Skip to content

Validate source archives before cache persistence - #21248

Merged
zanieb merged 2 commits into
mainfrom
zb/validate-source-archives-before-persistence
Aug 27, 2026
Merged

zanieb merged 2 commits into
mainfrom
zb/validate-source-archives-before-persistence

Conversation

@zanieb

@zanieb zanieb commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Source archives can be saved to the cache before their caller-supplied hashes are checked. Cache repair can also save replacement contents before detecting a mismatch with the previous revision.

Check supplied hashes alongside the existing download-size check in ValidatedSourceArchive::extract, before it returns the value consumed by persist. Check every digest from a previous revision there too, before a repaired source tree is saved. Extraction still streams into a private temporary directory and returns parser errors immediately.

This also removes the split in persistence behavior captured by ArchiveOrigin. HTTP and local archives now accept AlreadyExists or DirectoryNotEmpty only when the destination is a directory, and both retain temporary-directory ownership through persistence. The HTTP path no longer calls TempDir::keep for archives with multiple top-level entries, so failed persistence attempts clean up those staged files too.

HTTP response handling and local file opening remain separate, and cache locations and rename_with_retry are unchanged. The caller still supplies the hashes and any download size to check; this PR does not read trusted hashes from uv.lock. #21223 supplies the hashes recorded in an existing uv.lock.

Based on #21247.

@codspeed

codspeed Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 31 untouched benchmarks
⏩ 6 skipped benchmarks1


Comparing zb/validate-source-archives-before-persistence (2f30e1a) with main (187300c)2

Open in CodSpeed

Footnotes

  1. 6 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

  2. No successful run was found on main (60a38ed) during the generation of this report, so 187300c was used instead as the comparison base. There might be some changes unrelated to this pull request in this report. ↩

@zanieb
zanieb force-pushed the zb/validate-source-archives-before-persistence branch from 8c0eb9d to 4372c31 Compare August 20, 2026 21:46
@zanieb
zanieb force-pushed the zb/validate-source-archives-before-persistence branch from 4372c31 to 1fcaeee Compare August 21, 2026 00:08
@zanieb
zanieb force-pushed the zb/validate-source-archives-before-persistence branch from a0cc44a to 5a201e7 Compare August 21, 2026 18:44
@zanieb
zanieb force-pushed the zb/validate-source-archives-before-persistence branch from 5a201e7 to b428b00 Compare August 24, 2026 16:47
astral-automations-bot Bot pushed a commit to astral-sh/uv-dev that referenced this pull request Aug 24, 2026
Source archive helpers currently extract an archive and save it to the
cache in the same call. Separate those steps so the type system records
that extraction and its existing checks have completed before
persistence.

Introduce a private `ValidatedSourceArchive` that owns the temporary
directory. Its HTTP and local constructors retain their transport setup,
diagnostics, and cleanup behavior, while a private reader helper
performs the shared extraction and hash collection. The consuming
`persist` method saves the source tree and returns the collected hashes
and byte count. This preserves existing behavior; it does not add
trusted-hash comparisons or change cache repair.

astral-sh#21247 separates hash generation from verification, and astral-sh#21248 checks
caller-supplied hashes before persistence.
@zsol
zsol self-requested a review August 24, 2026 16:53
Base automatically changed from zb/source-hash-verification-policy to main August 24, 2026 17:08
zanieb added a commit that referenced this pull request Aug 24, 2026
`HashStrategy` currently represents hash generation and verification as
mutually exclusive choices. A resolution may need both: verify artifacts
whose hashes have been supplied, while generating hashes for new
artifacts.

Store generation separately from `HashVerification` in `HashStrategy`.
Each distribution still receives a `HashPolicy` specifying whether to
generate or check hashes. Update existing call sites to use the separate
settings while preserving their hash inputs and which hashes uv treats
as trusted. Generation remains available for artifacts without supplied
hashes, unless the caller requires a hash for every artifact. This does
not read hashes from `uv.lock` or add new archive comparisons.

Based on #21246. #21248 checks caller-supplied hashes before source
archives enter the cache. #21223 reads hashes from an existing `uv.lock`
and supplies them for verification.
@zanieb
zanieb force-pushed the zb/validate-source-archives-before-persistence branch from b428b00 to 2f30e1a Compare August 24, 2026 17:08
@astral-sh-bot

astral-sh-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown

uv test inventory changes

This PR changes the tests when compared with the main base revision.

  • Added tests: 1
  • Removed tests: 0
  • Changed suites: 1
uv-distribution: +1 / -0

Added:

  • uv-distribution::source::validated_archive::tests::staging_directory_is_removed_on_drop_or_failure

Removed: none

@zanieb
zanieb marked this pull request as ready for review August 26, 2026 18:13

@zsol zsol left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

seems fine to me

expected_size,
},
)
.instrument(info_span!("download_source_dist", source_dist = %source))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit

Suggested change
.instrument(info_span!("download_source_dist", source_dist = %source))
.instrument(info_span!("fetch_extract_source_dist", source_dist = %source))

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the existing name for the span, just moved. Let's consider adjusting the span names separately.

@zanieb
zanieb merged commit fadb166 into main Aug 27, 2026
60 checks passed
@zanieb
zanieb deleted the zb/validate-source-archives-before-persistence branch August 27, 2026 13:34
luketainton pushed a commit to luketainton/repos_labmcp that referenced this pull request Aug 27, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | final | patch | `0.12.6` → `0.12.7` |

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.12.7`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0127)

Released on 2026-08-27.

##### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#&#8203;21323](astral-sh/uv#21323))

##### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#&#8203;21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#&#8203;21318](astral-sh/uv#21318))

##### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#&#8203;19693](astral-sh/uv#19693))

##### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#&#8203;21248](astral-sh/uv#21248))

##### Other changes

- remove pyx specific features ([#&#8203;21182](astral-sh/uv#21182), [#&#8203;21183](astral-sh/uv#21183), [#&#8203;21184](astral-sh/uv#21184), [#&#8203;21185](astral-sh/uv#21185), [#&#8203;21186](astral-sh/uv#21186))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40OC4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDguMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://git.tainton.uk/repos/labmcp/pulls/44
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
hbjydev pushed a commit to hbjydev/phoebe that referenced this pull request Aug 29, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [uv](https://github.com/astral-sh/uv) | tools | patch | `0.12.6` → `0.12.7` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/141) for more information.

---

### Release Notes

<details>
<summary>astral-sh/uv (uv)</summary>

### [`v0.12.7`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0127)

[Compare Source](astral-sh/uv@0.12.6...0.12.7)

Released on 2026-08-27.

##### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#&#8203;21323](astral-sh/uv#21323))

##### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#&#8203;21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#&#8203;21318](astral-sh/uv#21318))

##### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#&#8203;19693](astral-sh/uv#19693))

##### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#&#8203;21248](astral-sh/uv#21248))

##### Other changes

- remove pyx specific features ([#&#8203;21182](astral-sh/uv#21182), [#&#8203;21183](astral-sh/uv#21183), [#&#8203;21184](astral-sh/uv#21184), [#&#8203;21185](astral-sh/uv#21185), [#&#8203;21186](astral-sh/uv#21186))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40OC4xIiwidXBkYXRlZEluVmVyIjoiNDQuNDguMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvZ2l0aHViLXJlbGVhc2UiLCJ0eXBlL3BhdGNoIl19-->

Reviewed-on: https://forgejo.hayden.moe/hayden/phoebe/pulls/379
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `editorconfig-checker` | `3.11.1` → `3.11.2` | `3.11.1` → `3.11.2` |
| `prek` | `0.4.14` → `0.5.0` | `0.4.14` → `0.5.0` |
| `rumdl` | `0.2.60` → `0.2.62` | `0.2.60` → `0.2.62` |
| `shfmt` | `3.13.1` → `3.14.0` | `3.13.1` → `3.14.0` |
| `tombi` | `1.4.1` → `1.5.0` | `1.4.1` → `1.5.0` |
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>editorconfig-checker: `3.11.1` → `3.11.2` (editorconfig-checker/editorconfig-checker)</summary>

### v3.11.2

## editorconfig-checker v3.11.2 (2026-08-25T21:11:31Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* b0a550a82df22ed8bbc48156d3d6fa9bf20c975c: upgrade go to v1.27 to mitigate #613 (@​klaernie)

## Thanks!

Those were the changes on v3.11.2!

</details>
<details>
<summary>prek: `0.4.14` → `0.5.0` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

</details>
<details>
<summary>rumdl: `0.2.60` → `0.2.62` (rvben/rumdl)</summary>

### v0.2.61

### Added

- **cli**: add `--stdin-batch` for NUL-framed multi-document linting and `--stdin-batch-closed-world` for supplied-document-only link resolution

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-a… (truncated)

### v0.2.62

### Added

- **flavor**: add support for Markdown with Gherkin (MDG) ([db62377](rvben/rumdl@db62377))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarc… (truncated)

</details>
<details>
<summary>shfmt: `3.13.1` → `3.14.0` (mvdan/sh)</summary>

### v3.14.0

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

- **cmd/shfmt**
  - Add `--detect` to find shell files by executable bit or shebang - #944
- **syntax**
  - Add `Preorder`, an iterator over all nodes, complementing `Walk`
  - Add `encoding.TextUnmarshaler` implementations for each operator type
  - Support `${ foo;}` and `${|foo;}` inside double quotes - #1368
  - Support array elements in `{varname}` redirects, like `exec {fds[3]}>&-` - #719
  - Backslashes inside backquotes within double quotes escape double quotes - #1083
  - Allow pound signs in associative array keys like `${args[cmd,#]}` - #1285
  - Don't treat `#` as the start of a comment inside `[[ ]]` tests - #1326
  - Don't join `then` or `do` with a semicolon when heredocs are pending - #1047
  - Print a space after `!` in arithmetic expressions, avoiding history expansion - #987
  - Space nested closing parentheses like the opening ones - #876
  - Make `SplitBraces` reject malformed sequences and skip backslash escapes - #1330
  - Zsh: support the `${=name}`, `${~name}`, and `${^name}` prefixes - #1238
  - Zsh: support the `;|` case terminator and leading parentheses for globs - #1293, #1279
  - Zsh: parse subscript flag arguments as patterns, and allow `[` globs in arrays - #1278, #1322
- **syntax/typedjson**
  - Encode operators as their syntax form, such as `">>"`, rather than integers - #1321
  - Return errors rather than panicking on malformed input
- **interp**
  - Add `BashOpts` to set Bash options like `shopt` - #962
  - Add `AccessHandler` to control file access checks, used by `-r` and `cd` - #1318
  - Add `HandlerContext.LastExitStatus`, and provide a `HandlerContext` to stat handlers
  - Implement the `help` and `times` builtins, as well as `$-` - #1398
  - Implement the `;&` and `;;&` case terminators - #1391
  - Implemen… (truncated)

</details>
<details>
<summary>tombi: `1.4.1` → `1.5.0` (tombi-toml/tombi)</summary>

### v1.5.0

<!-- Release notes generated using configuration in .github/release.yml at v1.5.0 -->

## What's Changed
Tombi v1.5.0 is a major performance and architecture release.

We redesigned the parser and AST around a compact, source-backed syntax tape, replacing the previous red-green syntax tree.
The new architecture is optimized for Tombi’s lossless, long-lived editor and LSP workloads: it improves memory locality and reduces allocation and pointer-chasing overhead while preserving comments, punctuation, incomplete syntax, and diagnostics.
The AST and document-tree interfaces are now also separated from their syntax-backed implementations.

We also optimized hot paths throughout the parser, JSON Schema processing, linter, formatter, and stdin-based CLI workflows.
In our Apple M2 Max benchmarks, long ASCII comment lexing was approximately 2.3× faster, selected JSON parsing workloads improved by up to 84%, and repository-wide lint time decreased from approximately 355 ms to 81 ms.

### 🚨 Breaking Changes
* perf(parser): replace syntax tree with compact tape by @​ya7010 in tombi-toml/tombi#2140

### 🐝 Bug Fixes
* fix(lsp): preserve composite schema metadata by @​ya7010 in tombi-toml/tombi#2139

### 🛠️ Other Changes
* Improve minimal-change guidance for agents by @​ya7010 in tombi-toml/tombi#2137
* perf(parser): accelerate long comment scanning by @​ya7010 in tombi-toml/tombi#2141
* perf: speed up lint and format by @​ya7010 in tombi-toml/tombi#2142
* perf: reduce stdin runtime overhead by @​ya7010 in tombi-toml/tombi#2143
* perf(json): accelerate long string parsing by @​ya7010 in tombi-toml/tombi#2145
* perf(json): optimize lexer and parser hot paths by @​ya7010 in tombi-toml/tombi#2146

**Full Changelog**: https://github.com/tombi-toml/tomb… (truncated)

</details>
<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (7 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `aube` | `latest` → `latest` | `2.1.0` → `2.2.0` |
| `editorconfig-checker` | `3.11.1` → `3.11.2` | `3.11.1` → `3.11.2` |
| `prek` | `0.4.14` → `0.5.0` | `0.4.14` → `0.5.0` |
| `rumdl` | `0.2.60` → `0.2.62` | `0.2.60` → `0.2.62` |
| `shfmt` | `3.13.1` → `3.14.0` | `3.13.1` → `3.14.0` |
| `tombi` | `1.4.1` → `1.5.0` | `1.4.1` → `1.5.0` |
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (7 tools)</summary>

<details>
<summary>aube: `2.1.0` → `2.2.0` (jdx/aube)</summary>

### v2.2.0

A small release that gives standalone aube a bundled package-extensions compatibility catalog and exposes its node-gyp bootstrap through the public embedding facade.

## Added

- **Embeddable node-gyp bootstrap** ([#1365](aubepkg/aube#1365) by @​jdx) — aube's locked, in-process node-gyp bootstrap is now available through the stable embedding facade and returns the resolved executable path. This lets embedders (e.g. mise) service aube's lazy shim command without an ambient `npm` or a separately installed `aube` binary, while aube keeps ownership of the node-gyp version, cache layout, npmrc propagation, and cross-process locking. Standalone aube's hidden `__node-gyp-bootstrap` command now routes through the same API, and binary lookup uses `is_file()` across platform names so Windows `.exe`/`.cmd` caches resolve correctly.

## Fixed

- **Bundled curated package extensions** ([#1369](aubepkg/aube#1369) by @​jdx) — Standalone aube now ships a bundled compatibility catalog (~161 curated rules from Yarn's `@​yarnpkg/extensions@2.0.7` plus pnpm's Rust CLI additions) that repairs missing or incompatible peer/optional dependencies across common ecosystems (Angular, Nuxt, React, Vue, Gatsby, GraphQL, Webpack, Parcel, and more). The phantom rules removed upstream by pnpm are excluded. These defaults are applied at the lowest precedence — user and project `packageExtensions` always win — and are kept out of `packageExtensionsChecksum`, so catalog updates never invalidate existing lockfiles or break `--frozen-lockfile`. Set `ignoreCompatibilityDb=true` to opt out of the bundled repairs; malformed bundled entries are skipped with a `WARN_AUBE_INVALID_BUNDLED_PACKAGE_EXTENSION` warning rather than failing the install.

**Full Changelog**: aubepkg/aube@v2.1.0...v2.2.0

## 💚 Sponsor aube

aube is maintained by [@​jdx](https://github.com/jdx), an open source developer for [**entire.io**](https://entire.io),… (truncated)

</details>
<details>
<summary>editorconfig-checker: `3.11.1` → `3.11.2` (editorconfig-checker/editorconfig-checker)</summary>

### v3.11.2

## editorconfig-checker v3.11.2 (2026-08-25T21:11:31Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* b0a550a82df22ed8bbc48156d3d6fa9bf20c975c: upgrade go to v1.27 to mitigate #613 (@​klaernie)

## Thanks!

Those were the changes on v3.11.2!

</details>
<details>
<summary>prek: `0.4.14` → `0.5.0` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

</details>
<details>
<summary>rumdl: `0.2.60` → `0.2.62` (rvben/rumdl)</summary>

### v0.2.61

### Added

- **cli**: add `--stdin-batch` for NUL-framed multi-document linting and `--stdin-batch-closed-world` for supplied-document-only link resolution

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.61-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.61-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.61/rumdl-v0.2.61-aarch64-a… (truncated)

### v0.2.62

### Added

- **flavor**: add support for Markdown with Gherkin (MDG) ([db62377](rvben/rumdl@db62377))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.62-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.62-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarch64-apple-darwin.tar.gz) | macOS ARM64 (Apple Silicon) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.62/rumdl-v0.2.62-aarc… (truncated)

</details>
<details>
<summary>shfmt: `3.13.1` → `3.14.0` (mvdan/sh)</summary>

### v3.14.0

This release drops support for Go 1.25 and includes many enhancements, particularly in the interpreter, which implements more shell features and fixes many divergences from Bash.

- **cmd/shfmt**
  - Add `--detect` to find shell files by executable bit or shebang - #944
- **syntax**
  - Add `Preorder`, an iterator over all nodes, complementing `Walk`
  - Add `encoding.TextUnmarshaler` implementations for each operator type
  - Support `${ foo;}` and `${|foo;}` inside double quotes - #1368
  - Support array elements in `{varname}` redirects, like `exec {fds[3]}>&-` - #719
  - Backslashes inside backquotes within double quotes escape double quotes - #1083
  - Allow pound signs in associative array keys like `${args[cmd,#]}` - #1285
  - Don't treat `#` as the start of a comment inside `[[ ]]` tests - #1326
  - Don't join `then` or `do` with a semicolon when heredocs are pending - #1047
  - Print a space after `!` in arithmetic expressions, avoiding history expansion - #987
  - Space nested closing parentheses like the opening ones - #876
  - Make `SplitBraces` reject malformed sequences and skip backslash escapes - #1330
  - Zsh: support the `${=name}`, `${~name}`, and `${^name}` prefixes - #1238
  - Zsh: support the `;|` case terminator and leading parentheses for globs - #1293, #1279
  - Zsh: parse subscript flag arguments as patterns, and allow `[` globs in arrays - #1278, #1322
- **syntax/typedjson**
  - Encode operators as their syntax form, such as `">>"`, rather than integers - #1321
  - Return errors rather than panicking on malformed input
- **interp**
  - Add `BashOpts` to set Bash options like `shopt` - #962
  - Add `AccessHandler` to control file access checks, used by `-r` and `cd` - #1318
  - Add `HandlerContext.LastExitStatus`, and provide a `HandlerContext` to stat handlers
  - Implement the `help` and `times` builtins, as well as `$-` - #1398
  - Implement the `;&` and `;;&` case terminators - #1391
  - Implemen… (truncated)

</details>
<details>
<summary>tombi: `1.4.1` → `1.5.0` (tombi-toml/tombi)</summary>

### v1.5.0

<!-- Release notes generated using configuration in .github/release.yml at v1.5.0 -->

## What's Changed
Tombi v1.5.0 is a major performance and architecture release.

We redesigned the parser and AST around a compact, source-backed syntax tape, replacing the previous red-green syntax tree.
The new architecture is optimized for Tombi’s lossless, long-lived editor and LSP workloads: it improves memory locality and reduces allocation and pointer-chasing overhead while preserving comments, punctuation, incomplete syntax, and diagnostics.
The AST and document-tree interfaces are now also separated from their syntax-backed implementations.

We also optimized hot paths throughout the parser, JSON Schema processing, linter, formatter, and stdin-based CLI workflows.
In our Apple M2 Max benchmarks, long ASCII comment lexing was approximately 2.3× faster, selected JSON parsing workloads improved by up to 84%, and repository-wide lint time decreased from approximately 355 ms to 81 ms.

### 🚨 Breaking Changes
* perf(parser): replace syntax tree with compact tape by @​ya7010 in tombi-toml/tombi#2140

### 🐝 Bug Fixes
* fix(lsp): preserve composite schema metadata by @​ya7010 in tombi-toml/tombi#2139

### 🛠️ Other Changes
* Improve minimal-change guidance for agents by @​ya7010 in tombi-toml/tombi#2137
* perf(parser): accelerate long comment scanning by @​ya7010 in tombi-toml/tombi#2141
* perf: speed up lint and format by @​ya7010 in tombi-toml/tombi#2142
* perf: reduce stdin runtime overhead by @​ya7010 in tombi-toml/tombi#2143
* perf(json): accelerate long string parsing by @​ya7010 in tombi-toml/tombi#2145
* perf(json): optimize lexer and parser hot paths by @​ya7010 in tombi-toml/tombi#2146

**Full Changelog**: https://github.com/tombi-toml/tomb… (truncated)

</details>
<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 1, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.5` → `0.12.7` | `0.12.5` → `0.12.7` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.5` → `0.12.7` (astral-sh/uv)</summary>

### 0.12.6

## Release Notes

Released on 2026-08-25.

### Python

- Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 [#21295](astral-sh/uv#21295))
### Enhancements

- Report cache-cleaning space savings from filesystem block allocation and avoid double-counting hard links ([#21261](astral-sh/uv#21261))
- Limit warnings about unbounded `uv_build` requirements to source-distribution builds ([#21078](astral-sh/uv#21078))
- Display byte counts below 1 KiB without a fractional part ([#21237](astral-sh/uv#21237))

### Preview features

- Add `uv workspace metadata --sync --exact` to remove packages outside the selected resolution ([#21117](astral-sh/uv#21117))
- Add the `artifact-hash-filtering` preview feature to make `uv pip compile --generate-hashes` honor `--only-binary` and `--no-binary` ([#21235](astral-sh/uv#21235))
- Respect package-specific `exclude-newer` cutoffs when `uv check` selects its `ty` executable ([#21227](astral-sh/uv#21227))
- Preserve virtual-environment hints from `tar-codec` source-distribution errors when the base interpreter is outside a `bin` directory ([#21146](astral-sh/uv#21146))

### Performance

- Enable profile-guided optimization for Linux x86-64 release binaries ([#21001](astral-sh/uv#21001))
- Enable profile-guided optimization for Windows x86-64 release binaries ([#21003](astral-sh/uv#21003))
- Enable profile-guided optimization for macOS ARM64 release binaries ([#21002](astral-sh/uv#21002))
- Enable profile-guided optimization for Linux ARM64 release binaries ([#21004](astral-sh/uv#21004))
- Speed up syncing projects with many activated conflict items by reusing their encoded representation ([#21148](https://github.com/astral-sh/uv/pull/21148))… (truncated)

### 0.12.7

## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
zanieb added a commit that referenced this pull request Sep 8, 2026
`uv.lock` records archive digests, but checking an existing lockfile or
resolving with `--locked` can obtain source metadata without comparing
those digests. A replaced source archive can therefore run its build
backend before a later hash or lockfile check rejects it.

Construct a `HashStrategy` from the existing lockfile's hashes for
registry packages, direct URLs, and local archives. Enforce the recorded
hashes when reusing cached source metadata, resolving with `--locked`,
and installing build dependencies recorded in the lockfile into isolated
build environments. Normalize equivalent archive subdirectories so they
find the same recorded hashes. Keep recorded hashes while checking
whether an existing lockfile is still usable, but allow unlocked fresh
resolution to replace them. Build dependencies without recorded hashes
remain allowed.

Based on #21248, which checks source archives before saving them to the
cache. #21246 contains the structural refactor, and #21247 separates
hash generation from verification.

---------

Co-authored-by: Zanie Blue <contact@zanie.dev>
Co-authored-by: Tomasz Kramkowski <tom@astral.sh>
Co-authored-by: Charlie Marsh <charlie.r.marsh@gmail.com>
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
uv 0.12.7

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## Release Notes

Released on 2026-08-27.

### Python

- Replace managed Python installations when upgrading to a newer build of the same version ([#21323](astral-sh/uv#21323))

### Enhancements

- Support Linux `s390x`, `ppc64le`, and `loongarch64` targets for cross-platform dependency resolution ([#21313](astral-sh/uv#21313))
- Retry downloads with configured credentials when Azure Storage denies anonymous access to an endpoint configured via `UV_AZURE_ENDPOINT_URL` ([#21318](astral-sh/uv#21318))

### Preview features

- Use content-based directory hashes to deduplicate extracted wheels in the cache with the `content-addressed-cache` preview feature ([#19693](astral-sh/uv#19693))

### Bug fixes

- Reject source archives with hash mismatches before persisting their extracted contents to the cache ([#21248](astral-sh/uv#21248))

### Other changes

- remove pyx specific features ([#21182](astral-sh/uv#21182), [#21183](astral-sh/uv#21183), [#21184](astral-sh/uv#21184), [#21185](astral-sh/uv#21185), [#21186](astral-sh/uv#21186))

## Install uv 0.12.7

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"
```

## Download uv 0.12.7

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i686-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-pc-windows-msvc.zip) | x86 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-pc-windows-msvc.zip.sha256) |
| [uv-x86_64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-pc-windows-msvc.zip.sha256) |
| [uv-aarch64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [uv-i686-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-unknown-linux-gnu.tar.gz) | x86 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-unknown-linux-gnu.tar.gz.sha256) |
| [uv-powerpc64le-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-powerpc64le-unknown-linux-gnu.tar.gz) | PPC64LE Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-powerpc64le-unknown-linux-gnu.tar.gz.sha256) |
| [uv-riscv64gc-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-riscv64gc-unknown-linux-gnu.tar.gz) | RISCV Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-riscv64gc-unknown-linux-gnu.tar.gz.sha256) |
| [uv-s390x-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-s390x-unknown-linux-gnu.tar.gz) | S390x Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-s390x-unknown-linux-gnu.tar.gz.sha256) |
| [uv-x86_64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-unknown-linux-gnu.tar.gz) | x64 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [uv-armv7-unknown-linux-gnueabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-armv7-unknown-linux-gnueabihf.tar.gz) | ARMv7 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-armv7-unknown-linux-gnueabihf.tar.gz.sha256) |
| [uv-aarch64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-unknown-linux-musl.tar.gz) | ARM64 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [uv-i686-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-unknown-linux-musl.tar.gz) | x86 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-i686-unknown-linux-musl.tar.gz.sha256) |
| [uv-riscv64gc-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-riscv64gc-unknown-linux-musl.tar.gz) | RISCV MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-riscv64gc-unknown-linux-musl.tar.gz.sha256) |
| [uv-x86_64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-unknown-linux-musl.tar.gz) | x64 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [uv-arm-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-arm-unknown-linux-musleabihf.tar.gz) | ARMv6 MUSL Linux (Hardfloat) | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-arm-unknown-linux-musleabihf.tar.gz.sha256) |
| [uv-armv7-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-armv7-unknown-linux-musleabihf.tar.gz) | ARMv7 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-armv7-unknown-linux-musleabihf.tar.gz.sha256) |

## Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):
```sh
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
```

You can also download the attestation from [GitHub](https://github.com/astral-sh/uv/attestations) and verify against that directly:
```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```


</pre>
  <p>View the full release notes at <a href="https://github.com/astral-sh/uv/releases/tag/0.12.7">https://github.com/astral-sh/uv/releases/tag/0.12.7</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!17934

This branch was previously deployed

1 inactive deployment
automations — 2f30e1aa Deployed Aug 24, 2026 by zanieb via review / security review #45214
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants