build(deps): bump astral-sh/uv from 0.12.3 to 0.12.15 - #351
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.12.3 to 0.12.15. - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.3...0.12.15) --- updated-dependencies: - dependency-name: astral-sh/uv dependency-version: 0.12.15 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
A newer version of astral-sh/uv exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Serialized uv 0.12.15 component-image candidate — current RED boundary
#333 remains the canonical single-writer owner for the root component-image
uvtag+digest together withtests/test_dependency_refresh_contract.py. The original Dependabot candidate was main-based; this PR remains serialized behind #333 rather than bypassing that lineage.1bd88ef61dfdcdeda537ec5ab968ba537f0aadfd;c60a1318c60e81a4da84583efebf22f618a979de;Dockerfileline toghcr.io/astral-sh/uv:0.12.15@sha256:62f8c047d0a0e9ece6b53fc63df902585a67a47a7f318ddec4a37db586edc8e3.#333's permanent dependency-refresh contract still requires the reviewed 0.12.12 tag+digest. This successor intentionally leaves that test authority unchanged until a genuine executable current-head CI/Release Acceptance RED proves the expected root-image assertion mismatch.
Fresh exact-head evidence remains source-inconclusive. CI
35150836091and Release Acceptance35150836036are terminalcancelled; neither provides executable evidence for the image/digest contract. Security35150836071and SAST35150836028succeeded. CodeQL35150836041failed in the central producer/receiver settlement path rather than diagnosing this leaf contract. Do not reinterpret cancellation or a central workflow failure as an image/digest source RED.Mutable central prerequisite
Do not freeze moving
.githubSHAs, workflow-run IDs, or mergeability probes in this durable dependency contract. Canonical live cross-repository authority is #244's single mutable commercial-integration ledger plus the live central owner PRs. In particular,.github#2040owns the current scheduler/repository-identity prerequisite and.github#1644/#772owns the solo-maintainer governance repair. A stale central snapshot must not trigger a Dependabot rebase, source churn, predecessor-evidence transfer, or leaf-contract change.Therefore do not advance
tests/test_dependency_refresh_contract.pyto 0.12.15 yet. Keep Draft until this exact source generation obtains a genuine executable CI/Release Acceptance RED (or a different causal source finding), then apply the minimum digest-contract repair while preserving #331 Rust authority and require a fresh exact generation. No Dependabot rebase/recreate, self-approval, synthetic status, no-op wake commit, blind rerun, force update, destructive rebase or predecessor-evidence transfer.