Skip to content

build(deps): bump uv from 0.12.3 to 0.12.5 in the python group - #52

Merged
gabrielspadon merged 3 commits into
mainfrom
dependabot/pip/python-6a0e00ede4
Sep 5, 2026
Merged

gabrielspadon merged 3 commits into
mainfrom
dependabot/pip/python-6a0e00ede4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the python group with 1 update: uv.

Updates uv from 0.12.3 to 0.12.5

Release notes

Sourced from uv's releases.

0.12.5

Release Notes

Released on 2026-08-14.

Python

  • Add CPython 3.10.21, 3.11.16, and 3.12.14 (#21138)
  • Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#21134)

Enhancements

  • Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#21130)

Preview features

  • Allow --index and --default-index to select configured package indexes by name with the index-by-name preview feature (#17455)
  • Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#21131)
  • Fall back to logical file sizes when using cache-physical-space on filesystems that do not support physical-space accounting (#21133)

Bug fixes

  • Resolve relative package index paths in PEP 723 scripts against the script directory (#21097)

Install uv 0.12.5

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.ps1 | iex"

Download uv 0.12.5

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.5

Released on 2026-08-14.

Python

  • Add CPython 3.10.21, 3.11.16, and 3.12.14 (#21138)
  • Prefer newer versions and standard variants when selecting between equally prioritized Python interpreters (#21134)

Enhancements

  • Simplify errors and hints for invalid editable requirements, and redact credentials in requirement URLs (#21130)

Preview features

  • Allow --index and --default-index to select configured package indexes by name with the index-by-name preview feature (#17455)
  • Include distribution artifact URLs and hashes in CycloneDX SBOM exports by default (#21131)
  • Fall back to logical file sizes when using cache-physical-space on filesystems that do not support physical-space accounting (#21133)

Bug fixes

  • Resolve relative package index paths in PEP 723 scripts against the script directory (#21097)

0.12.4

Released on 2026-08-13.

Enhancements

  • Prefer post-quantum key exchange and enable opt-in TLS diagnostics (#21054)
  • Accept whitespace before versions in noncompliant wildcard comparisons such as Requires-Python: >= 3.5.* (#21012)
  • Report a specific error when a PEP 723 closing tag contains trailing whitespace or other content (#20944)
  • Omit source-span carets from diagnostics for empty PEP 508 requirements (#21094)

Preview features

  • Add uv check --no-install-project and respect UV_NO_INSTALL_PROJECT to install dependencies without building or installing the project (#21085)
  • Make the ty subprocess invoked by uv check honor uv's color and progress settings, including quiet mode (#21086)

Performance

  • Speed up resolutions with long runs of unavailable package versions by coalescing gaps in the resolver's version ranges (#20804)
  • Speed up Simple API parsing by deserializing PyPI and Pyx file metadata directly (#21041)

Bug fixes

  • Use windowed pythonw.exe launchers for virtual environments created from managed Python minor-version links (#19235)
  • Allow uv lock to proceed when .venv is an unusable project environment (#21068)
  • Respect fork-strategy when ordering forks created from environments or existing lockfile resolution-markers (#21000)
  • Preserve consecutive wildcard Python minor-version exclusions such as !=3.11.*, !=3.12.* in uv.lock (#21045)

... (truncated)

Commits
  • 210d1f6 Bump version to 0.12.5 (#21140)
  • 802a916 Sync latest Python releases: 3.10.21, 3.11.16, 3.12.14 (#21138)
  • a6904bb Order equal-priority Python installations by key (#21134)
  • 728a70d Improve automated fixes for related bug manifestations (#21102)
  • b82b038 Include hashes in cyclonedx exports (#21131)
  • 8011778 Simplify editable requirement errors and hints (#21130)
  • dca33f5 Fall back to logical cache accounting on unsupported filesystems (#21133)
  • 3a76e49 Get rid of Lock::with_manifest, make Lock::from_resolution take the manif...
  • 7e6caa4 Support referencing indexes by name via --index and --default-index (#17455)
  • 298dda4 Fix relative indexes in PEP 723 scripts (#21097)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python group with 1 update: [uv](https://github.com/astral-sh/uv).


Updates `uv` from 0.12.3 to 0.12.5
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.3...0.12.5)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 23, 2026
@dependabot
dependabot Bot requested a review from gabrielspadon as a code owner August 23, 2026 20:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 23, 2026
@gabrielspadon
gabrielspadon enabled auto-merge (squash) September 1, 2026 12:04
gabrielspadon added a commit that referenced this pull request Sep 5, 2026
## What broke

`RefreshEngine.run` compares the bound discovery policy epoch against
its own wall clock (`citeforge/refresh/engine.py:116`), and derives the
inventory task epoch from that same clock (`engine.py:142`).
`Ledger.commit_initial_round` then requires the inventory authority to
agree with the bound discovery policy
(`citeforge/refresh/ledger.py:4463`).

Four tests in `tests/test_refresh_discovery.py` wrote the literal month
they were authored in (`"2026-08"`), so they agreed with the engine for
exactly one calendar month. When the clock rolled to `2026-09` the
engine started deriving `2026-09` while the bound policy still said
`2026-08`, and all four began raising:

```
ValueError: inventory authority conflicts with bound discovery policy
```

That is a test-only defect. No production code path pins a month, and
the monthly workflow derives its own with `date +%Y-%m`.

## Blast radius

Every `Test (py3.10 … py3.14)` leg failed identically, which failed the
`Required CI` aggregate and left PR #52 (a Dependabot `uv` bump touching
only `requirements-build.in` and `.lock`) `BLOCKED` on a failure it did
not cause. Any PR opened after 2026-09-01 would have been blocked the
same way.

## Fix

Both engine-driving test modules derive the epoch exactly as the engine
does. The staleness test builds its rejected month as an explicit offset
from today rather than naming one.

Two guard tests were also passing on the right status for the wrong
reason.
`test_generation_start_binds_discovery_preflight_before_inventory_send`
was tripping the epoch mismatch instead of the missing `s2` credential
it exists to prove. Both it and the staleness test now pin the exact
`detail` string their guard must return, so a guard that starts firing
for a different cause fails instead of passing silently.

`test_no_refresh_test_pins_a_literal_freshness_epoch` fails on any
double-quoted `YYYY-MM` literal in a `test_refresh_*.py` module that
drives `RefreshEngine`, so this cannot be reintroduced. Single-quoted
months inside the SQL of `test_refresh_corpus.py` write a deliberately
mismatching epoch to trip a drift guard and are correctly left alone.

## Verification

Run locally on Python 3.14.7 against `origin/main`.

- Reproduced first: the same 4 failures, same `ValueError`, before any
edit.
- `pytest -m 'not live'` (CI's exact invocation): **2077 passed, 2
skipped, 7 deselected**.
- `ruff check citeforge/ tests/ main.py`: clean.
- `mypy citeforge/ main.py`: clean, 56 source files.
- The four previously-detonating tests re-run under a simulated
`2027-02` clock: all pass, confirming the time coupling is gone rather
than merely re-pinned to the current month.
- The new guard was proved to fail by reintroducing a literal into
`test_refresh_discovery.py`, then restored.

Merging this unblocks #52.
@gabrielspadon
gabrielspadon merged commit 9d69ae4 into main Sep 5, 2026
11 checks passed
@gabrielspadon
gabrielspadon deleted the dependabot/pip/python-6a0e00ede4 branch September 5, 2026 11:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant