Skip to content

chore(deps): update astral-sh/setup-uv action to v8#346

Open
dreadnode-renovate-bot[bot] wants to merge 1 commit intomainfrom
renovate/astral-sh-setup-uv-8.x
Open

chore(deps): update astral-sh/setup-uv action to v8#346
dreadnode-renovate-bot[bot] wants to merge 1 commit intomainfrom
renovate/astral-sh-setup-uv-8.x

Conversation

@dreadnode-renovate-bot
Copy link
Copy Markdown
Contributor

@dreadnode-renovate-bot dreadnode-renovate-bot bot commented Apr 1, 2026

This PR contains the following updates:

| Package | Type | Update | Change |
|

Generated Summary:

  • Updated setup-uv action version from v7.6.0 to v8.0.0 across all workflows.
  • Changes made in the following workflow files:
    • .github/workflows/pre-commit.yaml
    • .github/workflows/publish.yaml
    • .github/workflows/test.yaml
  • Potential impact: Upgrading to version 8.0.0 may introduce new features or breaking changes; thorough testing is advised.

This summary was generated with ❤️ by rigging

| astral-sh/setup-uv | action | major | v7.6.0v8.0.0 |


Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v8.0.0: 🌈 Immutable releases and secure tags

Compare Source

This is the first immutable release of setup-uv 🥳

All future releases are also immutable, if you want to know more about what this means checkout the docs.

This release also has two breaking changes

New format for manifest-file

The previously deprecated way of defining a custom version manifest to control which uv versions are available and where to download them from got removed. The functionality is still there but you have to use the new format.

No more major and minor tags

To increase security even more we will stop publishing minor tags. You won't be able to use @v8 or @v8.0 any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to tj-actions.

[!TIP]
Use the immutable tag as a version astral-sh/setup-uv@v8.0.0
Or even better the githash astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57

🚨 Breaking changes
🧰 Maintenance

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

| datasource  | package            | from   | to     |
| ----------- | ------------------ | ------ | ------ |
| github-tags | astral-sh/setup-uv | v7.6.0 | v8.0.0 |
@dreadnode-renovate-bot dreadnode-renovate-bot bot added area/github Changes made to GitHub Actions type/digest Dependency digest updates labels Apr 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/github Changes made to GitHub Actions type/digest Dependency digest updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants