Skip to content

chore(deps): update docker - #282

Open
bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/docker
Open

bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/docker

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
astral-sh/uv minor 0.12.23 → 0.13.0
block/goose minor v1.53.0 → v1.54.0
jj-vcs/jj minor 0.45.1 → 0.46.0
nextest-rs/nextest patch 0.9.146 → 0.9.148
rust-nightly patch nightly-2026-10-04 → nightly-2026-10-11

Release Notes

astral-sh/uv

v0.13.0

Compare Source

Released on 2026-10-09.

uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.

We expect most users to be able to upgrade without making changes.

While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. uv may download or rebuild dependencies after upgrading, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.

There are no breaking changes to the configuration of the uv build backend. If your [build-system] table includes an upper bound on uv_build, update it to allow uv_build 0.13, e.g., uv_build>=0.13.0,<0.14.

Breaking changes
  • Use Python 3.15 as the default stable version

    The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running uv python install.

    uv continues to use compatible Python installations that are already present. For example, uv venv can still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such as uv venv and uvx python can now download Python 3.15.

    You can opt out of this behavior by requesting Python 3.14 explicitly, e.g., uv venv --python 3.14. For projects, use uv python pin 3.14 to record the version in .python-version.

  • Honor --require-hashes in included constraints files (#​22275)

    Previously, uv ignored --require-hashes in constraints files included with -c from a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.

    You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the --require-hashes directive from the included constraints file if hash checking is not intended.

  • Prefer native Python on Windows ARM64 (#​22100)

    Previously, ARM64 builds of uv preferred emulated x86_64 Python installations because native wheel support was limited. Now, uv prefers native ARM64 (aarch64) interpreters across Python versions.

    This follows similar changes in CPython, the official Windows Python install manager, and GitHub's actions/setup-python.

    When a native interpreter is unavailable, uv continues to fall back to x86_64, then 32-bit x86.

    You can opt out of this behavior by setting UV_PYTHON_ARCH=x86_64 or requesting an explicit architecture, e.g., cpython-3.14-windows-x86_64. If you are using setup-uv, you can set python-arch: x86_64 instead.

  • Reject editable requirements in included constraints files (#​22282)

    Previously, uv silently ignored editable (-e) requirements in constraints files included with -c from a requirements file. Now, uv rejects these requirements with an error, matching pip's behavior.

    You cannot opt out of this behavior. Move editable requirements to a requirements file passed with -r, or pass them directly with --editable, instead of including them in a constraints file.

  • Omit the distutils startup patch on Python 3.10 and later (#​22096)

    Previously, uv installed _virtualenv.py and _virtualenv.pth into every new virtual environment to prevent distutils configuration from changing installation paths. Now, like virtualenv 21.6.0, uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.

    You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.

    This stabilizes the no-distutils-patch preview feature.

  • Treat requirement-file option values as single paths (#​22290)

    Previously, uv split values passed to --constraint, --override, --exclude, and --build-constraint on spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.

    You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace -c "a.txt b.txt" with -c a.txt -c b.txt.

    Space-separated lists in UV_CONSTRAINT, UV_OVERRIDE, UV_EXCLUDE, and UV_BUILD_CONSTRAINT remain supported.

  • Use tar-codec for tar archives by default (#​22094)

    Previously, uv used astral-tokio-tar to extract tar archives, build source distributions with uv_build, and read their metadata for uv publish. Now, uv uses tar-codec, which applies stricter validation when reading archives.

    uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by uv_build can also have different archive bytes and hashes.

    You can opt out of this behavior by setting UV_LEGACY_TAR_BACKEND=1.

    This stabilizes the tar-codec preview feature.

  • Reject uv build --clear output directories that contain a build source
    (#​22276)

    Previously, uv build --clear could delete a project or input source distribution when the
    output directory contained the source. Now, uv rejects these output directories, including
    equivalent paths reached through symlinks, before clearing any build output.

    Select an output directory that does not contain any build sources, or omit --clear.

Python
Preview features
  • Require hashes for build dependencies, including transitive dependencies, with --require-build-hashes (#​21411)
Performance
  • Speed up revalidation of cached HTTP responses by avoiding rewrites of unchanged payloads (#​22130)
  • Reduce allocations when reading cached HTTP responses (#​22136)
  • Reduce cache storage for HTTP policies and package records (#​22135, #​22133)
  • Reduce allocations for cached source distribution revisions (#​22131)
Bug fixes
  • Fix incorrect dependency resolution when reusing source metadata with different build settings (#​22404)
  • Avoid overlong wheel cache lock filenames on Windows (#​22134)

v0.12.24

Compare Source

Release Notes

Released on 2026-10-08.

Enhancements
  • Remove orphaned temporary build environments with uv cache prune (#​22171)
  • Accept PEP 508 marker operators directly before grouped expressions (#​22309)
  • Reject malformed requirements-file options instead of partially parsing or ignoring them (#​22317)
  • Show underlying filesystem and registry errors when managed Python uninstallation fails (#​22362)
  • Identify the invalid source URL in Python mirror errors (#​22364)
Preview features
  • Display preferred advisory IDs in uv audit reports, prioritizing PYSEC, GHSA, then CVE identifiers (#​22292)
Configuration
  • Support custom installation mirrors for GraalPy (#​22269)
  • Support custom installation mirrors for Pyodide (#​22271)
  • Allow UV_NO_CACHE=false to override no-cache = true in configuration (#​22324)
  • Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#​22144)
Performance
  • Speed up later commands after creating an environment by warming its interpreter cache (#​21304)
  • Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#​22246)
  • Enforce resource limits when parsing package indexes and --find-links pages with astral-html (#​22203)
  • Reduce standalone uv-build executable size by 7.5% by omitting unused Zstandard support (#​22242)
  • Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#​22144)
  • Reduce Python download error formatting code size by sharing its formatter (#​22141)
Bug fixes
  • Verify supplied hashes even when hash presence is disabled with --no-require-hashes or require-hashes = false (#​22369)
  • Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#​22360)
  • Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#​22237)
  • Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#​22234)
  • Give explicit uv publish --trusted-publishing values precedence over configuration (#​22279)
  • Allow UV_OFFLINE=false to override offline = true in configuration (#​22283)
  • Allow UV_SYSTEM_CERTS=false to override system-certs = true in configuration (#​22291)
  • Allow uv auth login over IPv6 loopback addresses (#​22306)
  • Resolve GitHub dependencies whose Git references contain # or % characters (#​22281)
  • Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#​22322)
  • Preserve JSON output from uv version and uv self version with a single --quiet flag (#​22280)
  • Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#​22284)
  • Restore wheel incompatibility hints when WHEEL metadata contains multiple expanded Tag: rows (#​22235)
  • Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#​22302)
  • Prevent workspace-cache assertion failures after modifying a project at the workspace root (#​22236)
  • Hide the ignored --keyring-provider option from uv auth help (#​19520)
  • Report HTTP client setup failures directly when resolving unnamed uv tool requirements (#​22320)
Documentation
  • Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests (#​22172)
  • Fix stale links and descriptions in Rust crate documentation (#​22311, #​22361)
  • Fix a typo in the required-environments documentation (#​22238)
Install uv 0.12.24
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"
Download uv 0.12.24
File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
uv-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
uv-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
uv-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
uv-riscv64gc-unknown-linux-musl.tar.gz RISCV MUSL Linux checksum
uv-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
uv-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
uv-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum
Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
block/goose

v1.54.0

Compare Source

✨ Features
  • Prompt for goose mode during first-time configure #​12629
  • HTML session export with an interactive viewer #​11977
🐛 Bug Fixes
  • Adaptive thinking for Claude Sonnet and Haiku 5.5 #​12761
  • Treat a client extension selection as the exact session set #​12548
  • Support hyphenated GPT 6.1 Sol effort aliases #​12689
  • Use a system Node.js in the Windows npx wrapper #​12176
  • Show thinking when GOOSE_CLI_SHOW_THINKING is set to any value #​12454
  • Price Databricks GLM aliases from the zhipuai catalog #​12673
  • Read messages from config for tom #​12634
  • Preserve the service total when folding cache input tokens for Bedrock #​12586
  • Refresh revoked Copilot tokens when listing models #​12627
  • Refresh revoked GitHub Copilot API token once #​12616
  • Recognize ASAR when validating update target #​12599
  • Stamp the implemented protocol version in initialize #​12580
  • Session naming/"none" reasoning effort fails for gpt-6.1-sol #​12605
  • Reflect loading state of chats #​12603
  • Read cache write tokens from Responses API usage #​12509
🔧 Improvements
  • Route every extension operation through a lease #​12723
  • Foreground subagents in the state machine loop #​12632
  • Resolve extensions into a per-inference lease #​12161
  • Remove Nostr session sharing from goose core #​12453
  • Detect vision support #​12594
  • Upgrade rust to 1.99.0 #​12714
📚 Documentation
  • Update Desktop permission mode instructions #​12626
  • Clarify self-serve LLM provider path #​12552
jj-vcs/jj

v0.46.0

Compare Source

About

jj is a Git-compatible version control system that is both simple and powerful. See
the installation instructions to get started.

Release highlights
  • Jujutsu can now colocate workspaces besides the default one by creating Git
    worktrees. Use jj workspace add --[no-]colocate and the setting
    git.colocate to control this.
Breaking changes
  • The minimum supported git command version is now 2.42.0, up from 2.41.0.
    jj workspace add uses git worktree add --orphan, which was added in
    2.42.0.

  • The minimum supported Rust version (MSRV) is now 1.97.1.

  • jj bisect run now runs some consistency checks before proceeding to bisect.
    This helps ensure that the command can tell good and bad revisions apart,
    and that the working copy does go from bad to good over the provided revset.
    Use the new flag --trust-endpoints to disable these checks.

  • jj split now opens a single editor session to edit descriptions for the
    split commits.

  • jj undo and jj redo now refuse to undo/redo an operation that was
    performed in another workspace. Use --allow-cross-workspace to undo/redo
    it anyway.

  • jj workspace list/root no longer omit unreachable paths. All recorded
    paths are now shown, with warnings displayed in jj workspace root.

  • The List.get(), .first(), and .last() template functions now return
    Option<T> instead of throwing an error on out-of-bounds access.

New features
  • jj workspace add supports --colocate/--no-colocate flags to control
    whether a Git worktree is created alongside the workspace. The default
    colocates when the current workspace is colocated and the git.colocate
    config is true. jj workspace forget removes the corresponding Git
    worktree when one exists.

  • jj git colocation status/enable/disable now work on child
    workspaces. status correctly reports colocation state and includes
    the workspace name. enable creates a Git worktree and disable
    removes it, allowing colocation to be toggled after workspace
    creation.

  • jj workspace remove removes a workspace and its directory from disk. The
    working-copy state is snapshotted into a commit before removal.

  • Added commands jj file edit and jj file delete for editing files in any
    revision without needing to change the working copy.

  • jj git push now supports pushing to multiple remotes at the same time.
    This can be configured via git.push set to a string pattern
    or array of string patterns, or with the repeatable --remote flag,
    which also accepts string patterns.

  • The default target revisions for jj git push can now be configured via
    revsets.git-push.

  • Added the TreeEntry.normal_value() template method and the TreeValue type
    to access resolved tree values, formatted as their full object IDs, including
    Git submodule commit IDs.

  • Diff hunk headers now include nearby source symbols for many common
    programming and markup languages.

  • fix.tools.<name>.line-range-args (replaces line-range-arg) is an array of
    string template args to pass to the fix tool. This is more flexible in cases
    where you need to pass multiple arguments to the tool, such as separate args
    for the range start and range end.

  • jj run now uses the sparse patterns from the workspace it's run from.
    Use the --sparse-patterns option to control this behavior (evaluated
    per each jj run invocation).

  • jj util diff <path1> <path2> to compare files on disk.

  • Aliases now support setting aliases.<name>.enabled = false, which will
    disable them. This can be used to disable built-in aliases or disable aliases
    in later layers (such as repo config files).

  • ui.editor now supports $path and $line substitution variables. Example:
    ui.editor = ["emacs", "+$line", "$path"]

  • fill template function now supports an additional named parameter
    break_words, that allows specifying if the template should break words
    longer than width passed in the input to ensure no words overflow the
    specified width.

  • The json() template function now supports map literals: json({'key' => value})

  • The hunk headers of diff.color-words.conflict = "pair" now include the
    conflict labels of the compared terms.

Fixed bugs
  • On Windows, jj no longer hangs when a subprocess needs to prompt the user,
    such as ssh asking for a key passphrase or for confirmation of an unknown
    host key. Subprocesses started from a terminal now inherit its console, rather
    than being given an invisible one by CREATE_NO_WINDOW for the prompt to
    disappear into.
    #​6745
    #​8547

  • On Windows, jj git colocation enable and jj git colocation disable no
    longer fail with "Access is denied (os error 5)" when the Git repository
    contains pack files.
    #​8661

  • jj undo of jj workspace forget now correctly preserves the workspace's
    recorded path. Previously the path metadata was lost, leaving the workspace
    in a broken state after undo.
    #​9991

  • at_operation() can now be used with operations that are not ancestors of
    the current operation (e.g. sibling operations created by concurrent
    commands). Previously, evaluating such expressions failed if they resolved
    to commits missing from the current operation's index.

  • .gitignore files are now respected even if they aren't materialized in the
    working copy because they are excluded by the sparse patterns. Previously,
    ignored files could become tracked in a sparse working copy.
    #​2289

  • In-tree ignore files (.gitignore) are no longer read through symlinks,
    matching git behavior. Such files are now silently skipped instead of having
    their symlink target applied. $GIT_DIR/info/exclude and core.excludesFile
    are unaffected and still follow symlinks, as git does.
    #​7161

  • jj workspace list templates are now labeled with workspace name,
    workspace root, etc.

Contributors

Thanks to the people who made this release happen!

nextest-rs/nextest

v0.9.148: cargo-nextest 0.9.148

Compare Source

Changed
  • For setup scripts, slow-timeout no longer accepts on-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled. (#​3640)
  • Internal dependency updates: guppy updated to 0.19.1, and target-spec updated to 3.7.0, updating built-in targets to Rust 1.98.
Fixed
  • Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed. (#​3624)

  • Stress runs now always run at least one iteration. Previously, --stress-duration with a very short duration (such as 1ns) could finish without running any tests. (#​3633)

  • Runs stopped by immediate fail-fast (--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read 0 passed; cancelled due to test failure and the failing iteration was not counted as failed. (#​3639)

  • When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second Cancelling due to test failure line and reported a test failure as the reason. (#​3637)

  • After the global timeout fires, nextest no longer keeps a CPU core busy while it waits for running tests to shut down. (#​3647)

  • The leak timeout is no longer restarted each time a leaked handle produces output, or each time nextest handles a signal or an info request while waiting. Previously, a test that exited while leaving behind a process that kept writing to standard output or standard error could delay leak detection indefinitely. (#​3646)

  • If waiting on a test or setup script process fails, nextest now reports the test or script as an execution failure, with the underlying error shown. Previously, nextest panicked. (#​3643)

  • The Cancelling and Killing status lines no longer contain stray colons. Previously, nextest printed lines like Killing due to second signal: : 1 test still running, and a trailing colon when nothing was still running. (#​3641)

Internal improvements
  • Source builds of nextest no longer compile two versions of zstd. (#​3620)

    Thanks Jake-Shadle for your contribution!


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "on sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
@bootc-bot
bootc-bot Bot force-pushed the bootc-renovate/docker branch from d643070 to 9b35aa4 Compare October 11, 2026 02:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants