Skip to content

build(deps): bump astral-sh/uv from 0.12.3 to 0.12.15 - #351

Draft
dependabot[bot] wants to merge 2 commits into
build/uv-0-12-9-contract-b84f0c9from
dependabot/docker/astral-sh/uv-0.12.15
Draft

dependabot[bot] wants to merge 2 commits into
build/uv-0-12-9-contract-b84f0c9from
dependabot/docker/astral-sh/uv-0.12.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Serialized uv 0.12.15 component-image candidate — current RED boundary

#333 remains the canonical single-writer owner for the root component-image uv tag+digest together with tests/test_dependency_refresh_contract.py. The original Dependabot candidate was main-based; this PR remains serialized behind #333 rather than bypassing that lineage.

#333's permanent dependency-refresh contract still requires the reviewed 0.12.12 tag+digest. This successor intentionally leaves that test authority unchanged until a genuine executable current-head CI/Release Acceptance RED proves the expected root-image assertion mismatch.

Fresh exact-head evidence remains source-inconclusive. CI 35150836091 and Release Acceptance 35150836036 are terminal cancelled; neither provides executable evidence for the image/digest contract. Security 35150836071 and SAST 35150836028 succeeded. CodeQL 35150836041 failed in the central producer/receiver settlement path rather than diagnosing this leaf contract. Do not reinterpret cancellation or a central workflow failure as an image/digest source RED.

Mutable central prerequisite

Do not freeze moving .github SHAs, workflow-run IDs, or mergeability probes in this durable dependency contract. Canonical live cross-repository authority is #244's single mutable commercial-integration ledger plus the live central owner PRs. In particular, .github#2040 owns the current scheduler/repository-identity prerequisite and .github#1644/#772 owns the solo-maintainer governance repair. A stale central snapshot must not trigger a Dependabot rebase, source churn, predecessor-evidence transfer, or leaf-contract change.

Therefore do not advance tests/test_dependency_refresh_contract.py to 0.12.15 yet. Keep Draft until this exact source generation obtains a genuine executable CI/Release Acceptance RED (or a different causal source finding), then apply the minimum digest-contract repair while preserving #331 Rust authority and require a fresh exact generation. No Dependabot rebase/recreate, self-approval, synthetic status, no-op wake commit, blind rerun, force update, destructive rebase or predecessor-evidence transfer.

Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.12.3 to 0.12.15.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.3...0.12.15)

---
updated-dependencies:
- dependency-name: astral-sh/uv
  dependency-version: 0.12.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Sep 16, 2026
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 08593991-ad5c-4b5e-869a-a11b3a747e66

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of astral-sh/uv exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code maintenance priority: medium Normal-priority or P2 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant