Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-uv for openSUSE:Factory checked in at 2026-09-01 15:50:49 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-uv (Old) and /work/SRC/openSUSE:Factory/.python-uv.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-uv" Tue Sep 1 15:50:49 2026 rev:117 rq:1375030 version:0.12.8 Changes: -------- --- /work/SRC/openSUSE:Factory/python-uv/python-uv.changes 2026-08-28 19:52:53.305524009 +0200 +++ /work/SRC/openSUSE:Factory/.python-uv.new.1265/python-uv.changes 2026-09-01 15:51:30.141341205 +0200 @@ -1,0 +2,30 @@ +Tue Sep 1 06:04:00 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 0.12.8: + * Do not trust hashes from direct URLs that are discovered only in + wheel metadata when installing with --require-hashes + * Redact Azure shared access signature (sig) query parameters from + displayed URLs + * Use an Azure Storage API version compatible with both anonymous + and authenticated requests, so credential retries work when + public access is disabled + * Treat projects below one-level workspace member globs as + standalone instead of aborting workspace discovery + * Warn about invalid tool directories and keep upgrading the valid + ones with uv tool upgrade --all + * Avoid downloading and extracting the same remote wheel more than + once when uv processes run concurrently + * Speed up dependency graph construction from large lockfiles, and + reuse that indexing for exports, dependency trees, audits and + freshness checks + * Speed up warm resolutions by reducing repeated marker interner + work + * Deduplicate identical files within and across cached wheels under + the content-addressed-cache preview feature + * Update astral-tokio-tar to 0.7.0 and use effective sizes when + tracking extracted hard links + * Refresh the vendored crates; the linked graph grows to 516 crates + (cpubits and zerocopy-derive are new) but the licence set is + unchanged + +------------------------------------------------------------------- Old: ---- python-uv-0.12.7.tar.gz New: ---- python-uv-0.12.8.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-uv.spec ++++++ --- /var/tmp/diff_new_pack.weTYsE/_old 2026-09-01 15:51:33.793468619 +0200 +++ /var/tmp/diff_new_pack.weTYsE/_new 2026-09-01 15:51:33.798468794 +0200 @@ -36,13 +36,13 @@ %global build_rustflags -C linker=clang -C link-arg=-fuse-ld=%{_bindir}/mold -C link-arg=-Wl,-z,relro,-z,now -C debuginfo=2 -C incremental=false -C strip=none %endif Name: %{origname}%{psuffix} -Version: 0.12.7 +Version: 0.12.8 Release: 0 Summary: A Python package installer and resolver, written in Rust # Legal-Review-Notice: uv itself is "Apache-2.0 OR MIT", but the binary # statically links the vendored Rust dependencies. Re-derived on this # re-vendor with "cargo tree --offline -p uv -e normal" over the vendored -# tree (509 crates); the copyleft licences in the linked graph are: +# tree (516 crates); the copyleft licences in the linked graph are: # - MPL-2.0 from astral-pubgrub, astral-version-ranges and option-ext # (the last via shellexpand -> dirs -> dirs-sys), # - priority-queue, which is "LGPL-3.0-or-later OR MPL-2.0" - we elect ++++++ python-uv-0.12.7.tar.gz -> python-uv-0.12.8.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-uv/python-uv-0.12.7.tar.gz /work/SRC/openSUSE:Factory/.python-uv.new.1265/python-uv-0.12.8.tar.gz differ: char 13, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/python-uv/vendor.tar.zst /work/SRC/openSUSE:Factory/.python-uv.new.1265/vendor.tar.zst differ: char 7, line 1
