build(deps): bump astral-sh/setup-uv from 9.0.0 to 10.1.0 - #349
Conversation
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.1.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@c771a70...bec219d) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
A newer version of astral-sh/setup-uv exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Serialized setup-uv 10.1.0 update
The original Dependabot head
cd0ecbcb76a7290e661d0436b77f97d0d654d1d2was based directly on protectedmain@5913c4bad79d6bc29d7cc1c624abb7db2ea6a77cand modified the same CI/Release Acceptance paths already owned by the live workflow dependency stack. Applying that main-based tree directly would have regressed the current workflow contract inherited through #325 → #242 → #247 → #328. This remains a single-writer/wrong-base repair, not a reason to close a valid dependency delta.Exact current topology
dependabot/github_actions/step-security/harden-runner-2.21.1@973ab37d9be13d552cc2266d341c042971d33425;dependabot/github_actions/astral-sh/setup-uv-10.1.0@75830eae48435cfcfeb238c629858e25da7e8f3e;973ab37d9be13d552cc2266d341c042971d33425;.github/workflows/ci.yml— two setup-uv pins;.github/workflows/release-acceptance.yml— one setup-uv pin;tests/test_release_acceptance_workflow.py— the executable immutable-pin contract for the same Release Acceptance action.The earlier
3c5d5d23...reconciliation remains ordinary/non-destructive: original Dependabot history is retained and exact #328 is in ancestry. Current75830eae...is an ordinary fast-forward descendant; no force push, destructive rebase, protected-main write, or sibling source copy occurred.The production/workflow candidate uses
astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0at the three existing call sites while preserving #328's Harden Runner v2.21.1 pins, Python 3.10–3.14 matrix, PR-only cancellation semantics, removal of the obsolete repository-local hourly workflow, exact protected-main/manual Release Acceptance source binding, Ubuntu 24.04 acceptance runner, reproducibility checks, and release-impacting path inventory.Real exact-head RED → minimum causal repair
The first serialized setup-uv generation
3c5d5d239b3ddf0fed585c388f53ffd23ea54a0dobtained genuine runner-executed RED in CI35150493323rather than a queue/control-plane cancellation. Hosted jobs acquired runners, exact-head checkout succeeded, setup-uv succeeded, and locked dependency installation succeeded. The quality job then failed at Enforce line coverage, while Python 3.10/3.12/3.14 unit jobs failed at Run unit tests.The causal defect was repository-owned workflow-contract drift, not setup-uv execution:
tests/test_release_acceptance_workflow.pystill required the old v10.0.1 immutable SHA20cfd1bf945f4377ade1205e4dbc17946fc9a30deven though this serialized candidate had legitimately moved the Release Acceptance workflow to v10.1.0bec219d24cd3e171d82865faccec33120bb574f4. Because that regression participates in both unit and coverage lanes, the same stale assertion explains the observed failures.Minimum repair
75830eae48435cfcfeb238c629858e25da7e8f3echanges only that one executable expectation to the same v10.1.0 immutable SHA. It does not weaken generic immutable-SHA checking, remove a test, change uv's repository toolchain requirement, alter workflow permissions, or broaden this lane beyond the action update and its directly induced contract repair.SAST Semgrep
35150493298on the predecessor generation independently completed SUCCESS. That result remains historical only after the head moved; it does not transfer to the current exact head.Exact-current acceptance
Exact
75830eae48435cfcfeb238c629858e25da7e8f3eis now repository-local GREEN for the two owner acceptance workflows:35168910568: completed / success. All seven jobs completed successfully. The exact-head quality lane passed setup-uv v10.1.0, locked dependency installation, compile, Ruff, public-docstring enforcement, line coverage, lock freshness, and distribution build; supported-Python unit lanes and the container/PostgreSQL runtime-smoke lane also completed successfully.35168910640: completed / success on this exact head.Fresh formal-review and inline-thread inventories remain empty, so there is still no qualifying independent current-head approval. Repository-local GREEN also does not collapse the owner stack: #328 and its prerequisite chain remain outside protected integration. Keep Draft until the canonical parent chain is normally integrated/restacked and the resulting exact generation obtains the then-required acceptance/review evidence.
Do not ask Dependabot to rebase/recreate this serialized branch, self-approve, use routine bypass, add source-neutral wake commits, blind-rerun completed workflows, weaken the workflow contracts, force-push, destructively rebase, or transfer predecessor evidence.
Refs #233, #242, #244, #247, #325, #328.