build(deps): bump astral-sh/uv from 0.12.1 to 0.12.8 - #61
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [astral-sh/uv](https://github.com/astral-sh/uv) from 0.12.1 to 0.12.8. - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.1...0.12.8) --- updated-dependencies: - dependency-name: astral-sh/uv dependency-version: 0.12.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
## Outcome Consolidates the broken one-file Dependabot updates into one verified maintenance change and removes the wildcard review rule that automatically requested a personal review on every repository change. ## Changes - upgrades the Python runtime/development groups from #64 and #65 with a regenerated lock; - coordinates the uv 0.12.8 pin from #61 across Docker, CI, release, acceptance and documentation; - adapts the MCP 2.1 anticipated-error boundary so unavailable sources remain sanitized and fail closed; - adds stdio MCP to the isolated live four-source CLI/REST/CRM parity gate; - fixes the Redocly 2.49.0 execution pin left inconsistent after #62; - scopes CODEOWNERS to governed/security-sensitive paths; - moves version-update cadence to quarterly, limits concurrent update PRs, and disables uncoordinated Docker version PRs while retaining security updates; - adds the dependency labels referenced by Dependabot. Python 3.14 from #63 is intentionally not included: it is a runtime major migration, not a patch update, and its Compose acceptance currently fails the repository's supported Python 3.13.14 contract. ## Verification - `./scripts/check.sh`: 2,088 tests, 100% statement/branch coverage, package/docs/OpenAPI/secret/dependency checks pass; no known vulnerabilities. - `./scripts/test_compose.sh`: full PostgreSQL 18.4 reference deployment passes with zero project residue. - `./scripts/test_official_screening_live.sh`: current four-source refresh/replay and CLI/REST/CRM/MCP parity pass with zero residue (EU FSF 6,234; Annex I 384; OFAC SDN 19,321; Consolidated 481). - Stale-source and invalid-input MCP paths remain fail closed; no mutating/clearance tool is exposed. Evidence: `docs/evidence/dependency-and-mcp-smoke-2026-09-02.md`. Relates to #47. Supersedes #61, #64 and #65 after merge.
|
Superseded by #66, which coordinates uv 0.12.8 across Docker, CI, release, pyproject, acceptance scripts and documentation and passed all repository, Compose and live MCP gates. Closing this one-file update because it could not satisfy the repository's cross-file version contract. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Warning
Cooldown could not be applied because no publication date was available from the registry.
Bumps astral-sh/uv from 0.12.1 to 0.12.8.
Release notes
Sourced from astral-sh/uv's releases.
... (truncated)
Changelog
Sourced from astral-sh/uv's changelog.
... (truncated)
Commits
68209e5Bump version to 0.12.8 (#21390)e0c5b7fAdd preference for exhaustive matches toAGENTS.md(#21386)0b19a85Fix workflow checksums and tool upgrade test compilation (#21387)068344aAdd regression test for uv#21364 (#21383)fc332e3Use test contexts for tool directories (#21380)55075a3Warn and skip invalid tool directories (#21368)9078a76Avoid duplicate concurrent wheel downloads (#21379)442a3bfVersion all Azure requests (#21366)918e522automations: skip workflow failure diagnosis on successfully retried re-runs ...19600f6Use package indices for additional lockfile traversals (#21377)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)