Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-uv for openSUSE:Factory checked in at 2026-10-09 21:45:49 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-uv (Old) and /work/SRC/openSUSE:Factory/.python-uv.new.3698736 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-uv" Fri Oct 9 21:45:49 2026 rev:132 rq:1383704 version:0.12.24 Changes: -------- --- /work/SRC/openSUSE:Factory/python-uv/python-uv.changes 2026-10-05 13:01:52.659459196 +0200 +++ /work/SRC/openSUSE:Factory/.python-uv.new.3698736/python-uv.changes 2026-10-09 21:46:46.365825846 +0200 @@ -1,0 +2,29 @@ +Fri Oct 9 07:14:27 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 0.12.24: + * `uv cache prune` removes orphaned temporary build environments + * Accept PEP 508 marker operators before grouped expressions; + reject malformed requirements-file options instead of ignoring + them + * Managed Python: honour exact patch pins in script environments, + custom GraalPy/Pyodide mirrors, clearer uninstall errors + * Preview: `uv audit` prefers PYSEC, then GHSA, then CVE IDs + * UV_NO_CACHE/UV_OFFLINE/UV_SYSTEM_CERTS=false now override the + config file; explicit --trusted-publishing wins over config + * Verify supplied hashes even with require-hashes disabled; + overrides no longer pull unselected optional deps; IPv6 loopback + for `uv auth login`; GitHub refs with `#`/`%` + * Many more fixes and improvements; see upstream's release notes + for the full list +- Refresh the vendored dependencies: async-compression 0.4.19 -> + 0.4.50 (split out compression-codecs/core), astral-html 0.0.3 + replaces astral-tl and html-escape, smallvec 1.15.2 -> 1.16.2, + tokio-rustls 0.26.4 -> 0.26.6 and fs-err 3.3.1 -> 3.3.2 are all + linked into the binary; the linked graph grows to 525 nodes (was + 509) and the licence set is unchanged + * CVE-2026-92987 (boo#1281170): roxmltree is vendored but not + linked into the shipped binary, so this package is not affected +- Upstream MSRV is still Rust 1.97, so BuildRequires on cargo is + unchanged + +------------------------------------------------------------------- Old: ---- python-uv-0.12.23.tar.gz New: ---- python-uv-0.12.24.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-uv.spec ++++++ --- /var/tmp/diff_new_pack.MLqTYO/_old 2026-10-09 21:46:51.837056072 +0200 +++ /var/tmp/diff_new_pack.MLqTYO/_new 2026-10-09 21:46:51.840056198 +0200 @@ -36,13 +36,13 @@ %global build_rustflags -C linker=clang -C link-arg=-fuse-ld=%{_bindir}/mold -C link-arg=-Wl,-z,relro,-z,now -C debuginfo=2 -C incremental=false -C strip=none %endif Name: %{origname}%{psuffix} -Version: 0.12.23 +Version: 0.12.24 Release: 0 Summary: A Python package installer and resolver, written in Rust # Legal-Review-Notice: uv itself is "Apache-2.0 OR MIT", but the binary # statically links the vendored Rust dependencies. Re-derived on this # re-vendor with "cargo tree --offline -p uv -e normal" over the vendored -# tree (509 unique name-version nodes); the copyleft licences in the linked graph are: +# tree (525 unique name-version nodes); the copyleft licences in the linked graph are: # - MPL-2.0 from astral-pubgrub, astral-version-ranges and option-ext # (the last via shellexpand -> dirs -> dirs-sys), # - priority-queue, which is "LGPL-3.0-or-later OR MPL-2.0" - we elect @@ -217,11 +217,15 @@ # nothing, so the spawn fails outright - and would then resolve a # Python interpreter and its dependencies over the network. The other # nine uv-extract tests, including the rest of the dirhash suite, still -# run. +# run. uv-requirements-txt's malformed_option cases 2-3 are the same +# insta-in-one-process limitation as uv-build-backend above, new in +# 0.12.24 with the malformed-requirements-option rejections: three +# #[test_case]s share one inline snapshot, so the first passes and the +# rest panic before comparing anything. Case 1 still runs. # # The leading "--" is required: %%cargo_test is a parametrised macro, so # without it rpm parses "--workspace" as a macro option and aborts. -%{cargo_test -- --workspace --exclude uv --exclude uv-dev --exclude uv-build-backend -- --test-threads=1 --skip user_agent_version::test_user_agent_has_linehaul --skip dirhash::tests::test_vectors_json} +%{cargo_test -- --workspace --exclude uv --exclude uv-dev --exclude uv-build-backend -- --test-threads=1 --skip user_agent_version::test_user_agent_has_linehaul --skip dirhash::tests::test_vectors_json --skip malformed_option::test_case_2 --skip malformed_option::test_case_3} %endif %if %{without test} ++++++ python-uv-0.12.23.tar.gz -> python-uv-0.12.24.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-uv/python-uv-0.12.23.tar.gz /work/SRC/openSUSE:Factory/.python-uv.new.3698736/python-uv-0.12.24.tar.gz differ: char 14, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/python-uv/vendor.tar.zst /work/SRC/openSUSE:Factory/.python-uv.new.3698736/vendor.tar.zst differ: char 7, line 1
