Bump the dev-dependencies group across 16 directories with 1 update
Type: Pull Request
State: Open
Association: Unknown
Comments: 2
(2 months ago)
(2 months ago)
dependencies python:uv
Updates the requirements on and uv to permit the latest version.
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
0.11.14
Released on 2026-05-12.
Enhancements
- Add Astral mirror URL override (#19206)
... (truncated)
Commits
3cffe97Fix crates.io publish script lockfile (#19473)de16a7bBump version to 0.11.15 (#19472)cf826ccDisabletest_simultaneous_create_set_then_moveon Linux (#19469)2d566bcAllow retry ofcustom-publish-cratesseparately fromannounce(#19470)0588b8fRun release builds on maturin version bumps in CI (#19466)9a65753Enforce that entry points cannot escape in the scripts directory (#19464)d77d849Revert "Update maturin to v1.13.2 (#19445)" (#19465)5373e96Update Rust crate rustls to v0.23.40 (#19250)fb8d3d4Update Rust crate rustls-pki-types to v1.14.1 (#19251)078480dConfigure maturin and uv souv runcan be used to work on uv itself (#19461)- Additional commits viewable in compare view
Updates uv to 0.11.15
Release notes
Sourced from uv's releases.
0.11.15
Release Notes
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (#19452)
Documentation
- Move Bazel auth helper setup into integration guide (#19392)
Install uv 0.11.15
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh </tr></table>
... (truncated)
Changelog
Sourced from uv's changelog.
0.11.15
Released on 2026-05-18.
Security
- Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm (#19463)
- Enforce that entry points cannot escape in the scripts directory, see GHSA-4gg8-gxpx-9rph (#19464)
Enhancements
- Add TOML v1.1 -> v1.0 backwards compatibility for source distributions (#18741)
- Add support for Azure request signing (#19421)
- Apply stricter validation to all wheel filename segments (#19364)
- Reject empty strings as an invalid package name (#19435)
- Use structured errors for signing authentication failures (#19422)
Preview
- uv audit: Add JSON output (#19305)
Configuration
- Respect
required-environmentsinuv pip compile(#19378)Performance
- Avoid parsing JSON manifest when local Python is available (#19398)
- Avoid walking nested directories in linker conflict registration (#19382)
- Optimize async wheel ZIP writing (#19383)
- Fix dead "already trimmed" fast-path in
Version::only_release_trimmed(#19425)Bug fixes
- Apply workspace-member
[tool.uv.sources]credentials underuv sync --frozen(#19423)- Skip empty directories in uv build outputs (#19437)
- Fix Git submodule handling when using relative paths (#12156)
- Fix line number reporting in netrc parsing (
Technical Details
ID: 15845254UUID: 4473076307Node ID: PR_kwDOJnW9387c2atVHost: GitHub Repository: adamlui/python-utils