Repository navigation
⬆ Bump astral-sh/setup-uv from 10.1.0 to 10.2.0 - #344
Conversation
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.1.0 to 10.2.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@bec219d...c18668a) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Chisanan232
left a comment
There was a problem hiding this comment.
Approving: a pure SHA-pin bump of astral-sh/setup-uv, exercised live by 6 of the 9 workflows it touches.
Nothing rode along. Changed content lines = 28, of which setup-uv pin lines = 28 (100%). Repo-wide grep on this head: all 14 references sit at c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0, zero left at the old bec219d24cd3e171d82865faccec33120bb574f4.
Pin verified against the upstream tag. refs/tags/v10.2.0 is a lightweight tag (type: commit) resolving exactly to c18668ad3cf93ea998bef934396af7bb5c839dc7; v10.1.0 resolves to the old bec219d24.... No annotated-tag dereference ambiguity.
No workflow-syntax regression. actionlint baselined on main rather than run only on the PR: main rc=1 / 64 diagnostics, PR head rc=1 / 64 diagnostics, outputs byte-identical -> 0 introduced diagnostics. (The 64 are pre-existing and out of scope here.)
The new commit really executed. Two step names in the logs literally embed the new SHA (Run astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7), and the Dependency floors co-resolve log shows Download action repository ... (SHA:c18668ad...), then Downloading uv from .../0.12.18/..., Successfully installed uv version 0.12.18, then the job s real assertion All frameworks co-resolve with the current dependency floors. So green here means uv genuinely installed and resolved at the new pin, not that nothing referenced the action.
Exercised at the new pin: ci.yaml (unit + integration test matrices, pip-audit, LangChain contract test), documentation.yaml, framework-resolution-check.yml, native-core-build.yml, quickstart-tabs-check.yml, type-check.yml. Not exercised by a PR event, disclosed rather than glossed: release-python.yml and docs-backfill.yaml (both workflow_dispatch-only, so no run record exists on this head) and benchmarks.yml (label-gated). Their pins are byte-identical to the six that were exercised.
CI on head f99aaf7d: 36 check runs, {"skipped":14,"success":22} -- 0 failure, 0 cancelled, 0 pending, 0 non-green. Every one of the 14 skips is traced to an explicit source-level condition, not inferred from job shape (a billing-refused job is shape-identical to a skipped one):
unit-test_codecov_finish,integration-test_codecov_finish,e2e-test_codecov_finish,contract-test_codecov_finish,all-test_codecov_finish,sonarcloud_finish(6) --rw_run_all_test_and_record.yamlgates each ongithub.actor != 'dependabot[bot]' && !contains(github.event.pull_request.labels.*.name, 'dependencies'). This PR is both, so these are skipped by design for bot PRs.run_e2e-test,e2e-test_codecov,all_test_include_e2e_test_codecov(3) -- gated oninputs.run_e2e == true;ci.yamldoes not passrun_e2e, and the input declaresdefault: false. The complementaryall_test_not_e2e_test_codecovran green, so coverage aggregation was not silently lost.Run performance benchmarksx2 (2) --benchmarks.yml:29if: contains(github.event.pull_request.labels.*.name, 'benchmark'). Both workflow runs reportconclusion: skippedat run level.Deploy latest documentation--if: github.event_name == 'push'.Deploy release documentation (channel)--if: github.event_name == 'workflow_run' && ...event == 'repository_dispatch'.Manual republish documentation (operator)--if: github.event_name == 'workflow_dispatch'. The PR-path siblingBuild documentation (PR, no deploy)(if: github.event_name == 'pull_request') ran green.
No billing-refused steps on this head, so no local-equivalent evidence was required. Merging as a true merge commit per this repo s merge-commit-only setting.
Bumps astral-sh/setup-uv from 10.1.0 to 10.2.0.
Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
c18668achore(deps): roll up Dependabot updates (#1059)ffe1476chore: update known checksums for 0.12.17 (#1058)f5548c5chore: update known checksums for 0.12.16 (#1057)a761a4eDisable automatic cache saves for merge queues (#1056)3377a30chore: update known checksums for 0.12.15 (#1054)dfb5f38chore: update known checksums for 0.12.14 (#1053)45c121fchore: update known checksums for 0.12.13 (#1045)8073452docs: update version references to v10.1.0 (#1044)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)