Skip to content

⬆ Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 - #344

Merged
Chisanan232 merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.2.0
Sep 26, 2026
Merged

Chisanan232 merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-10.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 10.1.0 to 10.2.0.

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.2.0 🌈 Disable automatic cache saves for merge queues

Changes

This release contains the known-checksum of the most recent uv releases and also disabled the uploading(saving) of the cache when in a merge queue since theses caches would almost never be used.

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.1.0 to 10.2.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@bec219d...c18668a)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: 🔍 enhancement, 🤖 github actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Chisanan232 as a code owner September 24, 2026 08:56
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026

@Chisanan232 Chisanan232 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving: a pure SHA-pin bump of astral-sh/setup-uv, exercised live by 6 of the 9 workflows it touches.

Nothing rode along. Changed content lines = 28, of which setup-uv pin lines = 28 (100%). Repo-wide grep on this head: all 14 references sit at c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0, zero left at the old bec219d24cd3e171d82865faccec33120bb574f4.

Pin verified against the upstream tag. refs/tags/v10.2.0 is a lightweight tag (type: commit) resolving exactly to c18668ad3cf93ea998bef934396af7bb5c839dc7; v10.1.0 resolves to the old bec219d24.... No annotated-tag dereference ambiguity.

No workflow-syntax regression. actionlint baselined on main rather than run only on the PR: main rc=1 / 64 diagnostics, PR head rc=1 / 64 diagnostics, outputs byte-identical -> 0 introduced diagnostics. (The 64 are pre-existing and out of scope here.)

The new commit really executed. Two step names in the logs literally embed the new SHA (Run astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7), and the Dependency floors co-resolve log shows Download action repository ... (SHA:c18668ad...), then Downloading uv from .../0.12.18/..., Successfully installed uv version 0.12.18, then the job s real assertion All frameworks co-resolve with the current dependency floors. So green here means uv genuinely installed and resolved at the new pin, not that nothing referenced the action.

Exercised at the new pin: ci.yaml (unit + integration test matrices, pip-audit, LangChain contract test), documentation.yaml, framework-resolution-check.yml, native-core-build.yml, quickstart-tabs-check.yml, type-check.yml. Not exercised by a PR event, disclosed rather than glossed: release-python.yml and docs-backfill.yaml (both workflow_dispatch-only, so no run record exists on this head) and benchmarks.yml (label-gated). Their pins are byte-identical to the six that were exercised.

CI on head f99aaf7d: 36 check runs, {"skipped":14,"success":22} -- 0 failure, 0 cancelled, 0 pending, 0 non-green. Every one of the 14 skips is traced to an explicit source-level condition, not inferred from job shape (a billing-refused job is shape-identical to a skipped one):

  • unit-test_codecov_finish, integration-test_codecov_finish, e2e-test_codecov_finish, contract-test_codecov_finish, all-test_codecov_finish, sonarcloud_finish (6) -- rw_run_all_test_and_record.yaml gates each on github.actor != 'dependabot[bot]' && !contains(github.event.pull_request.labels.*.name, 'dependencies'). This PR is both, so these are skipped by design for bot PRs.
  • run_e2e-test, e2e-test_codecov, all_test_include_e2e_test_codecov (3) -- gated on inputs.run_e2e == true; ci.yaml does not pass run_e2e, and the input declares default: false. The complementary all_test_not_e2e_test_codecov ran green, so coverage aggregation was not silently lost.
  • Run performance benchmarks x2 (2) -- benchmarks.yml:29 if: contains(github.event.pull_request.labels.*.name, 'benchmark'). Both workflow runs report conclusion: skipped at run level.
  • Deploy latest documentation -- if: github.event_name == 'push'. Deploy release documentation (channel) -- if: github.event_name == 'workflow_run' && ...event == 'repository_dispatch'. Manual republish documentation (operator) -- if: github.event_name == 'workflow_dispatch'. The PR-path sibling Build documentation (PR, no deploy) (if: github.event_name == 'pull_request') ran green.

No billing-refused steps on this head, so no local-equivalent evidence was required. Merging as a true merge commit per this repo s merge-commit-only setting.

@Chisanan232
Chisanan232 merged commit d92ce86 into main Sep 26, 2026
36 checks passed
@Chisanan232
Chisanan232 deleted the dependabot/github_actions/astral-sh/setup-uv-10.2.0 branch September 26, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant