Skip to content

Verify hashes on arbitrary-equality pins - #21543

Merged
zsol merged 5 commits into
mainfrom
zsol/verify-hashes-exact-pins
Sep 8, 2026
Merged

zsol merged 5 commits into
mainfrom
zsol/verify-hashes-exact-pins

Conversation

@astral-automations-bot

Copy link
Copy Markdown
Contributor

With the default hash verification mode, uv pip install and uv pip sync ignore a supplied --hash when a registry requirement uses ===. HashStrategy::pin recognizes only ==, so uv can install a wheel whose bytes do not match the expected digest.

Accept === pins in both hash modes, including --require-hashes. Required-hash mode still requires a trusted digest for every requirement.

@astral-automations-bot astral-automations-bot Bot added the bug Something isn't working label Sep 8, 2026
@zsol
zsol enabled auto-merge (squash) September 8, 2026 18:16
@zsol
zsol merged commit 681f4bd into main Sep 8, 2026
58 checks passed
@zsol
zsol deleted the zsol/verify-hashes-exact-pins branch September 8, 2026 18:21
hbjydev pushed a commit to hbjydev/phoebe that referenced this pull request Sep 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [uv](https://github.com/astral-sh/uv) | tools | patch | `0.12.10` → `0.12.11` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/141) for more information.

---

### Release Notes

<details>
<summary>astral-sh/uv (uv)</summary>

### [`v0.12.11`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01211)

[Compare Source](astral-sh/uv@0.12.10...0.12.11)

Released on 2026-09-08.

##### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#&#8203;20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#&#8203;21462](astral-sh/uv#21462))

##### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#&#8203;21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#&#8203;21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#&#8203;21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#&#8203;21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#&#8203;21523](astral-sh/uv#21523))

##### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#&#8203;21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#&#8203;21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#&#8203;21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#&#8203;19159](astral-sh/uv#19159))
- Trim surrounding whitespace from entries in `.python-version` and `.python-versions` files ([#&#8203;21529](astral-sh/uv#21529))
- Suppress `VIRTUAL_ENV` mismatch warnings for `uv add --no-sync`, `uv remove --no-sync`, and `uv add --frozen` ([#&#8203;21496](astral-sh/uv#21496))
- Warn and continue when `uv python list` cannot query an interpreter ([#&#8203;21498](astral-sh/uv#21498))

##### Documentation

- Restore TOML syntax highlighting for `exclude-newer` examples ([#&#8203;21534](astral-sh/uv#21534))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/London)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42OS4xMSIsInVwZGF0ZWRJblZlciI6IjQ0LjY5LjExIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9naXRodWItcmVsZWFzZSIsInR5cGUvcGF0Y2giXX0=-->

Reviewed-on: https://forgejo.hayden.moe/hayden/phoebe/pulls/518
luketainton pushed a commit to luketainton/luke_rsu that referenced this pull request Sep 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | stage | patch | `0.12.9` → `0.12.12` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/11) for more information.

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.12.12`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01212)

[Compare Source](astral-sh/uv@0.12.11...0.12.12)

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

##### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#&#8203;21539](astral-sh/uv#21539))

### [`v0.12.11`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01211)

[Compare Source](astral-sh/uv@0.12.10...0.12.11)

Released on 2026-09-08.

##### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#&#8203;20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#&#8203;21462](astral-sh/uv#21462))

##### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#&#8203;21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#&#8203;21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#&#8203;21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#&#8203;21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#&#8203;21523](astral-sh/uv#21523))

##### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#&#8203;21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#&#8203;21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#&#8203;21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#&#8203;19159](astral-sh/uv#19159))
- Trim surrounding whitespace from entries in `.python-version` and `.python-versions` files ([#&#8203;21529](astral-sh/uv#21529))
- Suppress `VIRTUAL_ENV` mismatch warnings for `uv add --no-sync`, `uv remove --no-sync`, and `uv add --frozen` ([#&#8203;21496](astral-sh/uv#21496))
- Warn and continue when `uv python list` cannot query an interpreter ([#&#8203;21498](astral-sh/uv#21498))

##### Documentation

- Restore TOML syntax highlighting for `exclude-newer` examples ([#&#8203;21534](astral-sh/uv#21534))

### [`v0.12.10`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01210)

[Compare Source](astral-sh/uv@0.12.9...0.12.10)

Released on 2026-09-04.

##### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#&#8203;21423](astral-sh/uv#21423))

##### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#&#8203;21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#&#8203;21404](astral-sh/uv#21404))

##### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#&#8203;21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#&#8203;21389](astral-sh/uv#21389))

##### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#&#8203;21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#&#8203;19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#&#8203;21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#&#8203;21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#&#8203;21453](astral-sh/uv#21453))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42Mi4yIiwidXBkYXRlZEluVmVyIjoiNDQuNjIuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://git.tainton.uk/repos/rsu/pulls/42
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton pushed a commit to luketainton/repos_labmcp that referenced this pull request Sep 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | final | patch | `0.12.9` → `0.12.12` |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/51) for more information.

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.12.12`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01212)

[Compare Source](astral-sh/uv@0.12.11...0.12.12)

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

##### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#&#8203;21539](astral-sh/uv#21539))

### [`v0.12.11`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01211)

[Compare Source](astral-sh/uv@0.12.10...0.12.11)

Released on 2026-09-08.

##### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#&#8203;20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#&#8203;21462](astral-sh/uv#21462))

##### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#&#8203;21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#&#8203;21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#&#8203;21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#&#8203;21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#&#8203;21523](astral-sh/uv#21523))

##### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#&#8203;21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#&#8203;21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#&#8203;21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#&#8203;19159](astral-sh/uv#19159))
- Trim surrounding whitespace from entries in `.python-version` and `.python-versions` files ([#&#8203;21529](astral-sh/uv#21529))
- Suppress `VIRTUAL_ENV` mismatch warnings for `uv add --no-sync`, `uv remove --no-sync`, and `uv add --frozen` ([#&#8203;21496](astral-sh/uv#21496))
- Warn and continue when `uv python list` cannot query an interpreter ([#&#8203;21498](astral-sh/uv#21498))

##### Documentation

- Restore TOML syntax highlighting for `exclude-newer` examples ([#&#8203;21534](astral-sh/uv#21534))

### [`v0.12.10`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01210)

[Compare Source](astral-sh/uv@0.12.9...0.12.10)

Released on 2026-09-04.

##### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#&#8203;21423](astral-sh/uv#21423))

##### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#&#8203;21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#&#8203;21404](astral-sh/uv#21404))

##### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#&#8203;21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#&#8203;21389](astral-sh/uv#21389))

##### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#&#8203;21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#&#8203;19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#&#8203;21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#&#8203;21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#&#8203;21453](astral-sh/uv#21453))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42Mi4yIiwidXBkYXRlZEluVmVyIjoiNDQuNjIuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://git.tainton.uk/repos/labmcp/pulls/54
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.0` → `0.5.2` | `0.5.0` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.0` → `0.5.2` (j178/prek)</summary>

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.1` → `0.5.2` | `0.5.1` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.8` → `0.12.12` | `0.12.8` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.1` → `0.5.2` (j178/prek)</summary>

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.8` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.7` → `0.12.13` | `0.12.7` → `0.12.13` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.7` → `0.12.13` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

### 0.12.13

## Release Notes

Released on 2026-09-10.

### Python

- Add GraalPy 3.13.0 ([#21431](astral-sh/uv#21431))

### Enhancements

- Verify hashes when downloading PEP 658 metadata sidecars ([#21563](astral-sh/uv#21563))

### Preview features

- Respect `ty` exclusions when `uv check` automatically selects members of a virtual workspace ([#21555](astral-sh/uv#21555))

### Performance

- Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately ([#21279](astral-sh/uv#21279))

### Bug fixes

- Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention ([#18713](astral-sh/uv#18713))
- Prefer `core-metadata` over legacy aliases in JSON index responses ([#21563](astral-sh/uv#21563))

## Install uv 0.12.13

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1 | iex"
```

## Download uv 0.12.13

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.12.7` → `0.12.13` | `0.12.7` → `0.12.13` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.12.7` → `0.12.13` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

### 0.12.13

## Release Notes

Released on 2026-09-10.

### Python

- Add GraalPy 3.13.0 ([#21431](astral-sh/uv#21431))

### Enhancements

- Verify hashes when downloading PEP 658 metadata sidecars ([#21563](astral-sh/uv#21563))

### Preview features

- Respect `ty` exclusions when `uv check` automatically selects members of a virtual workspace ([#21555](astral-sh/uv#21555))

### Performance

- Avoid full wheel downloads during resolution by reusing supported hashes from direct URL fragments when metadata is available separately ([#21279](astral-sh/uv#21279))

### Bug fixes

- Edit Windows entry-point launcher resources in memory to support Nano Server and reduce antivirus contention ([#18713](astral-sh/uv#18713))
- Prefer `core-metadata` over legacy aliases in JSON index responses ([#21563](astral-sh/uv#21563))

## Install uv 0.12.13

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1 | iex"
```

## Download uv 0.12.13

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
uv 0.12.11

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Trim surrounding whitespace from entries in `.python-version` and `.python-versions` files ([#21529](astral-sh/uv#21529))
- Suppress `VIRTUAL_ENV` mismatch warnings for `uv add --no-sync`, `uv remove --no-sync`, and `uv add --frozen` ([#21496](astral-sh/uv#21496))
- Warn and continue when `uv python list` cannot query an interpreter ([#21498](astral-sh/uv#21498))

### Documentation

- Restore TOML syntax highlighting for `exclude-newer` examples ([#21534](astral-sh/uv#21534))

## Install uv 0.12.11

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-installer.ps1 | iex"
```

## Download uv 0.12.11

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i686-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-pc-windows-msvc.zip) | x86 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-pc-windows-msvc.zip.sha256) |
| [uv-x86_64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-pc-windows-msvc.zip.sha256) |
| [uv-aarch64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [uv-i686-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-unknown-linux-gnu.tar.gz) | x86 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-unknown-linux-gnu.tar.gz.sha256) |
| [uv-powerpc64le-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-powerpc64le-unknown-linux-gnu.tar.gz) | PPC64LE Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-powerpc64le-unknown-linux-gnu.tar.gz.sha256) |
| [uv-riscv64gc-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-riscv64gc-unknown-linux-gnu.tar.gz) | RISCV Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-riscv64gc-unknown-linux-gnu.tar.gz.sha256) |
| [uv-s390x-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-s390x-unknown-linux-gnu.tar.gz) | S390x Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-s390x-unknown-linux-gnu.tar.gz.sha256) |
| [uv-x86_64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-unknown-linux-gnu.tar.gz) | x64 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [uv-armv7-unknown-linux-gnueabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-armv7-unknown-linux-gnueabihf.tar.gz) | ARMv7 Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-armv7-unknown-linux-gnueabihf.tar.gz.sha256) |
| [uv-aarch64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-unknown-linux-musl.tar.gz) | ARM64 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [uv-i686-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-unknown-linux-musl.tar.gz) | x86 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-i686-unknown-linux-musl.tar.gz.sha256) |
| [uv-riscv64gc-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-riscv64gc-unknown-linux-musl.tar.gz) | RISCV MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-riscv64gc-unknown-linux-musl.tar.gz.sha256) |
| [uv-x86_64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-unknown-linux-musl.tar.gz) | x64 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [uv-arm-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-arm-unknown-linux-musleabihf.tar.gz) | ARMv6 MUSL Linux (Hardfloat) | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-arm-unknown-linux-musleabihf.tar.gz.sha256) |
| [uv-armv7-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-armv7-unknown-linux-musleabihf.tar.gz) | ARMv7 MUSL Linux | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-armv7-unknown-linux-musleabihf.tar.gz.sha256) |

## Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):
```sh
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
```

You can also download the attestation from [GitHub](https://github.com/astral-sh/uv/attestations) and verify against that directly:
```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```


</pre>
  <p>View the full release notes at <a href="https://github.com/astral-sh/uv/releases/tag/0.12.11">https://github.com/astral-sh/uv/releases/tag/0.12.11</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!18760

This branch was previously deployed

1 inactive deployment
automations — 9d40ad98 Deployed Sep 8, 2026 by astral-automations-bot[bot] via review / security review #46107
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant