Skip to content

chore(deps): bump astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.11.14-python3.11-trixie-slim in /jans-cedarling/flask-sidecar#14080

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.11.14-python3.11-trixie-slim
Closed

chore(deps): bump astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.11.14-python3.11-trixie-slim in /jans-cedarling/flask-sidecar#14080
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.11.14-python3.11-trixie-slim

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 13, 2026

Bumps astral-sh/uv from 0.11.7-python3.11-trixie-slim to 0.11.14-python3.11-trixie-slim.

Release notes

Sourced from astral-sh/uv's releases.

0.11.14

Release Notes

Released on 2026-05-12.

Enhancements

  • Add Astral mirror URL override (#19206)
  • Ignore top_level.txt entries in uninstall that are not valid Python identifiers (#19340)

Bug fixes

  • Avoid applying .env files in parent process (#19343)
  • Filter ANSI codes in logging output (#19311)
  • Fix uv tree showing extra-conditional deps for packages required without extras (#19332)
  • Respect build options (e.g., --no-build) during lock validation (#19366)

Install uv 0.11.14

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.14/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.14/uv-installer.ps1 | iex"

Download uv 0.11.14

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum

... (truncated)

Changelog

Sourced from astral-sh/uv's changelog.

Changelog

0.11.14

Released on 2026-05-12.

Enhancements

  • Add Astral mirror URL override (#19206)
  • Ignore top_level.txt entries in uninstall that are not valid Python identifiers (#19340)

Bug fixes

  • Avoid applying .env files in parent process (#19343)
  • Filter ANSI codes in logging output (#19311)
  • Fix uv tree showing extra-conditional deps for packages required without extras (#19332)
  • Respect build options (e.g., --no-build) during lock validation (#19366)

0.11.13

Released on 2026-05-10.

Bug fixes

  • Include data files in editable builds (#19312)
  • Respect --require-hashes when installing from pylock.toml files (#19334)

Python

Python

  • Add CPython 3.14.5

0.11.12

Released on 2026-05-08.

Python

  • Add CPython 3.15.0b1

Enhancements

  • Add --no-editable support to uv pip install (#19306)
  • Require git refs in URLs to be percent-encoded (#19320)

Bug fixes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.11.7-python3.11-trixie-slim to 0.11.14-python3.11-trixie-slim.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.7...0.11.14)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.11.14-python3.11-trixie-slim
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@mo-auto
Copy link
Copy Markdown
Member

mo-auto commented May 13, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 18, 2026

Superseded by #14110.

@dependabot dependabot Bot closed this May 18, 2026
@dependabot dependabot Bot deleted the dependabot/docker/jans-cedarling/flask-sidecar/astral-sh/uv-0.11.14-python3.11-trixie-slim branch May 18, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant