chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.0 in the github-actions group - #1824
Conversation
Bumps the github-actions group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv). Updates `astral-sh/setup-uv` from 9.0.0 to 10.0.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@c771a70...ae62891) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM — straightforward Dependabot version bump of astral-sh/setup-uv from v9.0.0 to v10.0.0, pinned by commit SHA with a matching version comment across both workflow files.
Extended reasoning...
Overview
This PR is an automated Dependabot bump of the astral-sh/setup-uv GitHub Action from v9.0.0 to v10.0.0, applied consistently across all 5 usages in .github/workflows/ci.yml and .github/workflows/release.yml. Each usage is pinned to the new release's commit SHA (ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d) with a matching # v10.0.0 comment, and the surrounding with: blocks (uv version, python-version, enable-cache) are untouched.
Security risks
None introduced. The action remains pinned by immutable commit SHA rather than a mutable tag, which is the secure pattern already in use. The v10.0.0 release notes actually tighten security further (disabling default caching for sensitive events like pull_request_target/workflow_run/release), which is a net positive for this repo's supply-chain posture.
Level of scrutiny
Low. This is a mechanical, single-dependency version bump with no logic changes, well within the pattern Dependabot handles routinely for this repo (consistent with the other recent dependency-bump commit in the log, f54f0a1).
Other factors
No prior comments or reviews on this PR to reconcile with. The change is self-verifying in that CI will run against the new action version before merge, providing an additional correctness check beyond static review.
wochinge
left a comment
There was a problem hiding this comment.
Validated the SHA-pinned v10.0.0 update, its cache-behavior change against the explicit workflow configuration, and the fully passing retry.
Bumps the github-actions group with 1 update: astral-sh/setup-uv.
Updates
astral-sh/setup-uvfrom 9.0.0 to 10.0.0Release notes
Sourced from astral-sh/setup-uv's releases.
... (truncated)
Commits
ae62891chore(deps): roll up Dependabot updates (#1013)f9cdb47Reject paths in .tool-versions (#1007)4f6036fRequire pull requests for Dependabot rollups (#1005)8d6402cchore(deps): roll up Dependabot updates (#1004)46f427bRead Python version from .tool-versions (#996)8ed89c5ci: pin Alpine container image (#995)8473c7fchore(deps): roll up Dependabot updates (#994)18d451dAdd latest-known version selector (#993)f451684Disable automatic caching for sensitive events (#992)b68407cchore: update known checksums for 0.12.3 (#991)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions