Repository navigation
chore(deps): update docker - #282
Open
bootc-bot[bot] wants to merge 1 commit into
Open
bootc-bot[bot] wants to merge 1 commit into
bootc-bot[bot] wants to merge 1 commit into
Conversation
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com> Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
bootc-bot
Bot
force-pushed
the
bootc-renovate/docker
branch
from
October 11, 2026 02:43
d643070 to
9b35aa4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.12.23→0.13.0v1.53.0→v1.54.00.45.1→0.46.00.9.146→0.9.148nightly-2026-10-04→nightly-2026-10-11Release Notes
astral-sh/uv
v0.13.0Compare Source
Released on 2026-10-09.
uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.
We expect most users to be able to upgrade without making changes.
While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. uv may download or rebuild dependencies after upgrading, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.
There are no breaking changes to the configuration of the uv build backend. If your
[build-system]table includes an upper bound onuv_build, update it to allowuv_build0.13, e.g.,uv_build>=0.13.0,<0.14.Breaking changes
Use Python 3.15 as the default stable version
The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running
uv python install.uv continues to use compatible Python installations that are already present. For example,
uv venvcan still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such asuv venvanduvx pythoncan now download Python 3.15.You can opt out of this behavior by requesting Python 3.14 explicitly, e.g.,
uv venv --python 3.14. For projects, useuv python pin 3.14to record the version in.python-version.Honor
--require-hashesin included constraints files (#22275)Previously, uv ignored
--require-hashesin constraints files included with-cfrom a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the
--require-hashesdirective from the included constraints file if hash checking is not intended.Prefer native Python on Windows ARM64 (#22100)
Previously, ARM64 builds of uv preferred emulated
x86_64Python installations because native wheel support was limited. Now, uv prefers native ARM64 (aarch64) interpreters across Python versions.This follows similar changes in CPython, the official Windows Python install manager, and GitHub's actions/setup-python.
When a native interpreter is unavailable, uv continues to fall back to
x86_64, then 32-bitx86.You can opt out of this behavior by setting
UV_PYTHON_ARCH=x86_64or requesting an explicit architecture, e.g.,cpython-3.14-windows-x86_64. If you are usingsetup-uv, you can setpython-arch: x86_64instead.Reject editable requirements in included constraints files (#22282)
Previously, uv silently ignored editable (
-e) requirements in constraints files included with-cfrom a requirements file. Now, uv rejects these requirements with an error, matching pip's behavior.You cannot opt out of this behavior. Move editable requirements to a requirements file passed with
-r, or pass them directly with--editable, instead of including them in a constraints file.Omit the distutils startup patch on Python 3.10 and later (#22096)
Previously, uv installed
_virtualenv.pyand_virtualenv.pthinto every new virtual environment to prevent distutils configuration from changing installation paths. Now, likevirtualenv21.6.0, uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.
This stabilizes the
no-distutils-patchpreview feature.Treat requirement-file option values as single paths (#22290)
Previously, uv split values passed to
--constraint,--override,--exclude, and--build-constrainton spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace
-c "a.txt b.txt"with-c a.txt -c b.txt.Space-separated lists in
UV_CONSTRAINT,UV_OVERRIDE,UV_EXCLUDE, andUV_BUILD_CONSTRAINTremain supported.Use
tar-codecfor tar archives by default (#22094)Previously, uv used
astral-tokio-tarto extract tar archives, build source distributions withuv_build, and read their metadata foruv publish. Now, uv usestar-codec, which applies stricter validation when reading archives.uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by
uv_buildcan also have different archive bytes and hashes.You can opt out of this behavior by setting
UV_LEGACY_TAR_BACKEND=1.This stabilizes the
tar-codecpreview feature.Reject
uv build --clearoutput directories that contain a build source(#22276)
Previously,
uv build --clearcould delete a project or input source distribution when theoutput directory contained the source. Now, uv rejects these output directories, including
equivalent paths reached through symlinks, before clearing any build output.
Select an output directory that does not contain any build sources, or omit
--clear.Python
Preview features
--require-build-hashes(#21411)Performance
Bug fixes
v0.12.24Compare Source
Release Notes
Released on 2026-10-08.
Enhancements
uv cache prune(#22171)Preview features
uv auditreports, prioritizing PYSEC, GHSA, then CVE identifiers (#22292)Configuration
UV_NO_CACHE=falseto overrideno-cache = truein configuration (#22324)Performance
--find-linkspages withastral-html(#22203)uv-buildexecutable size by 7.5% by omitting unused Zstandard support (#22242)Bug fixes
--no-require-hashesorrequire-hashes = false(#22369)uv publish --trusted-publishingvalues precedence over configuration (#22279)UV_OFFLINE=falseto overrideoffline = truein configuration (#22283)UV_SYSTEM_CERTS=falseto overridesystem-certs = truein configuration (#22291)uv auth loginover IPv6 loopback addresses (#22306)#or%characters (#22281)uv versionanduv self versionwith a single--quietflag (#22280)WHEELmetadata contains multiple expandedTag:rows (#22235)--keyring-provideroption fromuv authhelp (#19520)uv toolrequirements (#22320)Documentation
required-environmentsdocumentation (#22238)Install uv 0.12.24
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"Download uv 0.12.24
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
block/goose
v1.54.0Compare Source
✨ Features
🐛 Bug Fixes
🔧 Improvements
📚 Documentation
jj-vcs/jj
v0.46.0Compare Source
About
jj is a Git-compatible version control system that is both simple and powerful. See
the installation instructions to get started.
Release highlights
worktrees. Use
jj workspace add --[no-]colocateand the settinggit.colocateto control this.Breaking changes
The minimum supported
gitcommand version is now 2.42.0, up from 2.41.0.jj workspace addusesgit worktree add --orphan, which was added in2.42.0.
The minimum supported Rust version (MSRV) is now 1.97.1.
jj bisect runnow runs some consistency checks before proceeding to bisect.This helps ensure that the command can tell good and bad revisions apart,
and that the working copy does go from bad to good over the provided revset.
Use the new flag
--trust-endpointsto disable these checks.jj splitnow opens a single editor session to edit descriptions for thesplit commits.
jj undoandjj redonow refuse to undo/redo an operation that wasperformed in another workspace. Use
--allow-cross-workspaceto undo/redoit anyway.
jj workspace list/rootno longer omit unreachable paths. All recordedpaths are now shown, with warnings displayed in
jj workspace root.The
List.get(),.first(), and.last()template functions now returnOption<T>instead of throwing an error on out-of-bounds access.New features
jj workspace addsupports--colocate/--no-colocateflags to controlwhether a Git worktree is created alongside the workspace. The default
colocates when the current workspace is colocated and the
git.colocateconfig is
true.jj workspace forgetremoves the corresponding Gitworktree when one exists.
jj git colocation status/enable/disablenow work on childworkspaces.
statuscorrectly reports colocation state and includesthe workspace name.
enablecreates a Git worktree anddisableremoves it, allowing colocation to be toggled after workspace
creation.
jj workspace removeremoves a workspace and its directory from disk. Theworking-copy state is snapshotted into a commit before removal.
Added commands
jj file editandjj file deletefor editing files in anyrevision without needing to change the working copy.
jj git pushnow supports pushing to multiple remotes at the same time.This can be configured via
git.pushset to a string patternor array of string patterns, or with the repeatable
--remoteflag,which also accepts string patterns.
The default target revisions for
jj git pushcan now be configured viarevsets.git-push.Added the
TreeEntry.normal_value()template method and theTreeValuetypeto access resolved tree values, formatted as their full object IDs, including
Git submodule commit IDs.
Diff hunk headers now include nearby source symbols for many common
programming and markup languages.
fix.tools.<name>.line-range-args(replacesline-range-arg) is an array ofstring template args to pass to the fix tool. This is more flexible in cases
where you need to pass multiple arguments to the tool, such as separate args
for the range start and range end.
jj runnow uses the sparse patterns from the workspace it's run from.Use the
--sparse-patternsoption to control this behavior (evaluatedper each
jj runinvocation).jj util diff <path1> <path2>to compare files on disk.Aliases now support setting
aliases.<name>.enabled = false, which willdisable them. This can be used to disable built-in aliases or disable aliases
in later layers (such as repo config files).
ui.editornow supports$pathand$linesubstitution variables. Example:ui.editor = ["emacs", "+$line", "$path"]filltemplate function now supports an additional named parameterbreak_words, that allows specifying if the template should break wordslonger than
widthpassed in the input to ensure no words overflow thespecified width.
The
json()template function now supports map literals:json({'key' => value})The hunk headers of
diff.color-words.conflict = "pair"now include theconflict labels of the compared terms.
Fixed bugs
On Windows,
jjno longer hangs when a subprocess needs to prompt the user,such as
sshasking for a key passphrase or for confirmation of an unknownhost key. Subprocesses started from a terminal now inherit its console, rather
than being given an invisible one by
CREATE_NO_WINDOWfor the prompt todisappear into.
#6745
#8547
On Windows,
jj git colocation enableandjj git colocation disablenolonger fail with "Access is denied (os error 5)" when the Git repository
contains pack files.
#8661
jj undoofjj workspace forgetnow correctly preserves the workspace'srecorded path. Previously the path metadata was lost, leaving the workspace
in a broken state after undo.
#9991
at_operation()can now be used with operations that are not ancestors ofthe current operation (e.g. sibling operations created by concurrent
commands). Previously, evaluating such expressions failed if they resolved
to commits missing from the current operation's index.
.gitignorefiles are now respected even if they aren't materialized in theworking copy because they are excluded by the sparse patterns. Previously,
ignored files could become tracked in a sparse working copy.
#2289
In-tree ignore files (
.gitignore) are no longer read through symlinks,matching
gitbehavior. Such files are now silently skipped instead of havingtheir symlink target applied.
$GIT_DIR/info/excludeandcore.excludesFileare unaffected and still follow symlinks, as
gitdoes.#7161
jj workspace listtemplates are now labeled withworkspace name,workspace root, etc.Contributors
Thanks to the people who made this release happen!
nextest-rs/nextest
v0.9.148: cargo-nextest 0.9.148Compare Source
Changed
slow-timeoutno longer acceptson-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled. (#3640)guppyupdated to 0.19.1, andtarget-specupdated to 3.7.0, updating built-in targets to Rust 1.98.Fixed
Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed. (#3624)
Stress runs now always run at least one iteration. Previously,
--stress-durationwith a very short duration (such as1ns) could finish without running any tests. (#3633)Runs stopped by immediate fail-fast (
--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read0 passed; cancelled due to test failureand the failing iteration was not counted as failed. (#3639)When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second
Cancelling due to test failureline and reported a test failure as the reason. (#3637)After the global timeout fires, nextest no longer keeps a CPU core busy while it waits for running tests to shut down. (#3647)
The leak timeout is no longer restarted each time a leaked handle produces output, or each time nextest handles a signal or an info request while waiting. Previously, a test that exited while leaving behind a process that kept writing to standard output or standard error could delay leak detection indefinitely. (#3646)
If waiting on a test or setup script process fails, nextest now reports the test or script as an execution failure, with the underlying error shown. Previously, nextest panicked. (#3643)
The
CancellingandKillingstatus lines no longer contain stray colons. Previously, nextest printed lines likeKilling due to second signal: : 1 test still running, and a trailing colon when nothing was still running. (#3641)Internal improvements
Source builds of nextest no longer compile two versions of
zstd. (#3620)Thanks Jake-Shadle for your contribution!
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.