Skip to content

Update uv to 0.11.30 - #480

Merged
twitchyliquid64 merged 1 commit into
mainfrom
update-uv-0.11.30
Jul 21, 2026
Merged

Update uv to 0.11.30#480
twitchyliquid64 merged 1 commit into
mainfrom
update-uv-0.11.30

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update uv 0.11.190.11.30

Source: github:astral-sh/uv:operator-pinned
Release: https://github.com/astral-sh/uv/releases/tag/0.11.30
Changelog: astral-sh/uv@0.11.19...0.11.30
Released: 7 hours ago (2026-07-20)

Warning

Pkgscan: 1 new signal introduced by this update (risk score 2.0).
Diff against the prior version surfaced patterns that weren't present before. Review carefully before merging — supply-chain attacks land via version-bump injection.

Severity File Line Capability (MBC) Pattern
MEDIUM uv (upstream release) 0 metadata/recent-bump upstream release <12h ago

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ uv 0.11.19 0.11.30
~ uv-upstream 0.11.19 0.11.30

Changes

Old New
Version 0.11.19 0.11.30
SHA256 316a5fb9fca07906... ff895fff1c218fca...
Size 5.4 MB 7.4 MB
Source gs://minimal-staging-archives/uv-0.11.19.tar.gz gs://minimal-staging-archives/uv-0.11.30.tar.gz
  • License: MIT OR Apache-2.0 (source: GitHub + tarball)

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

@twitchyliquid64
twitchyliquid64 disabled auto-merge July 21, 2026 04:33
@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Jul 21, 2026
Merged via the queue into main with commit 6b1628a Jul 21, 2026
9 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-uv-0.11.30 branch July 21, 2026 04:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant