20963))
- Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested ([#&#8203;20930](https://github.com/astral-sh/uv/pull/20930))

##### Documentation

- Separate build and publish jobs in the GitHub Actions publishing guide ([#&#8203;20946](https://github.com/astral-sh/uv/pull/20946))
- Ensure the GitHub Actions publishing example waits for the build job to finish ([#&#8203;20957](https://github.com/astral-sh/uv/pull/20957))
- Correct typos in the Docker integration guide ([#&#8203;20970](https://github.com/astral-sh/uv/pull/20970))

### [`v0.12.1`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0121)

[Compare Source](https://github.com/astral-sh/uv/compare/0.12.0...0.12.1)

Released on 2026-07-31.

##### Enhancements

- Add package-specific pre-release policies with `--prerelease-package` ([#&#8203;20837](https://github.com/astral-sh/uv/pull/20837))
- Support local HTML files as flat indexes ([#&#8203;20802](https://github.com/astral-sh/uv/pull/20802))
- Add Xonsh virtual environment activation scripts (`activate.xsh`) ([#&#8203;19740](https://github.com/astral-sh/uv/pull/19740))
- Preserve filesystem paths passed to `uv add --index` when updating `pyproject.toml` ([#&#8203;20817](https://github.com/astral-sh/uv/pull/20817))

##### Preview features

- Add automatic fixes to `uv check` with `--fix` ([#&#8203;20793](https://github.com/astral-sh/uv/pull/20793))
- Avoid rejecting unchanged metadata-free lockfiles when workspace dependencies share direct sources ([#&#8203;20847](https://github.com/astral-sh/uv/pull/20847))
- Honor direct URL constraints when validating metadata-free lockfiles ([#&#8203;20796](https://github.com/astral-sh/uv/pull/20796))
- Ignore malformed PEP 723 scripts discovered during project checks ([#&#8203;20784](https://github.com/astral-sh/uv/pull/20784))
- Use ty's native script exclusion in `uv check` ([#&#8203;20742](https://github.com/astral-sh/uv/pull/20742))

##### Performance

- Parse canonical uv lockfiles directly, with a fallback for other valid TOML syntax ([#&#8203;20648](https://github.com/astral-sh/uv/pull/20648))
- Accelerate SHA-256 hashing on non-Windows ARM64 platforms ([#&#8203;20805](https://github.com/astral-sh/uv/pull/20805))

##### Bug fixes

- Flush shell startup file updates before `uv tool update-shell` and `uv python update-shell` exit ([#&#8203;20842](https://github.com/astral-sh/uv/pull/20842))
- Make workspace-root dependency groups available to commands run from workspace members ([#&#8203;20840](https://github.com/astral-sh/uv/pull/20840))
- Resolve `--find-links` paths in requirements files relative to the containing file ([#&#8203;20832](https://github.com/astral-sh/uv/pull/20832))
- Respect configured indexes in `uv tool list --outdated` ([#&#8203;20770](https://github.com/astral-sh/uv/pull/20770))

##### Documentation

- Document Astral GPU indexes in the PyTorch guide ([#&#8203;20785](https://github.com/astral-sh/uv/pull/20785))
- Use consistent dependency-group argument descriptions throughout the CLI documentation ([#&#8203;20823](https://github.com/astral-sh/uv/pull/20823))

### [`v0.12.0`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0120)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.33...0.12.0)

Released on 2026-07-28.

Since we released uv [0.11.0](https://github.com/astral-sh/uv/releases/tag/0.11.0) in March, we've accumulated changes that improve correctness, safety, and compatibility with specifications, but could break some workflows. This release contains those changes; many have been marked as breaking out of an abundance of caution.

**We expect most users to be able to upgrade without making changes.**

There are no breaking changes to the configuration of the [uv build backend](https://docs.astral.sh/uv/concepts/build-backend/). If your `[build-system]` table includes an upper bound on `uv_build`, update it to allow `uv_build` 0.12, e.g., `uv_build>=0.11.32,<0.13`.

##### Breaking changes

- **Define build systems by default with `uv init`** ([#&#8203;19197](https://github.com/astral-sh/uv/pull/19197))

  Projects created with `uv init` now declare a build system and are packaged by default. This was the default project layout all the way back in [v0.3](https://github.com/astral-sh/uv/releases/tag/0.3.0), but we found that the use of the `hatchling` build system was confusing to newcomers and consequently dropped use of a build system by default in [v0.4](https://github.com/astral-sh/uv/releases/tag/0.4.0). Since then, we've created our own build system (`uv_build`) with tight integration with uv and are excited to restore the default to a best-practice project layout.

  Previously, `uv init example` created an unpackaged layout containing `main.py` and a `pyproject.toml` without a build system. The project could declare dependencies but was not itself installed into its virtual environment.

  Now, `uv init example` defines a `[build-system]` using `uv_build`, places application source code in `src/example`, and includes a `[project.scripts]` entry named `example`. Defining a build system allows the project to be imported from tests or other code, installed as a dependency, and run as a command:

  ```console
  $ uv init example
  $ cd example
  $ uv run example
  Hello from example!
  ```

  Existing projects are unaffected. Use [`uv init --no-package example`](https://docs.astral.sh/uv/concepts/projects/init/#creating-a-project-without-a-build-system) to create the previous unpackaged layout without a build system.

  See the [project creation documentation](https://docs.astral.sh/uv/concepts/projects/init/#applications) for more details.

  This stabilizes the `packaged-init` preview feature.
- **Reject unsupported source distribution and wheel archive formats** ([#&#8203;18927](https://github.com/astral-sh/uv/pull/18927))

  [PEP 625](https://peps.python.org/pep-0625/) requires [source distributions](https://docs.astral.sh/uv/concepts/resolution/#source-distribution) to use `.tar.gz` archives. Previously, uv also accepted legacy formats such as `.tar.bz2` and `.tar.xz`. Those formats are now rejected, including when referenced by an existing lockfile. Legacy `.zip` source distributions remain supported for backwards compatibility.

  Wheels and other ZIP archives can no longer contain entries compressed with bzip2, LZMA, or XZ. Entries must use the stored, DEFLATE, or zstd compression methods.

  Removing support for uncommon compression methods reduces uv's compression dependencies and the attack surface exposed when processing untrusted packages.

  You cannot opt out of this behavior. If you depend on a legacy source distribution that uses an unsupported format, we recommend rebuilding it as a `.tar.gz` archive and regenerating any lockfile containing references to the legacy archive.
- **Reject wheel files that could replace the Python interpreter** ([#&#8203;20748](https://github.com/astral-sh/uv/pull/20748), [#&#8203;20749](https://github.com/astral-sh/uv/pull/20749))

  uv already rejected wheel entry points named `python`, but case variants such as `Python` were still accepted. On case-insensitive filesystems, including common macOS and Windows setups, these entry points could overwrite the virtual environment's interpreter.

  Wheels could also place interpreter files in their `.data/scripts` directory or in paths such as `.data/data/bin/python`, bypassing the entry-point check and replacing the interpreter during installation.

  uv now rejects case-insensitive variants of reserved interpreter names and wheel data files that would be installed over an interpreter. This includes names such as `Python`, `python.py`, and `Python.exe`, along with other reserved interpreter names and their versioned variants.

  You cannot opt out of these checks. Rename conflicting entry points or wheel data files and rebuild the affected wheel.
- **Prefer stable releases before falling back to pre-releases** ([#&#8203;19993](https://github.com/astral-sh/uv/pull/19993))

  A dependency can introduce a [pre-release requirement](https://docs.astral.sh/uv/concepts/resolution/#pre-release-handling) after resolution starts. uv previously required each package's pre-release eligibility to be known before resolution began: the default `if-necessary-or-explicit` mode allowed them for direct requirements that explicitly requested a pre-release, or for packages that only published pre-releases.

  This meant that a pre-release requirement discovered in a dependency's metadata, e.g., `example>=2.0.0b1`, would fail to resolve even when a compatible pre-release existed. To resolve it, you had to add that dependency as a direct requirement or allow pre-releases across your entire dependency graph.

  The default mode is now `if-necessary`. uv tries stable candidates first and falls back to pre-releases when no stable candidate satisfies the active constraints. Like pip, uv now supports [pre-release requirements discovered transitively](https://docs.astral.sh/uv/pip/compatibility/#pre-release-compatibility), but can select different versions than previous uv releases when both stable and pre-release candidates are available.

  You can opt out of automatic pre-release selection with `--prerelease disallow`. Alternatively, `--prerelease allow` considers pre-releases without first preferring stable releases, and `--prerelease explicit` only allows them for direct requirements that mention a pre-release.

  The old `if-necessary-or-explicit` mode distinguished between explicitly requested pre-releases and packages with no stable releases. That distinction is unnecessary now that `if-necessary` handles both cases, including transitive requirements. The old name remains available as an alias but is deprecated and will be removed in a future release.
- **Respect `--require-hashes` directives in `requirements.txt`** ([#&#8203;19336](https://github.com/astral-sh/uv/pull/19336))

  Previously, `uv pip install` and `uv pip sync` warned about `--require-hashes` inside a `requirements.txt` file but still installed dependencies without checking their hashes. Now, the directive enables hash-checking mode, just as if `--require-hashes` had been passed on the command line.

  For example, this requirements file is no longer accepted because the requirement is neither pinned nor hashed:

  ```text
  --require-hashes
  anyio
  ```

  You cannot opt out while the directive is present. Pin every requirement with `==` and provide its hash, or remove `--require-hashes` if hash checking is not intended.
- **Reject MD5-only hashes in hash-checking mode** ([#&#8203;20758](https://github.com/astral-sh/uv/pull/20758))

  Previously, `uv pip install --require-hashes` and `uv pip sync --require-hashes` accepted requirements whose only available digest used MD5. MD5 is not collision-resistant, so relying on it undermined installations that require hash verification and differed from pip's behavior.

  Hash-checking mode now requires at least one secure digest for every requirement. For example, the following requirement is rejected unless a secure hash, such as SHA-256, is also supplied:

  ```text
  anyio==4.0.0 --hash=md5:420d85e19168705cdf0223621b18831a
  ```

  A secure hash can be supplied directly on the requirement or in a matching constraints file. Ordinary hash verification without `--require-hashes` continues to support MD5.

  You cannot opt out while hash checking is required. Regenerate affected hashes with SHA-256 or another supported secure hash.
- **Reject invalid `pylock.toml` files and artifacts** ([#&#8203;20402](https://github.com/astral-sh/uv/pull/20402), [#&#8203;20440](https://github.com/astral-sh/uv/pull/20440), [#&#8203;20443](https://github.com/astral-sh/uv/pull/20443))

  uv now validates additional requirements from the [`pylock.toml` specification](https://packaging.python.org/en/latest/specifications/pylock-toml/):

  - The `packages` array must be present. Previously, uv interpreted a missing array as an empty lockfile, so `uv pip sync` could uninstall an environment instead of rejecting malformed input. An explicitly empty `packages = []` array remains valid.
  - Lockfile filenames must be `pylock.toml` or a single-name variant such as `pylock.dev.toml`. Names such as `pylock..toml` and `pylock.foo.bar.toml` are rejected.
  - If a wheel, source distribution, or other artifact declares a `size`, the downloaded or cached artifact must match. Previously, an incorrect size was accepted when the hash was correct. Sizes reported by package indexes remain advisory.

  You cannot opt out of these checks. Regenerate malformed lockfiles, rename invalid filenames, and either correct or remove an incorrect optional `size` value.
- **Honor explicit certificate overrides even when no certificates can be loaded** ([#&#8203;20741](https://github.com/astral-sh/uv/pull/20741), [#&#8203;20767](https://github.com/astral-sh/uv/pull/20767))

  Previously, uv ignored [`SSL_CERT_FILE` or `SSL_CERT_DIR`](https://docs.astral.sh/uv/concepts/authentication/certificates/#custom-certificates) values that pointed to missing or inaccessible paths, empty files or directories, or sources without valid certificates. Instead, it fell back to its default trust roots, potentially allowing HTTPS connections that the configured override was intended to reject.

  Now, any non-empty `SSL_CERT_FILE` or `SSL_CERT_DIR` value replaces uv's default certificate roots, even when no valid certificates can be loaded. In that case, HTTPS requests fail because no certificates are trusted. This applies to package downloads and remote scripts, including GitHub Gists.

  Fix or unset the certificate override. Unsetting it restores the default trust store; empty environment-variable values continue to be ignored.
- **Support pip-compatible `--cert` handling in `uv pip`** ([#&#8203;20418](https://github.com/astral-sh/uv/pull/20418))

  The `uv pip` interface now accepts [`--cert <path>`](https://docs.astral.sh/uv/concepts/authentication/certificates/#custom-certificates), e.g.:

  ```console
  $ uv pip install --cert ./company-ca.pem example
  ```

  As in pip, the provided PEM bundle replaces all other certificate sources for that invocation, including system certificates and `SSL_CERT_FILE` or `SSL_CERT_DIR`. This change has no effect unless you pass `--cert`. Include the necessary certificate authorities in the bundle.

  `--cert` is only supported by `uv pip` commands; other uv commands continue to use their existing certificate configuration.
- **Discover projects relative to the script passed to `uv run`** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  Previously, `uv run project/script.py` discovered its project from the current directory, even when the script belonged to another project. uv now starts project and workspace discovery from the script's directory instead.

  For example, running `uv run other-project/script.py` now uses `other-project` and its dependencies. This fixes scripts that previously failed because their own dependencies were not installed, but can select a different environment than before.

  You can opt out of script-relative discovery by selecting a project explicitly, e.g., `uv run --project . other-project/script.py`.

  This stabilizes the `target-workspace-discovery` preview feature.
- **Require `--force` before clearing a directory that is not a virtual environment** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  `uv venv --clear` previously removed any existing target directory, even if it was not a virtual environment. uv emitted a warning but still deleted the directory and its contents. Now, uv refuses to clear directories that do not contain a virtual environment.

  You can opt out of this safety check by explicitly passing `--force`, e.g., `uv venv --clear --force ./not-a-virtualenv`.

  This stabilizes the `venv-safe-clear` preview feature.
- **Reject `--project` when initializing a project** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  `--project` selects an existing project, so it is not meaningful when initializing a new one. Previously, `uv init --project example` warned and initialized `example` anyway; if a positional path was also provided, `--project` was ignored.

  This usage is now an error. Use `uv init example` to initialize a project at the requested path, or `uv init --directory example` to change the working directory first.

  This stabilizes the `init-project-flag` preview feature.
- **Reject missing or invalid `--project` paths** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  uv previously warned when `--project` referred to a missing directory or a file other than `pyproject.toml`, but then attempted to continue. This could produce confusing errors later or run against an unintended project.

  Now, `uv run --project missing python` fails immediately instead of continuing. You cannot opt out of this behavior. Create the directory first or select an existing project. Passing `--project path/to/pyproject.toml` remains supported and selects the file's parent directory.

  This stabilizes the `project-directory-must-exist` preview feature.
- **Skip distributions with non-normalized filenames when publishing** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  Distribution filenames must use [normalized package names](https://packaging.python.org/en/latest/specifications/name-normalization/) and versions. For example, a wheel for version `1.01.0` should be named `example-1.1.0-py3-none-any.whl`, not `example-1.01.0-py3-none-any.whl`.

  Previously, `uv publish` warned about non-normalized filenames but still attempted to upload them. It now skips the affected wheels and source distributions instead.

  You cannot opt out of this behavior. Rebuild distributions with normalized filenames before publishing.

  This stabilizes the `publish-require-normalized` preview feature.
- **Classify Conda environments named `base` and `root` by their paths** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  Conda environments named `base` or `root` were previously assumed to be the base Conda environment, even when they were ordinary child environments. uv now recognizes child Conda environments named `base` or `root` based on their paths, as it already does for other names.

  You can opt out of automatic interpreter selection by requesting an interpreter explicitly with `--python /path/to/python`.

  This stabilizes the `special-conda-env-names` preview feature.
- **Reject broken `.venv` symlinks during environment discovery** ([#&#8203;20433](https://github.com/astral-sh/uv/pull/20433))

  Previously, uv could ignore a broken `.venv` symlink and continue searching parent directories for another virtual environment. As a result, commands such as `uv pip install` could unexpectedly modify an unrelated ancestor environment.

  uv now stops at a broken `.venv` symlink and reports its exact path. Errors encountered while reading virtual environment metadata, including permission failures, are also reported immediately instead of being ignored.

  You cannot opt out of this behavior. Repair or remove the broken `.venv` symlink and correct any permissions that prevent uv from inspecting the environment.
- **Reinstall matching installed Python patch versions instead of upgrading implicitly** ([#&#8203;20659](https://github.com/astral-sh/uv/pull/20659))

  Before [Python upgrades](https://docs.astral.sh/uv/guides/install-python/#upgrading-python-versions) were supported, `uv python install 3.12 --reinstall` doubled as a way to install the latest Python 3.12 patch release. Now that `--upgrade` is available, `--reinstall` reinstalls the matching patch releases that are already present.

  For example, if Python 3.12.6 and 3.12.7 are installed, `uv python install 3.12 --reinstall` reinstalls both versions instead of installing the latest available 3.12 release.

  You can recover the previous upgrade behavior with `uv python install 3.12 --upgrade`. Combine `--upgrade --reinstall` to reinstall only the latest patch.
- **Require `--upgrade-group` to name an existing dependency group** ([#&#8203;18957](https://github.com/astral-sh/uv/pull/18957))

  Previously, `uv lock --upgrade-group docs` silently succeeded even if no `docs` [dependency group](https://docs.astral.sh/uv/concepts/projects/dependencies/#dependency-groups) existed. uv now validates the requested group against the project, its workspace members, and workspace-level dependency groups.

  You cannot opt out of this behavior. Correct the group name or add it to `[dependency-groups]`. Legacy `tool.uv.dev-dependencies` still satisfies `--upgrade-group dev`.
- **Resolve relative indexes and find-links against `--directory`** ([#&#8203;20740](https://github.com/astral-sh/uv/pull/20740))

  The `--directory` option changes the directory in which uv operates. Previously, relative index and find-links paths supplied on the command line were still resolved against the original working directory.

  uv now resolves `--index`, `--default-index`, `--index-url`, `--extra-index-url`, and `--find-links` relative to the directory selected by `--directory`. For example:

  ```console
  $ uv add --directory project --index ./packages example
  ```

  This now uses `project/packages` instead of `./packages` in the original working directory. Absolute paths and indexes loaded from configuration files are unaffected.

  To preserve the previous target, pass an absolute path or adjust the relative path, e.g., `--index ../packages`.
- **Preserve absolute paths provided to `uv add`** ([#&#8203;18402](https://github.com/astral-sh/uv/pull/18402))

  `uv add` previously converted every local dependency into a project-relative path, even when the original request used an absolute path or a literal `file://` URL. It now preserves the form of the request in `pyproject.toml` and `uv.lock`:

  ```console
  $ uv add ../library             # remains relative
  $ uv add /projects/library      # remains absolute
  ```

  Absolute paths make a project less portable. Use a relative path to avoid recording an absolute path. URLs containing expanded variables retain their existing relative-path behavior.
- **Remove older PyPy distributions that are only available as bzip2 archives** ([#&#8203;20423](https://github.com/astral-sh/uv/pull/20423))

  Older PyPy patch releases that are only distributed as `.tar.bz2` archives are no longer available through `uv python install`. These releases require unsupported bzip2 archives.

  The latest PyPy release for each supported Python minor version is available as a gzip-compressed archive and remains supported. For example, `uv python list 3.10 --all-versions` still includes the latest PyPy 3.10 release, but older bzip2-only patch releases are omitted.

  You cannot opt out of this behavior. Request a newer PyPy patch release instead.
- **Omit excluded-package comments when annotations are disabled** ([#&#8203;20085](https://github.com/astral-sh/uv/pull/20085))

  `uv pip compile --no-annotate` suppresses comments describing the generated requirements file. Previously, a footer listing packages excluded with `--unsafe-package` was still included, even though annotations were disabled. That footer is now omitted.

  You can recover the footer by removing `--no-annotate`.

##### Stabilizations

- **TOML 1.0-compatible source distributions** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  `uv_build` now writes a TOML 1.0-compatible `pyproject.toml` when building source distributions, allowing older Python build frontends to consume projects that use newer TOML syntax. The original project file remains available in the archive as `pyproject.toml.orig`.

  This stabilizes the `toml-backwards-compatibility` preview feature.
- **Automatic open-file limit adjustment on Unix** ([#&#8203;20225](https://github.com/astral-sh/uv/pull/20225))

  On Linux and macOS, uv now attempts to raise the soft open-file limit at startup toward the hard limit, capped at 1,048,576 descriptors. The new limit also applies to subprocesses and reduces failures caused by running out of file descriptors. If the limit cannot be raised, uv continues running with the existing limit.

  This stabilizes the `adjust-ulimit` preview feature.

##### Preview features

- Allow `uv upgrade` to target multiple packages, upgrade all production dependencies, and exclude selected dependencies ([#&#8203;20338](https://github.com/astral-sh/uv/pull/20338))

##### Bug fixes

- Include extras activated by dependency groups when evaluating conflicts ([#&#8203;20237](https://github.com/astral-sh/uv/pull/20237))

### [`v0.11.33`](https://github.com/astral-sh/uv/releases/tag/0.11.33)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.32...0.11.33)

#### Release Notes

Released on 2026-07-28.

##### Enhancements

- Abort panics in release builds for smaller uv binaries ([#&#8203;20271](https://github.com/astral-sh/uv/pull/20271))
- Use `.tar.gz` archives for Pyodide installs ([#&#8203;20667](https://github.com/astral-sh/uv/pull/20667))

##### Preview features

- Avoid checking any scripts in `uv check` unless `--script` is passed ([#&#8203;20676](https://github.com/astral-sh/uv/pull/20676))
- Check locked tools for malware before cache reuse ([#&#8203;20301](https://github.com/astral-sh/uv/pull/20301))
- Write and read `package.metadata`-free lockfiles ([#&#8203;20688](https://github.com/astral-sh/uv/pull/20688), [#&#8203;20691](https://github.com/astral-sh/uv/pull/20691), [#&#8203;20685](https://github.com/astral-sh/uv/pull/20685), [#&#8203;20695](https://github.com/astral-sh/uv/pull/20695))

##### Bug fixes

- Correctly split dependencies into production and optional markers ([#&#8203;20671](https://github.com/astral-sh/uv/pull/20671))
- Fix discrepancies in argument parsing of exclude-newer ([#&#8203;20679](https://github.com/astral-sh/uv/pull/20679))
- Cleanup managed Python temporary directory on error ([#&#8203;20752](https://github.com/astral-sh/uv/pull/20752))

#### Install uv 0.11.33

##### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.sh | sh
```

##### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.ps1 | iex"
```

#### Download uv 0.11.33

| File                                                                                                                                                | Platform                     | Checksum                                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-apple-darwin.tar.gz)                     | Apple Silicon macOS          | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-apple-darwin.tar.gz.sha256)           |
| [uv-x86\_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-apple-darwin.tar.gz)                      | Intel macOS                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-apple-darwin.tar.gz.sha256)            |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-pc-windows-msvc.zip)                     | ARM64 Windows                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-pc-windows-msvc.zip.sha256)           |
| [uv-i686-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-pc-windows-msvc.zip)                           | x86 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-pc-windows-msvc.zip.sha256)              |
| [uv-x86\_64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-pc-windows-msvc.zip)                      | x64 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-pc-windows-msvc.zip.sha256)            |
| [uv-aarch64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-unknown-linux-gnu.tar.gz)           | ARM64 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-unknown-linux-gnu.tar.gz.sha256)      |
| [uv-i686-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-unknown-linux-gnu.tar.gz)                 | x86 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-unknown-linux-gnu.tar.gz.sha256)         |
| [uv-powerpc64le-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-powerpc64le-unknown-linux-gnu.tar.gz)   | PPC64LE Linux                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-powerpc64le-unknown-linux-gnu.tar.gz.sha256)  |
| [uv-riscv64gc-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-riscv64gc-unknown-linux-gnu.tar.gz)       | RISCV Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-riscv64gc-unknown-linux-gnu.tar.gz.sha256)    |
| [uv-s390x-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-s390x-unknown-linux-gnu.tar.gz)               | S390x Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-s390x-unknown-linux-gnu.tar.gz.sha256)        |
| [uv-x86\_64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-unknown-linux-gnu.tar.gz)            | x64 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-unknown-linux-gnu.tar.gz.sha256)       |
| [uv-armv7-unknown-linux-gnueabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-armv7-unknown-linux-gnueabihf.tar.gz)   | ARMv7 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-armv7-unknown-linux-gnueabihf.tar.gz.sha256)  |
| [uv-aarch64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-unknown-linux-musl.tar.gz)         | ARM64 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-aarch64-unknown-linux-musl.tar.gz.sha256)     |
| [uv-i686-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-unknown-linux-musl.tar.gz)               | x86 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-i686-unknown-linux-musl.tar.gz.sha256)        |
| [uv-riscv64gc-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-riscv64gc-unknown-linux-musl.tar.gz)     | RISCV MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-riscv64gc-unknown-linux-musl.tar.gz.sha256)   |
| [uv-x86\_64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-unknown-linux-musl.tar.gz)          | x64 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-x86_64-unknown-linux-musl.tar.gz.sha256)      |
| [uv-arm-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-arm-unknown-linux-musleabihf.tar.gz)     | ARMv6 MUSL Linux (Hardfloat) | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-arm-unknown-linux-musleabihf.tar.gz.sha256)   |
| [uv-armv7-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-armv7-unknown-linux-musleabihf.tar.gz) | ARMv7 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-armv7-unknown-linux-musleabihf.tar.gz.sha256) |

#### Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):

```sh
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
```

You can also download the attestation from [GitHub](https://github.com/astral-sh/uv/attestations) and verify against that directly:

```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```

### [`v0.11.32`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01132)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.31...0.11.32)

Released on 2026-07-23.

##### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#&#8203;20628](https://github.com/astral-sh/uv/pull/20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#&#8203;20335](https://github.com/astral-sh/uv/pull/20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#&#8203;20646](https://github.com/astral-sh/uv/pull/20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#&#8203;20634](https://github.com/astral-sh/uv/pull/20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#&#8203;20643](https://github.com/astral-sh/uv/pull/20643))

##### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#&#8203;20611](https://github.com/astral-sh/uv/pull/20611))

##### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#&#8203;20586](https://github.com/astral-sh/uv/pull/20586))

### [`v0.11.31`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01131)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.30...0.11.31)

Released on 2026-07-21.

##### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#&#8203;18401](https://github.com/astral-sh/uv/pull/18401))
- Support `.venv` files containing paths to centralized project environments ([#&#8203;20022](https://github.com/astral-sh/uv/pull/20022))
- Update bundled Windows timezone data to IANA 2026c ([#&#8203;20554](https://github.com/astral-sh/uv/pull/20554))

##### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#&#8203;20605](https://github.com/astral-sh/uv/pull/20605))

##### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#&#8203;20587](https://github.com/astral-sh/uv/pull/20587))

##### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#&#8203;20578](https://github.com/astral-sh/uv/pull/20578))

##### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#&#8203;20582](https://github.com/astral-sh/uv/pull/20582))
- Reject source distributions and wheels with mismatched package names ([#&#8203;20432](https://github.com/astral-sh/uv/pull/20432))
- Avoid retrying TLS certificate verification failures ([#&#8203;16245](https://github.com/astral-sh/uv/pull/16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#&#8203;20153](https://github.com/astral-sh/uv/pull/20153))

### [`v0.11.30`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01130)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.29...0.11.30)

Released on 2026-07-20.

##### Python

- Add CPython 3.15.0b4 ([#&#8203;20519](https://github.com/astral-sh/uv/pull/20519))

##### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#&#8203;20500](https://github.com/astral-sh/uv/pull/20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#&#8203;20436](https://github.com/astral-sh/uv/pull/20436))

##### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#&#8203;20460](https://github.com/astral-sh/uv/pull/20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#&#8203;20427](https://github.com/astral-sh/uv/pull/20427))
- Accelerate lockfile serialization with `toml_writer` ([#&#8203;20450](https://github.com/astral-sh/uv/pull/20450))
- Compact cached Simple API distribution metadata and hashes ([#&#8203;20463](https://github.com/astral-sh/uv/pull/20463), [#&#8203;20483](https://github.com/astral-sh/uv/pull/20483))
- Decode stale cache entries in a single blocking task ([#&#8203;20486](https://github.com/astral-sh/uv/pull/20486))
- Decode cached payloads outside resolver workers ([#&#8203;20464](https://github.com/astral-sh/uv/pull/20464))
- Cache resolver Python requirement markers ([#&#8203;20461](https://github.com/astral-sh/uv/pull/20461))
- Reuse resolver fork markers while recording preferences ([#&#8203;20462](https://github.com/astral-sh/uv/pull/20462))

##### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#&#8203;20429](https://github.com/astral-sh/uv/pull/20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#&#8203;20466](https://github.com/astral-sh/uv/pull/20466))

##### Documentation

- Add a contribution guide ([#&#8203;20511](https://github.com/astral-sh/uv/pull/20511), [#&#8203;20552](https://github.com/astral-sh/uv/pull/20552))

### [`v0.11.29`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01129)

[Compare Source](https://github.com/astral-sh/uv/compare/0.11.28...0.11.29)

Released on 2026-07-15.

##### Python

- Use gzip-compressed artifacts for PyPy downloads ([#&#8203;20265](https://github.com/astral-sh/uv/pull/20265))

##### Enhancements

- Add JSON output to `uv tree` ([#&#8203;19978](https://github.com/astral-sh/uv/pull/19978))
- Add CUDA 13.2 as a supported PyTorch backend ([#&#8203;20267](https://github.com/astral-sh/uv/pull/20267))
- Prefer local artifacts over URLs when installing from `pylock.toml` ([#&#8203;20393](https://github.com/astral-sh/uv/pull/20393))
- Clarify diagnostics for unsatisfiable direct requirement ranges ([#&#8203;20227](https://github.com/astral-sh/uv/pull/20227))
- Include the selected project name in missing-extra errors ([#&#8203;20358](https://github.com/astral-sh/uv/pull/20358))

##### Preview features

- Preserve extras and dependency-group conflict context when selecting locked project tools ([#&#8203;20078](https://github.com/astral-sh/uv/pull/20078))
- Split OSV audit queries that exceed the service's 1,000-package limit ([#&#8203;20398](https://github.com/astral-sh/uv/pull/20398))
- Apply OSV fixed-version information only to the matching package and ecosystem ([#&#8203;20399](https://github.com/astral-sh/uv/pull/20399))
- Skip the virtualenv distutils monkeypatch on Python 3.10 and later ([#&#8203;20222](https://github.com/astral-sh/uv/pull/20222))
- Report invalid `uv audit --service-url` values instead of panicking ([#&#8203;20374](https://github.com/astral-sh/uv/pull/20374))
- Include preview settings in the published SchemaStore schema ([#&#8203;20304](https://github.com/astral-sh/uv/pull/20304))

##### Performance

- Reduce resolver work by widening selected versions across ranges without other known candidates ([#&#8203;20115](https://github.com/astral-sh/uv/pull/20115))
- Defer client and build setup for no-op `uv sync` operations ([#&#8203;20364](https://github.com/astral-sh/uv/pull/20364))
- Reuse workspace discovery during frozen syncs ([#&#8203;20363](https://github.com/astral-sh/uv/pull/20363))
- Reuse workspace discovery after resolving settings ([#&#8203;20356](https://github.com/astral-sh/uv/pull/20356))
- Reuse workspace discovery in `uv tree`, `uv export`, `uv format`, and `uv audit` ([#&#8203;20359](https://github.com/astral-sh/uv/pull/20359))
- Avoid cache and interpreter setup when reading a project version ([#&#8203;20360](https://github.com/astral-sh/uv/pull/20360))

##### Bug fixes

- Reject duplicate active package entries in `pylock.toml` ([#&#8203;20391](https://github.com/astral-sh/uv/pull/20391))
- Preserve direct-archive hashes in `uv pip freeze` output ([#&#8203;20395](https://github.com/astral-sh/uv/pull/20395))
- Explain conflicting root requirements instead of displaying an empty version range ([#&#8203;20228](https://github.com/astral-sh/uv/pull/20228))
- Prevent build-backend data paths from escaping the project or bypassing wheel exclusions ([#&#8203;20397](https://github.com/astral-sh/uv/pull/20397))
- Reject PEP 517 backend paths outside the source tree, including paths that escape through symlinks ([#&#8203;20387](https://github.com/astral-sh/uv/pull/20387))
- Redact credentials from failed Git fetch commands ([#&#8203;20401](https://github.com/astral-sh/uv/pull/20401))
- Fix exclusive post-release range ordering to match PEP 440 ([#&#8203;20268](https://github.com/astral-sh/uv/pull/20268))
- Canonicalize equivalent PEP 440 ranges during dependency resolution ([#&#8203;20182](https://github.com/astral-sh/uv/pull/20182))
- Honor Python version pins when initializing scripts ([#&#8203;20404](https://github.com/astral-sh/uv/pull/20404))
- Respect package-scoped source filtering for scripts ([#&#8203;20389](https://github.com/astral-sh/uv/pull/20389))
- Report existing environment incompatibilities when `uv pip install --strict` has nothing to install ([#&#8203;20388](https://github.com/astral-sh/uv/pull/20388))
- Continue scanning `platlib` when `purelib` is missing ([#&#8203;20405](https://github.com/astral-sh/uv/pull/20405))
- Handle versionless `.egg-info` files as legacy package metadata ([#&#8203;20403](https://github.com/astral-sh/uv/pull/20403))
- Make repeated locking idempotent for impossible cross-variable platform markers ([#&#8203;20369](https://github.com/astral-sh/uv/pull/20369))
- Report invalid cloud credential endpoint URLs instead of panicking ([#&#8203;20372](https://github.com/astral-sh/uv/pull/20372))
- Report invalid `pylock.toml` artifact URLs instead of panicking ([#&#8203;20373](https://github.com/astral-sh/uv/pull/20373))
- Report non-UTF-8 virtual environment paths instead of panicking while generating activation scripts ([#&#8203;20375](https://github.com/astral-sh/uv/pull/20375))
- Return an unsupported-operation error from unimplemented build-backend requirement hooks ([#&#8203;20376](https://github.com/astral-sh/uv/pull/20376))

##### Documentation

- Clarify `--no-build` behavior for editable requirements ([#&#8203;20234](https://github.com/astral-sh/uv/pull/20234))
- Document uv's threat model ([#&#8203;20236](https://github.com/astral-sh/uv/pull/20236))
- Reduce the number of badges in the README ([#&#8203;11257](https://github.com/astral-sh/uv/pull/11257))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjAuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjQ2LjUiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2dpdGh1Yi1yZWxlYXNlIiwidHlwZS9taW5vciJdfQ==-->

Reviewed-on: https://forgejo.hayden.moe/hayden/phoebe/pulls/274
DaniPopes added a commit to paradigmxyz/solar that referenced this pull request Aug 30, 2026
Release binaries now use a custom native workflow based on [uv's Linux
x86-64 PGO release work](astral-sh/uv#21001).
Five host-native targets collect an LLVM profile from the existing
synthetic and Standard JSON corpora, then build and package the final
binary with the same target flags. The cross-compiled musl target stays
unprofiled. cargo-dist 0.32.0 still plans and hosts releases, consumes
the checksummed local artifact manifest, and builds the installers,
source archive, and wasm bundle. Release builds use Rust 1.98.0, and the
GNU installers require glibc 2.34; CI rejects binaries that exceed that
limit.

The Linux x86-64 PR job compares the PGO binary with an unprofiled build
on a fixed, source-file-disjoint set of eight named projects. It warms
both binaries, runs paired per-case ABBA measurements, checks canonical
compiler output for every repeat, and gates aggregate speed, case
regressions, drift, and binary growth.

The [hosted PR
run](https://github.com/paradigmxyz/solar/actions/runs/33299097055)
measured these compile-time reductions:

| Case | Wall time |
| --- | ---: |
| `solady-lib-string` | 🟢 15.95% |
| `seaport-1.6-project` | 🟢 14.30% |
| `v4-core-project` | 🟢 13.11% |
| `morpho-blue-project` | 🟢 12.60% |
| `forge-std-1.16.1-project` | 🟢 12.71% |
| `prb-math-4.1.1-project` | 🟢 10.59% |
| `solmate-6-project` | 🟢 14.01% |
| `solarray-a547630-project` | 🟢 3.81% |
| **Geometric mean** | **🟢 12.20%** |

A local Valgrind 3.25.1 Callgrind run at commit `50c0b1a87` measured
retired guest instructions (`Ir`) for two ABBA legs per binary. This
deterministic count is a stable proxy for CPU work, not a hardware cycle
count. Canonical compiler output matched in every run, and maximum leg
drift was 0.09%.

| Case | Callgrind instructions |
| --- | ---: |
| `solady-lib-string` | 🟢 6.88% |
| `seaport-1.6-project` | 🟢 9.14% |
| `v4-core-project` | 🟢 9.13% |
| `morpho-blue-project` | 🟢 7.80% |
| `forge-std-1.16.1-project` | 🟢 7.88% |
| `prb-math-4.1.1-project` | 🟢 7.07% |
| `solmate-6-project` | 🟢 7.66% |
| `solarray-a547630-project` | 🟢 2.46% |
| **Geometric mean** | **🟢 7.27%** |

The Linux x86-64 binary decreased from 13,731,504 bytes to 13,011,952
bytes, or 5.24%. These measurements apply only to Linux x86-64.

Prompted by: @DaniPopes

---------

Co-authored-by: DaniPopes <57450786+DaniPopes@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `editorconfig-checker` | `3.11.1` → `3.11.2` | `3.11.1` → `3.11.2` |
| `prek` | `0.4.14` → `0.5.0` | `0.4.14` → `0.5.0` |
| `rumdl` | `0.2.60` → `0.2.62` | `0.2.60` → `0.2.62` |
| `shfmt` | `3.13.1` → `3.14.0` | `3.13.1` → `3.14.0` |
| `tombi` | `1.4.1` → `1.5.0` | `1.4.1` → `1.5.0` |
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>editorconfig-checker: `3.11.1` → `3.11.2` (editorconfig-checker/editorconfig-checker)</summary>

### v3.11.2

## editorconfig-checker v3.11.2 (2026-08-25T21:11:31Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* b0a550a82df22ed8bbc48156d3d6fa9bf20c975c: upgrade go to v1.27 to mitigate #613 (@​klaernie)

## Thanks!

Those were the changes on v3.11.2!

</details>
<details>
<summary>prek: `0.4.14` → `0.5.0` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

</details>
<details>
<summary>rumdl: `0.2.60` → `0.2.62` (rvben/rumdl)</summary>

### v0.2.61

### Added

- **cli**: add `--stdin-batch` for NUL-framed multi-document linting and `--stdin-batch-closed-world` for supplied-document-only link resolution

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-a… (truncated)

### v0.2.62

### Added

- **flavor**: add support for Markdown with Gherkin (MDG) ([db62377](rvben/rumdl@db62377))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarc… (truncated)

</details>
<details>
<summary>shfmt: `3.13.1` → `3.14.0` (mvdan/sh)</summary>

### v3.14.0

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

- **cmd/shfmt**
  - Add `--detect` to find shell files by executable bit or shebang - #944
- **syntax**
  - Add `Preorder`, an iterator over all nodes, complementing `Walk`
  - Add `encoding.TextUnmarshaler` implementations for each operator type
  - Support `${ foo;}` and `${|foo;}` inside double quotes - #1368
  - Support array elements in `{varname}` redirects, like `exec {fds[3]}>&-` - #719
  - Backslashes inside backquotes within double quotes escape double quotes - #1083
  - Allow pound signs in associative array keys like `${args[cmd,#]}` - #1285
  - Don't treat `#` as the start of a comment inside `[[ ]]` tests - #1326
  - Don't join `then` or `do` with a semicolon when heredocs are pending - #1047
  - Print a space after `!` in arithmetic expressions, avoiding history expansion - #987
  - Space nested closing parentheses like the opening ones - #876
  - Make `SplitBraces` reject malformed sequences and skip backslash escapes - #1330
  - Zsh: support the `${=name}`, `${~name}`, and `${^name}` prefixes - #1238
  - Zsh: support the `;|` case terminator and leading parentheses for globs - #1293, #1279
  - Zsh: parse subscript flag arguments as patterns, and allow `[` globs in arrays - #1278, #1322
- **syntax/typedjson**
  - Encode operators as their syntax form, such as `">>"`, rather than integers - #1321
  - Return errors rather than panicking on malformed input
- **interp**
  - Add `BashOpts` to set Bash options like `shopt` - #962
  - Add `AccessHandler` to control file access checks, used by `-r` and `cd` - #1318
  - Add `HandlerContext.LastExitStatus`, and provide a `HandlerContext` to stat handlers
  - Implement the `help` and `times` builtins, as well as `$-` - #1398
  - Implement the `;&` and `;;&` case terminators - #1391
  - Implemen… (truncated)

</details>
<details>
<summary>tombi: `1.4.1` → `1.5.0` (tombi-toml/tombi)</summary>

### v1.5.0

<!-- Release notes generated using configuration in .github/release.yml at v1.5.0 -->

## What's Changed
Tombi v1.5.0 is a major performance and architecture release.

We redesigned the parser and AST around a compact, source-backed syntax tape, replacing the previous red-green syntax tree.
The new architecture is optimized for Tombi’s lossless, long-lived editor and LSP workloads: it improves memory locality and reduces allocation and pointer-chasing overhead while preserving comments, punctuation, incomplete syntax, and diagnostics.
The AST and document-tree interfaces are now also separated from their syntax-backed implementations.

We also optimized hot paths throughout the parser, JSON Schema processing, linter, formatter, and stdin-based CLI workflows.
In our Apple M2 Max benchmarks, long ASCII comment lexing was approximately 2.3× faster, selected JSON parsing workloads improved by up to 84%, and repository-wide lint time decreased from approximately 355 ms to 81 ms.

### 🚨 Breaking Changes
* perf(parser): replace syntax tree with compact tape by @​ya7010 in tombi-toml/tombi#2140

### 🐝 Bug Fixes
* fix(lsp): preserve composite schema metadata by @​ya7010 in tombi-toml/tombi#2139

### 🛠️ Other Changes
* Improve minimal-change guidance for agents by @​ya7010 in tombi-toml/tombi#2137
* perf(parser): accelerate long comment scanning by @​ya7010 in tombi-toml/tombi#2141
* perf: speed up lint and format by @​ya7010 in tombi-toml/tombi#2142
* perf: reduce stdin runtime overhead by @​ya7010 in tombi-toml/tombi#2143
* perf(json): accelerate long string parsing by @​ya7010 in tombi-toml/tombi#2145
* perf(json): optimize lexer and parser hot paths by @​ya7010 in tombi-toml/tombi#2146

**Full Changelog**: https://github.com/tombi-toml/tomb… (truncated)

</details>
<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (7 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `aube` | `latest` → `latest` | `2.1.0` → `2.2.0` |
| `editorconfig-checker` | `3.11.1` → `3.11.2` | `3.11.1` → `3.11.2` |
| `prek` | `0.4.14` → `0.5.0` | `0.4.14` → `0.5.0` |
| `rumdl` | `0.2.60` → `0.2.62` | `0.2.60` → `0.2.62` |
| `shfmt` | `3.13.1` → `3.14.0` | `3.13.1` → `3.14.0` |
| `tombi` | `1.4.1` → `1.5.0` | `1.4.1` → `1.5.0` |
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (7 tools)</summary>

<details>
<summary>aube: `2.1.0` → `2.2.0` (jdx/aube)</summary>

### v2.2.0

A small release that gives standalone aube a bundled package-extensions compatibility catalog and exposes its node-gyp bootstrap through the public embedding facade.

## Added

- **Embeddable node-gyp bootstrap** ([#1365](aubepkg/aube#1365) by @​jdx) — aube's locked, in-process node-gyp bootstrap is now available through the stable embedding facade and returns the resolved executable path. This lets embedders (e.g. mise) service aube's lazy shim command without an ambient `npm` or a separately installed `aube` binary, while aube keeps ownership of the node-gyp version, cache layout, npmrc propagation, and cross-process locking. Standalone aube's hidden `__node-gyp-bootstrap` command now routes through the same API, and binary lookup uses `is_file()` across platform names so Windows `.exe`/`.cmd` caches resolve correctly.

## Fixed

- **Bundled curated package extensions** ([#1369](aubepkg/aube#1369) by @​jdx) — Standalone aube now ships a bundled compatibility catalog (~161 curated rules from Yarn's `@​yarnpkg/extensions@2.0.7` plus pnpm's Rust CLI additions) that repairs missing or incompatible peer/optional dependencies across common ecosystems (Angular, Nuxt, React, Vue, Gatsby, GraphQL, Webpack, Parcel, and more). The phantom rules removed upstream by pnpm are excluded. These defaults are applied at the lowest precedence — user and project `packageExtensions` always win — and are kept out of `packageExtensionsChecksum`, so catalog updates never invalidate existing lockfiles or break `--frozen-lockfile`. Set `ignoreCompatibilityDb=true` to opt out of the bundled repairs; malformed bundled entries are skipped with a `WARN_AUBE_INVALID_BUNDLED_PACKAGE_EXTENSION` warning rather than failing the install.

**Full Changelog**: aubepkg/aube@v2.1.0...v2.2.0

## 💚 Sponsor aube

aube is maintained by [@​jdx](https://github.com/jdx), an open source developer for [**entire.io**](https://entire.io),… (truncated)

</details>
<details>
<summary>editorconfig-checker: `3.11.1` → `3.11.2` (editorconfig-checker/editorconfig-checker)</summary>

### v3.11.2

## editorconfig-checker v3.11.2 (2026-08-25T21:11:31Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* b0a550a82df22ed8bbc48156d3d6fa9bf20c975c: upgrade go to v1.27 to mitigate #613 (@​klaernie)

## Thanks!

Those were the changes on v3.11.2!

</details>
<details>
<summary>prek: `0.4.14` → `0.5.0` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

</details>
<details>
<summary>rumdl: `0.2.60` → `0.2.62` (rvben/rumdl)</summary>

### v0.2.61

### Added

- **cli**: add `--stdin-batch` for NUL-framed multi-document linting and `--stdin-batch-closed-world` for supplied-document-only link resolution

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-a… (truncated)

### v0.2.62

### Added

- **flavor**: add support for Markdown with Gherkin (MDG) ([db62377](rvben/rumdl@db62377))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarc… (truncated)

</details>
<details>
<summary>shfmt: `3.13.1` → `3.14.0` (mvdan/sh)</summary>

### v3.14.0

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

- **cmd/shfmt**
  - Add `--detect` to find shell files by executable bit or shebang - #944
- **syntax**
  - Add `Preorder`, an iterator over all nodes, complementing `Walk`
  - Add `encoding.TextUnmarshaler` implementations for each operator type
  - Support `${ foo;}` and `${|foo;}` inside double quotes - #1368
  - Support array elements in `{varname}` redirects, like `exec {fds[3]}>&-` - #719
  - Backslashes inside backquotes within double quotes escape double quotes - #1083
  - Allow pound signs in associative array keys like `${args[cmd,#]}` - #1285
  - Don't treat `#` as the start of a comment inside `[[ ]]` tests - #1326
  - Don't join `then` or `do` with a semicolon when heredocs are pending - #1047
  - Print a space after `!` in arithmetic expressions, avoiding history expansion - #987
  - Space nested closing parentheses like the opening ones - #876
  - Make `SplitBraces` reject malformed sequences and skip backslash escapes - #1330
  - Zsh: support the `${=name}`, `${~name}`, and `${^name}` prefixes - #1238
  - Zsh: support the `;|` case terminator and leading parentheses for globs - #1293, #1279
  - Zsh: parse subscript flag arguments as patterns, and allow `[` globs in arrays - #1278, #1322
- **syntax/typedjson**
  - Encode operators as their syntax form, such as `">>"`, rather than integers - #1321
  - Return errors rather than panicking on malformed input
- **interp**
  - Add `BashOpts` to set Bash options like `shopt` - #962
  - Add `AccessHandler` to control file access checks, used by `-r` and `cd` - #1318
  - Add `HandlerContext.LastExitStatus`, and provide a `HandlerContext` to stat handlers
  - Implement the `help` and `times` builtins, as well as `$-` - #1398
  - Implement the `;&` and `;;&` case terminators - #1391
  - Implemen… (truncated)

</details>
<details>
<summary>tombi: `1.4.1` → `1.5.0` (tombi-toml/tombi)</summary>

### v1.5.0

<!-- Release notes generated using configuration in .github/release.yml at v1.5.0 -->

## What's Changed
Tombi v1.5.0 is a major performance and architecture release.

We redesigned the parser and AST around a compact, source-backed syntax tape, replacing the previous red-green syntax tree.
The new architecture is optimized for Tombi’s lossless, long-lived editor and LSP workloads: it improves memory locality and reduces allocation and pointer-chasing overhead while preserving comments, punctuation, incomplete syntax, and diagnostics.
The AST and document-tree interfaces are now also separated from their syntax-backed implementations.

We also optimized hot paths throughout the parser, JSON Schema processing, linter, formatter, and stdin-based CLI workflows.
In our Apple M2 Max benchmarks, long ASCII comment lexing was approximately 2.3× faster, selected JSON parsing workloads improved by up to 84%, and repository-wide lint time decreased from approximately 355 ms to 81 ms.

### 🚨 Breaking Changes
* perf(parser): replace syntax tree with compact tape by @​ya7010 in tombi-toml/tombi#2140

### 🐝 Bug Fixes
* fix(lsp): preserve composite schema metadata by @​ya7010 in tombi-toml/tombi#2139

### 🛠️ Other Changes
* Improve minimal-change guidance for agents by @​ya7010 in tombi-toml/tombi#2137
* perf(parser): accelerate long comment scanning by @​ya7010 in tombi-toml/tombi#2141
* perf: speed up lint and format by @​ya7010 in tombi-toml/tombi#2142
* perf: reduce stdin runtime overhead by @​ya7010 in tombi-toml/tombi#2143
* perf(json): accelerate long string parsing by @​ya7010 in tombi-toml/tombi#2145
* perf(json): optimize lexer and parser hot paths by @​ya7010 in tombi-toml/tombi#2146

**Full Changelog**: https://github.com/tombi-toml/tomb… (truncated)

</details>
<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
VedantMadane added a commit to VedantMadane/uv that referenced this pull request Sep 21, 2026
This PR enables PGO for uv releases, starting with Linux x86-64.

The release pipeline is modified as follows:

- We build instrumented `uv` and `uvx` release binaries inside the
existing manylinux container.
- We train directly on eleven shared `test/ecosystem` fixtures:
cibuildwheel, Cookiecutter, Flask, HTTPX, LLM, the OpenAI Python SDK,
Poetry, pytest-cov, Sentry, Zulip, and the 38-project pyx workspace.
- Every project exercises cold and warm `uv pip compile` resolution,
cold and warm `uv lock` resolution, `uv export`, `uv pip` installation,
and `uv sync` installation on every release platform.
- Per-project `exclude-dependencies` settings omit packages without
compatible release-platform wheels while preserving the rest of each
real dependency graph.
- Raw profiles are merged online by workload family, then merged with
`llvm-profdata` and fed back into the existing `maturin` build.
- JupyterLab, Saleor, Semantic Kernel, Transformers, and Warehouse
remain separate, held-out evaluation projects.

We benchmarked the builds on Linux x86-64 using the expanded corpus for
training and five separate held-out ecosystem projects for evaluation.

| Held-out project | Dependency resolution | Wheel installation |
Project locking | Lockfile export |
| ---------------- | --------------------: | -----------------: |
---------------: | --------------: |
| JupyterLab | 11.2% faster | 0.0% | 10.1% faster | 10.6% faster |
| Semantic Kernel | 9.3% faster | 7.1% faster | 12.5% faster | 8.7%
faster |
| Transformers | 11.7% faster | 4.1% faster | 9.5% faster | 11.0% faster
|
| Saleor | — | — | 9.7% faster | 10.0% faster |
| Warehouse | — | — | 9.7% faster | 7.6% faster |
| Geometric mean | **10.7% faster** | **3.7% faster** | **10.3% faster**
| **9.6% faster** |

Across all sixteen held-out workloads, wall time decreased by **8.9%**
(95% CI: 8.4–9.8%) and CPU time decreased by **8.4%** (95% CI:
7.9–9.0%). The matched Linux executable was **13.3% smaller** (58.91 MB
to 51.05 MB), or **12.3% smaller** after gzip compression (22.68 MB to
19.90 MB).

(Saleor and Warehouse include source-only dependencies, so they are
benchmarked on locking and export rather than wheel-only installation.)

Additional platforms are covered in subsequent PRs in the stack: macOS
ARM64, Windows x86-64, and Linux ARM64.

Ruff and ty follow the same approach; see the stacks here:

- astral-sh/ruff#27570
- astral-sh/ty#4213
VedantMadane added a commit to VedantMadane/uv that referenced this pull request Sep 21, 2026
## Summary

This PR enables PGO for uv's macOS ARM64 releases, following the
approach outlined in astral-sh#21001.
VedantMadane added a commit to VedantMadane/uv that referenced this pull request Sep 21, 2026
## Summary

This PR enables PGO for uv's Windows x86-64 releases, following the
approach outlined in astral-sh#21001. The
existing static-CRT configuration is preserved.
VedantMadane added a commit to VedantMadane/uv that referenced this pull request Sep 21, 2026
## Summary

This PR enables PGO for uv's Linux ARM64 releases, following the
approach outlined in astral-sh#21001. (To
enable PGO, we also move to a native ARM64 runner.)

This branch was previously deployed

1 inactive deployment
automations — aa0874f7 Deployed Aug 17, 2026 by charliermarsh via review / security review #44865
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal:releases Related to building and distributing release artifacts of uv

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants