0.12.9
Release Notes
Released on 2026-09-01.
Python
Enhancements
- Add
--no-lockedand--no-frozento disable lock modes enabled byUV_LOCKEDandUV_FROZENfor a single invocation (#21408) - Report the exact command-line lock-mode flag in warnings and errors (#21402)
Performance
- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#21372)
Bug fixes
- Update
async_http_range_readerto 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#21401) - Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#21382)
- Redact secrets in signed URLs from retry diagnostics, including nested request errors (#21381)
- Give
--locked,--frozen,--check, and--check-existsprecedence over conflictingUV_LOCKEDandUV_FROZENvalues (#21396) - Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#21400)
Install uv 0.12.9
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
Download uv 0.12.9
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify --bundle
评论
?
参与讨论