chore(deps): update astral-sh/setup-uv action to v8 #433

Merged
luke merged 1 commits from renovate/astral-sh-setup-uv-8.x into main 2026-04-16 19:38:46 +00:00
Member

This PR contains the following updates:

Package Type Update Change
astral-sh/setup-uv action major v7v8.0.0

Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v8.0.0: 🌈 Immutable releases and secure tags

Compare Source

This is the first immutable release of setup-uv 🥳

All future releases are also immutable, if you want to know more about what this means checkout the docs.

This release also has two breaking changes

New format for manifest-file

The previously deprecated way of defining a custom version manifest to control which uv versions are available and where to download them from got removed. The functionality is still there but you have to use the new format.

No more major and minor tags

To increase security even more we will stop publishing minor tags. You won't be able to use @v8 or @v8.0 any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to tj-actions.

[!TIP]
Use the immutable tag as a version astral-sh/setup-uv@v8.0.0
Or even better the githash astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57

🚨 Breaking changes

🧰 Maintenance

v7.6.0: 🌈 Fetch uv from Astral's mirror by default

Compare Source

Changes

We now default to download uv from releases.astral.sh.
This means by default we don't hit the GitHub API at all and shouldn't see any rate limits and timeouts any more.

🚀 Enhancements

🧰 Maintenance

⬆️ Dependency updates

v7.5.0: 🌈 Use astral-sh/versions as version provider

Compare Source

No more rate-limits

This release addresses a long-standing source of timeouts and rate-limit failures in setup-uv.

Previously, the action resolved version identifiers like 0.5.x by iterating over available uv releases via the GitHub API to find the best match. In contrast, latest and exact versions such as 0.5.0 skipped version resolution entirely and downloaded uv directly.

The manifest-file input was an earlier attempt to improve this. It allows providing an url to a file that lists available versions, checksums, and even custom download URLs. The action also shipped with such a manifest.
However, because that bundled file could become outdated whenever new uv releases were published, the action still had to fall back to the GitHub API in many cases.

This release solves the problem by sourcing version data from Astral’s versions repository via the raw content endpoint:

https://raw.githubusercontent.com/astral-sh/versions/refs/heads/main/v1/uv.ndjson

By using the raw endpoint instead of the GitHub API, version resolution no longer depends on API authentication and is much less likely to run into rate limits or timeouts.


[!TIP]
The next section is only interesting for users of the manifest-file input

The manifest-file input lets you override that source with your own URL, for example to test custom uv builds or alternate download locations.

The manifest file must be in NDJSON format, where each line is a JSON object representing a version and its artifacts. For example:

{"version":"0.10.7","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]}
{"version":"0.10.6","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]}

[!WARNING]
The old format still works but is deprecated. A warning will be logged when you use it.

Changes

🚀 Enhancements

📚 Documentation

v7.4.0: 🌈 Add riscv64 architecture support to platform detection

Compare Source

Changes

Thank you @​luhenry for adding support for riscv64 arch

🚀 Enhancements

🧰 Maintenance

⬆️ Dependency updates

v7.3.1: 🌈 fall back to VERSION_CODENAME when VERSION_ID is not available

Compare Source

Changes

This release adds support for running in containers like debian:testing or debian:unstable

🐛 Bug fixes

🧰 Maintenance

⬆️ Dependency updates

v7.3.0: 🌈 New features and bug fixes for activate-environment

Compare Source

Changes

This release contains a few bug fixes and a new feature for the activate-environment functionality.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v7.2.1: 🌈 update known checksums up to 0.9.28

Compare Source

Changes

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v7.2.0: 🌈 add outputs python-version and python-cache-hit

Compare Source

Changes

Among some minor typo fixes and quality of life features for developers of actions the main feature of this release are new outputs:

  • python-version: The Python version that was set (same content as existing UV_PYTHON)
  • python-cache-hit: A boolean value to indicate the Python cache entry was found

While implementing this it became clear, that it is easier to handle the Python binaries in a separate cache entry. The added benefit for users is that the "normal" cache containing the dependencies can be used in all runs no matter if these cache the Python binaries or not.

[!NOTE]
This release will invalidate caches that contain the Python binaries. This happens a single time.

🐛 Bug fixes

  • chore: remove stray space from UV_PYTHON_INSTALL_DIR message @​akx (#​720)

🚀 Enhancements

🧰 Maintenance

⬆️ Dependency updates

v7.1.6: 🌈 add OS version to cache key to prevent binary incompatibility

Compare Source

Changes

This release will invalidate your cache existing keys!

The os version e.g. ubuntu-22.04 is now part of the cache key. This prevents failing builds when a cache got populated with wheels built with different tools (e.g. glibc) than are present on the runner where the cache got restored.

🐛 Bug fixes

🧰 Maintenance

⬆️ Dependency updates

v7.1.5: 🌈 allow setting cache-local-path without enable-cache: true

Compare Source

Changes

#​612 fixed a faulty behavior where this action set UV_CACHE_DIR even though enable-cache was false. It also fixed the cases were the cache dir is already configured in a settings file like pyproject.toml or UV_CACHE_DIR was already set. Here the action shouldn't overwrite or set UV_CACHE_DIR.

These fixes introduced an unwanted behavior: You can still set cache-local-path but this action didn't do anything. This release fixes that.

You can now use cache-local-path to automatically set UV_CACHE_DIR even when enable-cache is false (or gets set to false by default e.g. on self-hosted runners)

- name: This is now possible
  uses: astral-sh/setup-uv@v7
  with:
    enable-cache: false
    cache-local-path: "/path/to/cache"

🐛 Bug fixes

🧰 Maintenance

⬆️ Dependency updates

v7.1.4: 🌈 Fix libuv closing bug on Windows

Compare Source

Changes

This release fixes the bug Assertion failed: !(handle->flags & UV_HANDLE_CLOSING) on Windows runners

🐛 Bug fixes

🧰 Maintenance

v7.1.3: 🌈 Support act

Compare Source

Changes

This bug fix release adds support for https://github.com/nektos/act
It was previously broken because of a too new undici version and TS transpilation target.

Compatibility with act is now automatically tested.

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

v7.1.2: 🌈 Speed up extraction on Windows

Compare Source

Changes

@​lazka fixed a bug that caused extracting uv to take up to 30s. Thank you!

🐛 Bug fixes

🧰 Maintenance

⬆️ Dependency updates

v7.1.1: 🌈 Fix empty workdir detection and lowest resolution strategy

Compare Source

Changes

This release fixes a bug where the working-directory input was not used to detect an empty work dir. It also fixes the lowest resolution strategy resolving to latest when only a lower bound was specified.

Special thanks to @​tpgillam for the first contribution!

🐛 Bug fixes

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v7.1.0: 🌈 Support all the use cases

Compare Source

Changes

Support all the use cases!!!
... well, that we know of.

This release adds support for some use cases that most users don't encounter but are useful for e.g. people running Gitea.

The input resolution-strategy lets you use the lowest possible version of uv from a version range. Useful if you want to test your tool with different versions of uv.

If you use activate-environment the path to the activated venv is now also exposed under the output venv.

Downloaded python installations can now also be uploaded to the GitHub Actions cache backend. Useful if you are running in act and have configured your own backend and don't want to download python again, and again over a slow internet connection.

Finally the path to installed python interpreters is now added to the PATH on Windows.

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | action | major | `v7` → `v8.0.0` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v8.0.0`](https://github.com/astral-sh/setup-uv/releases/tag/v8.0.0): 🌈 Immutable releases and secure tags [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.6.0...v8.0.0) ### This is the first immutable release of `setup-uv` 🥳 All future releases are also immutable, if you want to know more about what this means checkout [the docs](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases). This release also has two breaking changes #### New format for `manifest-file` The previously deprecated way of defining a custom version manifest to control which `uv` versions are available and where to download them from got removed. The functionality is still there but you have to use the [new format](https://github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format). #### No more major and minor tags To increase **security** even more we will **stop publishing minor tags**. You won't be able to use `@v8` or `@v8.0` any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to [tj-actions](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/). > \[!TIP] > Use the immutable tag as a version `astral-sh/setup-uv@v8.0.0` > Or even better the githash `astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57` #### 🚨 Breaking changes - Remove update-major-minor-tags workflow [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;826](https://github.com/astral-sh/setup-uv/issues/826)) - Remove deprecrated custom manifest [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;813](https://github.com/astral-sh/setup-uv/issues/813)) #### 🧰 Maintenance - Shortcircuit latest version from manifest [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;828](https://github.com/astral-sh/setup-uv/issues/828)) - Simplify inputs.ts [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;827](https://github.com/astral-sh/setup-uv/issues/827)) - Bump release-drafter to v7.1.1 [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;825](https://github.com/astral-sh/setup-uv/issues/825)) - Refactor inputs [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;823](https://github.com/astral-sh/setup-uv/issues/823)) - Replace inline compile args with tsconfig [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;824](https://github.com/astral-sh/setup-uv/issues/824)) - chore: update known checksums for 0.11.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;821](https://github.com/astral-sh/setup-uv/issues/821)) - chore: update known checksums for 0.11.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;817](https://github.com/astral-sh/setup-uv/issues/817)) - chore: update known checksums for 0.11.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;815](https://github.com/astral-sh/setup-uv/issues/815)) - Fix latest-version workflow check [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;812](https://github.com/astral-sh/setup-uv/issues/812)) - chore: update known checksums for 0.10.11/0.10.12 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;811](https://github.com/astral-sh/setup-uv/issues/811)) ### [`v7.6.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.6.0): 🌈 Fetch uv from Astral's mirror by default [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.5.0...v7.6.0) #### Changes We now default to download uv from `releases.astral.sh`. This means by default we don't hit the GitHub API at all and shouldn't see any rate limits and timeouts any more. #### 🚀 Enhancements - Fetch uv from Astral's mirror by default [@&#8203;zsol](https://github.com/zsol) ([#&#8203;809](https://github.com/astral-sh/setup-uv/issues/809)) #### 🧰 Maintenance - Switch to ESM for source and test, use CommonJS for dist [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;806](https://github.com/astral-sh/setup-uv/issues/806)) - chore: update known checksums for 0.10.10 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;804](https://github.com/astral-sh/setup-uv/issues/804)) #### ⬆️ Dependency updates - chore(deps): bump zizmorcore/zizmor-action from 0.5.0 to 0.5.2 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;808](https://github.com/astral-sh/setup-uv/issues/808)) - Bump deps [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;805](https://github.com/astral-sh/setup-uv/issues/805)) ### [`v7.5.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.5.0): 🌈 Use `astral-sh/versions` as version provider [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.4.0...v7.5.0) ### No more rate-limits This release addresses a long-standing source of timeouts and rate-limit failures in setup-uv. Previously, the action resolved version identifiers like 0.5.x by iterating over available uv releases via the GitHub API to find the best match. In contrast, latest and exact versions such as 0.5.0 skipped version resolution entirely and downloaded uv directly. The `manifest-file` input was an earlier attempt to improve this. It allows providing an url to a file that lists available versions, checksums, and even custom download URLs. The action also shipped with such a manifest. However, because that bundled file could become outdated whenever new uv releases were published, the action still had to fall back to the GitHub API in many cases. This release solves the problem by sourcing version data from Astral’s versions repository via the raw content endpoint: <https://raw.githubusercontent.com/astral-sh/versions/refs/heads/main/v1/uv.ndjson> By using the raw endpoint instead of the GitHub API, version resolution no longer depends on API authentication and is much less likely to run into rate limits or timeouts. *** > \[!TIP] > The next section is only interesting for users of the `manifest-file` input The `manifest-file` input lets you override that source with your own URL, for example to test custom uv builds or alternate download locations. The manifest file must be in NDJSON format, where each line is a JSON object representing a version and its artifacts. For example: ```json {"version":"0.10.7","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]} {"version":"0.10.6","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]} ``` > \[!WARNING]\ > The old format still works but is deprecated. A warning will be logged when you use it. #### Changes - docs: replace copilot instructions with AGENTS.md [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;794](https://github.com/astral-sh/setup-uv/issues/794)) #### 🚀 Enhancements - Use astral-sh/versions as primary version provider [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;802](https://github.com/astral-sh/setup-uv/issues/802)) #### 📚 Documentation - docs: add cross-client dependabot rollup skill [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;793](https://github.com/astral-sh/setup-uv/issues/793)) ### [`v7.4.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.4.0): 🌈 Add riscv64 architecture support to platform detection [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.3.1...v7.4.0) #### Changes Thank you [@&#8203;luhenry](https://github.com/luhenry) for adding support for riscv64 arch #### 🚀 Enhancements - Add riscv64 architecture support to platform detection [@&#8203;luhenry](https://github.com/luhenry) ([#&#8203;791](https://github.com/astral-sh/setup-uv/issues/791)) #### 🧰 Maintenance - Delete .github/workflows/dependabot-build.yml [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;789](https://github.com/astral-sh/setup-uv/issues/789)) - Harden Dependabot build workflow [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;788](https://github.com/astral-sh/setup-uv/issues/788)) - Fix: check PR author instead of event sender for Dependabot detection [@&#8203;eifinger-bot](https://github.com/eifinger-bot) ([#&#8203;787](https://github.com/astral-sh/setup-uv/issues/787)) - chore: update known checksums for 0.10.9 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;783](https://github.com/astral-sh/setup-uv/issues/783)) - Add workflow to auto-build dist on Dependabot PRs [@&#8203;eifinger-bot](https://github.com/eifinger-bot) ([#&#8203;782](https://github.com/astral-sh/setup-uv/issues/782)) - chore: update known checksums for 0.10.8 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;779](https://github.com/astral-sh/setup-uv/issues/779)) - chore: update known checksums for 0.10.7 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;775](https://github.com/astral-sh/setup-uv/issues/775)) #### ⬆️ Dependency updates - chore(deps): bump versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;792](https://github.com/astral-sh/setup-uv/issues/792)) - Bump actions/setup-node from 6.2.0 to 6.3.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;790](https://github.com/astral-sh/setup-uv/issues/790)) - Bump eifinger/actionlint-action from 1.10.0 to 1.10.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;778](https://github.com/astral-sh/setup-uv/issues/778)) ### [`v7.3.1`](https://github.com/astral-sh/setup-uv/releases/tag/v7.3.1): 🌈 fall back to VERSION_CODENAME when VERSION_ID is not available [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.3.0...v7.3.1) #### Changes This release adds support for running in containers like `debian:testing` or `debian:unstable` #### 🐛 Bug fixes - fix: fall back to VERSION\_CODENAME when VERSION\_ID is not available [@&#8203;eifinger-bot](https://github.com/eifinger-bot) ([#&#8203;774](https://github.com/astral-sh/setup-uv/issues/774)) #### 🧰 Maintenance - chore: update known checksums for 0.10.6 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;771](https://github.com/astral-sh/setup-uv/issues/771)) - chore: update known checksums for 0.10.5 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;770](https://github.com/astral-sh/setup-uv/issues/770)) - chore: update known checksums for 0.10.4 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;768](https://github.com/astral-sh/setup-uv/issues/768)) - chore: update known checksums for 0.10.3 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;767](https://github.com/astral-sh/setup-uv/issues/767)) - chore: update known checksums for 0.10.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;765](https://github.com/astral-sh/setup-uv/issues/765)) - chore: update known checksums for 0.10.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;764](https://github.com/astral-sh/setup-uv/issues/764)) #### ⬆️ Dependency updates - Bump github/codeql-action from 4.31.9 to 4.32.2 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;766](https://github.com/astral-sh/setup-uv/issues/766)) - Bump zizmorcore/zizmor-action from 0.4.1 to 0.5.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;763](https://github.com/astral-sh/setup-uv/issues/763)) ### [`v7.3.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.3.0): 🌈 New features and bug fixes for activate-environment [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.2.1...v7.3.0) #### Changes This release contains a few bug fixes and a new feature for the activate-environment functionality. #### 🐛 Bug fixes - fix: warn instead of error when no python to cache [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;762](https://github.com/astral-sh/setup-uv/issues/762)) - fix: use --clear to create venv [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;761](https://github.com/astral-sh/setup-uv/issues/761)) #### 🚀 Enhancements - feat: add venv-path input for activate-environment [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;746](https://github.com/astral-sh/setup-uv/issues/746)) #### 🧰 Maintenance - chore: update known checksums for 0.10.0 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;759](https://github.com/astral-sh/setup-uv/issues/759)) - refactor: tilde-expansion tests as unittests and no self-hosted tests [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;760](https://github.com/astral-sh/setup-uv/issues/760)) - chore: update known checksums for 0.9.30 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;756](https://github.com/astral-sh/setup-uv/issues/756)) - chore: update known checksums for 0.9.29 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;748](https://github.com/astral-sh/setup-uv/issues/748)) #### 📚 Documentation - Fix punctuation [@&#8203;pm-dev563](https://github.com/pm-dev563) ([#&#8203;747](https://github.com/astral-sh/setup-uv/issues/747)) #### ⬆️ Dependency updates - Bump typesafegithub/github-actions-typing from 2.2.1 to 2.2.2 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;753](https://github.com/astral-sh/setup-uv/issues/753)) - Bump peter-evans/create-pull-request from 8.0.0 to 8.1.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;751](https://github.com/astral-sh/setup-uv/issues/751)) - Bump actions/checkout from 6.0.1 to 6.0.2 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;740](https://github.com/astral-sh/setup-uv/issues/740)) - Bump release-drafter/release-drafter from 6.1.0 to 6.2.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;743](https://github.com/astral-sh/setup-uv/issues/743)) - Bump eifinger/actionlint-action from 1.9.3 to 1.10.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;731](https://github.com/astral-sh/setup-uv/issues/731)) - Bump actions/setup-node from 6.1.0 to 6.2.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;738](https://github.com/astral-sh/setup-uv/issues/738)) ### [`v7.2.1`](https://github.com/astral-sh/setup-uv/releases/tag/v7.2.1): 🌈 update known checksums up to 0.9.28 [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.2.0...v7.2.1) #### Changes #### 🧰 Maintenance - chore: update known checksums for 0.9.28 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;744](https://github.com/astral-sh/setup-uv/issues/744)) - chore: update known checksums for 0.9.27 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;742](https://github.com/astral-sh/setup-uv/issues/742)) - chore: update known checksums for 0.9.26 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;734](https://github.com/astral-sh/setup-uv/issues/734)) - chore: update known checksums for 0.9.25 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;733](https://github.com/astral-sh/setup-uv/issues/733)) - chore: update known checksums for 0.9.24 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;730](https://github.com/astral-sh/setup-uv/issues/730)) #### 📚 Documentation - Clarify impact of using actions/setup-python [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;732](https://github.com/astral-sh/setup-uv/issues/732)) #### ⬆️ Dependency updates - Bump zizmorcore/zizmor-action from 0.3.0 to 0.4.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;741](https://github.com/astral-sh/setup-uv/issues/741)) ### [`v7.2.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.2.0): 🌈 add outputs python-version and python-cache-hit [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.6...v7.2.0) #### Changes Among some minor typo fixes and quality of life features for developers of actions the main feature of this release are new outputs: - **python-version:** The Python version that was set (same content as existing `UV_PYTHON`) - **python-cache-hit:** A boolean value to indicate the Python cache entry was found While implementing this it became clear, that it is easier to handle the Python binaries in a separate cache entry. The added benefit for users is that the "normal" cache containing the dependencies can be used in all runs no matter if these cache the Python binaries or not. > \[!NOTE]\ > This release will invalidate caches that contain the Python binaries. This happens a single time. #### 🐛 Bug fixes - chore: remove stray space from UV\_PYTHON\_INSTALL\_DIR message [@&#8203;akx](https://github.com/akx) ([#&#8203;720](https://github.com/astral-sh/setup-uv/issues/720)) #### 🚀 Enhancements - add outputs python-version and python-cache-hit [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;728](https://github.com/astral-sh/setup-uv/issues/728)) - Add action typings with validation [@&#8203;krzema12](https://github.com/krzema12) ([#&#8203;721](https://github.com/astral-sh/setup-uv/issues/721)) #### 🧰 Maintenance - fix: use uv\_build backend for old-python-constraint-project [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;729](https://github.com/astral-sh/setup-uv/issues/729)) - chore: update known checksums for 0.9.22 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;727](https://github.com/astral-sh/setup-uv/issues/727)) - chore: update known checksums for 0.9.21 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;726](https://github.com/astral-sh/setup-uv/issues/726)) - chore: update known checksums for 0.9.20 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;725](https://github.com/astral-sh/setup-uv/issues/725)) - chore: update known checksums for 0.9.18 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;718](https://github.com/astral-sh/setup-uv/issues/718)) #### ⬆️ Dependency updates - Bump peter-evans/create-pull-request from 7.0.9 to 8.0.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;719](https://github.com/astral-sh/setup-uv/issues/719)) - Bump github/codeql-action from 4.31.6 to 4.31.9 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;723](https://github.com/astral-sh/setup-uv/issues/723)) ### [`v7.1.6`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.6): 🌈 add OS version to cache key to prevent binary incompatibility [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.5...v7.1.6) #### Changes This release will invalidate your cache existing keys! The os version e.g. `ubuntu-22.04` is now part of the cache key. This prevents failing builds when a cache got populated with wheels built with different tools (e.g. glibc) than are present on the runner where the cache got restored. #### 🐛 Bug fixes - feat: add OS version to cache key to prevent binary incompatibility [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;716](https://github.com/astral-sh/setup-uv/issues/716)) #### 🧰 Maintenance - chore: update known checksums for 0.9.17 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;714](https://github.com/astral-sh/setup-uv/issues/714)) #### ⬆️ Dependency updates - Bump actions/checkout from 5.0.0 to 6.0.1 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;712](https://github.com/astral-sh/setup-uv/issues/712)) - Bump actions/setup-node from 6.0.0 to 6.1.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;715](https://github.com/astral-sh/setup-uv/issues/715)) ### [`v7.1.5`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.5): 🌈 allow setting `cache-local-path` without `enable-cache: true` [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.4...v7.1.5) #### Changes [#&#8203;612](https://github.com/astral-sh/setup-uv/pull/612) fixed a faulty behavior where this action set `UV_CACHE_DIR` even though `enable-cache` was `false`. It also fixed the cases were the cache dir is already configured in a settings file like `pyproject.toml` or `UV_CACHE_DIR` was already set. Here the action shouldn't overwrite or set `UV_CACHE_DIR`. These fixes introduced an unwanted behavior: You can still set `cache-local-path` but this action didn't do anything. This release fixes that. You can now use `cache-local-path` to automatically set `UV_CACHE_DIR` even when `enable-cache` is `false` (or gets set to false by default e.g. on self-hosted runners) ```yaml - name: This is now possible uses: astral-sh/setup-uv@v7 with: enable-cache: false cache-local-path: "/path/to/cache" ``` #### 🐛 Bug fixes - allow cache-local-path w/o enable-cache [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;707](https://github.com/astral-sh/setup-uv/issues/707)) #### 🧰 Maintenance - set biome files.maxSize to 2MiB [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;708](https://github.com/astral-sh/setup-uv/issues/708)) - chore: update known checksums for 0.9.16 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;706](https://github.com/astral-sh/setup-uv/issues/706)) - chore: update known checksums for 0.9.15 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;704](https://github.com/astral-sh/setup-uv/issues/704)) - chore: use `npm ci --ignore-scripts` everywhere [@&#8203;woodruffw](https://github.com/woodruffw) ([#&#8203;699](https://github.com/astral-sh/setup-uv/issues/699)) - chore: update known checksums for 0.9.14 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;700](https://github.com/astral-sh/setup-uv/issues/700)) - chore: update known checksums for 0.9.13 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;694](https://github.com/astral-sh/setup-uv/issues/694)) - chore: update known checksums for 0.9.12 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;693](https://github.com/astral-sh/setup-uv/issues/693)) - chore: update known checksums for 0.9.11 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;688](https://github.com/astral-sh/setup-uv/issues/688)) #### ⬆️ Dependency updates - Bump peter-evans/create-pull-request from 7.0.8 to 7.0.9 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;695](https://github.com/astral-sh/setup-uv/issues/695)) - bump dependencies [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;709](https://github.com/astral-sh/setup-uv/issues/709)) - Bump github/codeql-action from 4.30.9 to 4.31.6 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;698](https://github.com/astral-sh/setup-uv/issues/698)) - Bump zizmorcore/zizmor-action from 0.2.0 to 0.3.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;696](https://github.com/astral-sh/setup-uv/issues/696)) - Bump eifinger/actionlint-action from 1.9.2 to 1.9.3 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;690](https://github.com/astral-sh/setup-uv/issues/690)) ### [`v7.1.4`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.4): 🌈 Fix libuv closing bug on Windows [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.3...v7.1.4) #### Changes This release fixes the bug `Assertion failed: !(handle->flags & UV_HANDLE_CLOSING)` on Windows runners #### 🐛 Bug fixes - Wait 50ms before exit to fix libuv bug [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;689](https://github.com/astral-sh/setup-uv/issues/689)) #### 🧰 Maintenance - chore: update known checksums for 0.9.10 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;681](https://github.com/astral-sh/setup-uv/issues/681)) - chore: update known checksums for 0.9.9 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;679](https://github.com/astral-sh/setup-uv/issues/679)) ### [`v7.1.3`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.3): 🌈 Support act [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.2...v7.1.3) #### Changes This bug fix release adds support for <https://github.com/nektos/act> It was previously broken because of a too new `undici` version and TS transpilation target. Compatibility with act is now automatically tested. #### 🐛 Bug fixes - use old undici and ES2022 target for act support [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;678](https://github.com/astral-sh/setup-uv/issues/678)) #### 🧰 Maintenance - chore: update known checksums for 0.9.8 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;677](https://github.com/astral-sh/setup-uv/issues/677)) - chore: update known checksums for 0.9.7 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;671](https://github.com/astral-sh/setup-uv/issues/671)) - chore: update known checksums for 0.9.6 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;670](https://github.com/astral-sh/setup-uv/issues/670)) #### 📚 Documentation - Correct description of `cache-dependency-glob` [@&#8203;allanlewis](https://github.com/allanlewis) ([#&#8203;676](https://github.com/astral-sh/setup-uv/issues/676)) ### [`v7.1.2`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.2): 🌈 Speed up extraction on Windows [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.1...v7.1.2) #### Changes [@&#8203;lazka](https://github.com/lazka) fixed a bug that caused extracting uv to take up to 30s. Thank you! #### 🐛 Bug fixes - Use tar for extracting the uv zip file on Windows too [@&#8203;lazka](https://github.com/lazka) ([#&#8203;660](https://github.com/astral-sh/setup-uv/issues/660)) #### 🧰 Maintenance - chore: update known checksums for 0.9.5 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;663](https://github.com/astral-sh/setup-uv/issues/663)) #### ⬆️ Dependency updates - Bump dependencies [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;664](https://github.com/astral-sh/setup-uv/issues/664)) - Bump github/codeql-action from 4.30.8 to 4.30.9 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;652](https://github.com/astral-sh/setup-uv/issues/652)) ### [`v7.1.1`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.1): 🌈 Fix empty workdir detection and lowest resolution strategy [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7.1.0...v7.1.1) #### Changes This release fixes a bug where the `working-directory` input was not used to detect an empty work dir. It also fixes the `lowest` resolution strategy resolving to latest when only a lower bound was specified. Special thanks to [@&#8203;tpgillam](https://github.com/tpgillam) for the first contribution! #### 🐛 Bug fixes - Fix "lowest" resolution strategy with lower-bound only [@&#8203;tpgillam](https://github.com/tpgillam) ([#&#8203;649](https://github.com/astral-sh/setup-uv/issues/649)) - Use working-directory to detect empty workdir [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;645](https://github.com/astral-sh/setup-uv/issues/645)) #### 🧰 Maintenance - chore: update known checksums for 0.9.4 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;651](https://github.com/astral-sh/setup-uv/issues/651)) - chore: update known checksums for 0.9.3 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;644](https://github.com/astral-sh/setup-uv/issues/644)) #### 📚 Documentation - Change version in docs to v7 [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;647](https://github.com/astral-sh/setup-uv/issues/647)) #### ⬆️ Dependency updates - Bump github/codeql-action from 4.30.7 to 4.30.8 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;639](https://github.com/astral-sh/setup-uv/issues/639)) - Bump actions/setup-node from 5.0.0 to 6.0.0 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;641](https://github.com/astral-sh/setup-uv/issues/641)) - Bump eifinger/actionlint-action from 1.9.1 to 1.9.2 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;634](https://github.com/astral-sh/setup-uv/issues/634)) - Update lockfile with latest npm [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;636](https://github.com/astral-sh/setup-uv/issues/636)) ### [`v7.1.0`](https://github.com/astral-sh/setup-uv/releases/tag/v7.1.0): 🌈 Support all the use cases [Compare Source](https://github.com/astral-sh/setup-uv/compare/v7...v7.1.0) #### Changes **Support all the use cases!!!** ... well, that we know of. This release adds support for some use cases that most users don't encounter but are useful for e.g. people running Gitea. The input `resolution-strategy` lets you use the lowest possible version of uv from a version range. Useful if you want to test your tool with different versions of uv. If you use `activate-environment` the path to the activated venv is now also exposed under the output `venv`. Downloaded python installations can now also be uploaded to the GitHub Actions cache backend. Useful if you are running in `act` and have configured your own backend and don't want to download python again, and again over a slow internet connection. Finally the path to installed python interpreters is now added to the `PATH` on Windows. #### 🚀 Enhancements - Add resolution-strategy input to support oldest compatible version selection @&#8203;[copilot-swe-agent\[bot\]](https://github.com/apps/copilot-swe-agent) ([#&#8203;631](https://github.com/astral-sh/setup-uv/issues/631)) - Add value of UV\_PYTHON\_INSTALL\_DIR to path [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;628](https://github.com/astral-sh/setup-uv/issues/628)) - Set output venv when activate-environment is used [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;627](https://github.com/astral-sh/setup-uv/issues/627)) - Cache python installs [@&#8203;merlinz01](https://github.com/merlinz01) ([#&#8203;621](https://github.com/astral-sh/setup-uv/issues/621)) #### 🧰 Maintenance - Add copilot-instructions.md [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;630](https://github.com/astral-sh/setup-uv/issues/630)) - chore: update known checksums for 0.9.2 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;626](https://github.com/astral-sh/setup-uv/issues/626)) - chore: update known checksums for 0.9.1 @&#8203;[github-actions\[bot\]](https://github.com/apps/github-actions) ([#&#8203;625](https://github.com/astral-sh/setup-uv/issues/625)) - Fall back to PR for updating known versions [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;623](https://github.com/astral-sh/setup-uv/issues/623)) #### 📚 Documentation - Split up documentation [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;632](https://github.com/astral-sh/setup-uv/issues/632)) #### ⬆️ Dependency updates - Bump deps [@&#8203;eifinger](https://github.com/eifinger) ([#&#8203;633](https://github.com/astral-sh/setup-uv/issues/633)) - Bump github/codeql-action from 3.30.6 to 4.30.7 @&#8203;[dependabot\[bot\]](https://github.com/apps/dependabot) ([#&#8203;614](https://github.com/astral-sh/setup-uv/issues/614)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==-->
renovate-bot requested review from luke 2026-04-16 13:03:05 +00:00
renovate-bot added 1 commit 2026-04-16 18:03:24 +00:00
chore(deps): update astral-sh/setup-uv action to v8
All checks were successful
Conventional Commit / Validate PR Title (pull_request) Successful in 3s
CI / ci (pull_request) Successful in 30s
7d1895b1e5
renovate-bot force-pushed renovate/astral-sh-setup-uv-8.x from 040c83604d to 7d1895b1e5 2026-04-16 18:03:24 +00:00 Compare
luke merged commit b7eb8aacfc into main 2026-04-16 19:38:46 +00:00
luke deleted branch renovate/astral-sh-setup-uv-8.x 2026-04-16 19:38:46 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: repos/pypilot#433