Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-uv for openSUSE:Factory 
checked in at 2026-10-09 21:45:49
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-uv (Old)
 and      /work/SRC/openSUSE:Factory/.python-uv.new.3698736 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-uv"

Fri Oct  9 21:45:49 2026 rev:132 rq:1383704 version:0.12.24

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-uv/python-uv.changes      2026-10-05 
13:01:52.659459196 +0200
+++ /work/SRC/openSUSE:Factory/.python-uv.new.3698736/python-uv.changes 
2026-10-09 21:46:46.365825846 +0200
@@ -1,0 +2,29 @@
+Fri Oct  9 07:14:27 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to 0.12.24:
+  * `uv cache prune` removes orphaned temporary build environments
+  * Accept PEP 508 marker operators before grouped expressions;
+    reject malformed requirements-file options instead of ignoring
+    them
+  * Managed Python: honour exact patch pins in script environments,
+    custom GraalPy/Pyodide mirrors, clearer uninstall errors
+  * Preview: `uv audit` prefers PYSEC, then GHSA, then CVE IDs
+  * UV_NO_CACHE/UV_OFFLINE/UV_SYSTEM_CERTS=false now override the
+    config file; explicit --trusted-publishing wins over config
+  * Verify supplied hashes even with require-hashes disabled;
+    overrides no longer pull unselected optional deps; IPv6 loopback
+    for `uv auth login`; GitHub refs with `#`/`%`
+  * Many more fixes and improvements; see upstream's release notes
+    for the full list
+- Refresh the vendored dependencies: async-compression 0.4.19 ->
+  0.4.50 (split out compression-codecs/core), astral-html 0.0.3
+  replaces astral-tl and html-escape, smallvec 1.15.2 -> 1.16.2,
+  tokio-rustls 0.26.4 -> 0.26.6 and fs-err 3.3.1 -> 3.3.2 are all
+  linked into the binary; the linked graph grows to 525 nodes (was
+  509) and the licence set is unchanged
+  * CVE-2026-92987 (boo#1281170): roxmltree is vendored but not
+    linked into the shipped binary, so this package is not affected
+- Upstream MSRV is still Rust 1.97, so BuildRequires on cargo is
+  unchanged
+
+-------------------------------------------------------------------

Old:
----
  python-uv-0.12.23.tar.gz

New:
----
  python-uv-0.12.24.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-uv.spec ++++++
--- /var/tmp/diff_new_pack.MLqTYO/_old  2026-10-09 21:46:51.837056072 +0200
+++ /var/tmp/diff_new_pack.MLqTYO/_new  2026-10-09 21:46:51.840056198 +0200
@@ -36,13 +36,13 @@
 %global build_rustflags -C linker=clang -C link-arg=-fuse-ld=%{_bindir}/mold 
-C link-arg=-Wl,-z,relro,-z,now -C debuginfo=2 -C incremental=false -C 
strip=none
 %endif
 Name:           %{origname}%{psuffix}
-Version:        0.12.23
+Version:        0.12.24
 Release:        0
 Summary:        A Python package installer and resolver, written in Rust
 # Legal-Review-Notice: uv itself is "Apache-2.0 OR MIT", but the binary
 # statically links the vendored Rust dependencies. Re-derived on this
 # re-vendor with "cargo tree --offline -p uv -e normal" over the vendored
-# tree (509 unique name-version nodes); the copyleft licences in the linked 
graph are:
+# tree (525 unique name-version nodes); the copyleft licences in the linked 
graph are:
 #  - MPL-2.0 from astral-pubgrub, astral-version-ranges and option-ext
 #    (the last via shellexpand -> dirs -> dirs-sys),
 #  - priority-queue, which is "LGPL-3.0-or-later OR MPL-2.0" - we elect
@@ -217,11 +217,15 @@
 # nothing, so the spawn fails outright - and would then resolve a
 # Python interpreter and its dependencies over the network. The other
 # nine uv-extract tests, including the rest of the dirhash suite, still
-# run.
+# run. uv-requirements-txt's malformed_option cases 2-3 are the same
+# insta-in-one-process limitation as uv-build-backend above, new in
+# 0.12.24 with the malformed-requirements-option rejections: three
+# #[test_case]s share one inline snapshot, so the first passes and the
+# rest panic before comparing anything. Case 1 still runs.
 #
 # The leading "--" is required: %%cargo_test is a parametrised macro, so
 # without it rpm parses "--workspace" as a macro option and aborts.
-%{cargo_test -- --workspace --exclude uv --exclude uv-dev --exclude 
uv-build-backend -- --test-threads=1 --skip 
user_agent_version::test_user_agent_has_linehaul --skip 
dirhash::tests::test_vectors_json}
+%{cargo_test -- --workspace --exclude uv --exclude uv-dev --exclude 
uv-build-backend -- --test-threads=1 --skip 
user_agent_version::test_user_agent_has_linehaul --skip 
dirhash::tests::test_vectors_json --skip malformed_option::test_case_2 --skip 
malformed_option::test_case_3}
 %endif
 
 %if %{without test}

++++++ python-uv-0.12.23.tar.gz -> python-uv-0.12.24.tar.gz ++++++
/work/SRC/openSUSE:Factory/python-uv/python-uv-0.12.23.tar.gz 
/work/SRC/openSUSE:Factory/.python-uv.new.3698736/python-uv-0.12.24.tar.gz 
differ: char 14, line 1

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/python-uv/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.python-uv.new.3698736/vendor.tar.zst differ: char 
7, line 1

Reply via email to