From b10326c4947428a70ef31370b7bff408cf62c5eb Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Sat, 11 Jul 2026 10:12:21 +0000 Subject: [PATCH 1/4] chore(deps): update astral-sh/setup-uv action to v8.3.2 --- .github/workflows/release-please.yml | 2 +- .github/workflows/test.yml | 10 +++++----- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index fa55514..69e1f64 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -46,7 +46,7 @@ jobs: with: ref: ${{ needs.release-please.outputs.tag_name }} - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7067c19..bb3c855 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -25,7 +25,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true @@ -51,7 +51,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true @@ -127,7 +127,7 @@ jobs: env: NODE_OPTIONS: --max-old-space-size=4096 - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true @@ -199,7 +199,7 @@ jobs: # Intentionally skip installing promptfoo globally # This tests the npx fallback path - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true @@ -228,7 +228,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 with: enable-cache: true From 532cc20e24fa466f4ca49c03fad5df212ee7fd22 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 10:46:49 -0700 Subject: [PATCH 2/4] chore(deps): upgrade setup-uv and pin the CLI --- .github/workflows/release-please.yml | 5 +++-- .github/workflows/test.yml | 25 +++++++++++++++---------- 2 files changed, 18 insertions(+), 12 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 69e1f64..de963ce 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -46,9 +46,10 @@ jobs: with: ref: ${{ needs.release-please.outputs.tag_name }} - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin 3.12 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index bb3c855..c51cd87 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -25,9 +25,10 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin 3.12 @@ -51,9 +52,10 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin 3.12 @@ -127,9 +129,10 @@ jobs: env: NODE_OPTIONS: --max-old-space-size=4096 - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin ${{ matrix.python-version }} @@ -199,9 +202,10 @@ jobs: # Intentionally skip installing promptfoo globally # This tests the npx fallback path - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin ${{ matrix.python-version }} @@ -228,9 +232,10 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - enable-cache: true + version: "0.12.11" + enable-cache: auto - name: Pin Python version run: uv python pin 3.12 From 03a2a4f9de01fe73fcdf4f7a726058c0911b3160 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 10:37:57 -0700 Subject: [PATCH 3/4] ci(deps): isolate Windows npm installations --- .github/workflows/test.yml | 53 ++++---------------------------------- 1 file changed, 5 insertions(+), 48 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index c51cd87..68f7478 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -93,36 +93,12 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - # Add global bin directories to PATH - $binPaths = @($globalPrefix, (Join-Path $globalPrefix "bin")) | Where-Object { Test-Path $_ } - foreach ($binPath in $binPaths) { - $binPath | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - } - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" + $globalPrefix | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - name: Install promptfoo globally run: npm install -g promptfoo@latest @@ -174,30 +150,11 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" # Intentionally skip installing promptfoo globally # This tests the npx fallback path From 8d407d30148ee311c86e6cded993da036e14183e Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 12:15:11 -0700 Subject: [PATCH 4/4] ci(deps): pin uv 0.12.17 --- .github/workflows/release-please.yml | 2 +- .github/workflows/test.yml | 10 +++++----- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 146d5eb..22c514f 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -62,7 +62,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index fe8abc4..46a309d 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -53,7 +53,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version @@ -120,7 +120,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version @@ -186,7 +186,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version @@ -251,7 +251,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version @@ -286,7 +286,7 @@ jobs: - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: - version: "0.12.11" + version: "0.12.17" enable-cache: auto - name: Pin Python version