Skip to content

build(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.2 - #1430

Merged
Czaki merged 4 commits into
developfrom
dependabot/github_actions/develop/astral-sh/setup-uv-8.3.2
Jul 31, 2026
Merged

build(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.2#1430
Czaki merged 4 commits into
developfrom
dependabot/github_actions/develop/astral-sh/setup-uv-8.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 8.3.0 to 8.3.2.

Commits
  • 11f9893 chore: roll up Dependabot updates (#948)
  • f798556 docs: update version references to v8.3.1 (#946)
  • e80544d chore: update known checksums for 0.11.28 (#947)
  • f98e069 Change update-docs PR labels from 'update-docs' to 'documentation' (#945)
  • cd46263 chore: update known checksums for 0.11.27 (#944)
  • 11245c7 docs: update version references to v8.3.0 (#939)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.0 to 8.3.2.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v8.3.0...v8.3.2)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 20, 2026
@codecov

codecov Bot commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.58%. Comparing base (3df1223) to head (cf0c0d7).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #1430   +/-   ##
========================================
  Coverage    92.58%   92.58%           
========================================
  Files          211      211           
  Lines        33224    33224           
========================================
  Hits         30760    30760           
  Misses        2464     2464           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Czaki Czaki added the skip check PR title skip spellcheking PR title label Jul 27, 2026
@Czaki Czaki added this to the 0.17.1 milestone Jul 27, 2026
Comment thread .github/workflows/test_prereleases.yml Outdated
- uses: actions/checkout@v6.0.2
- name: Install the latest version of uv
uses: astral-sh/setup-uv@v8.3.0
uses: astral-sh/setup-uv@v8.3.2

@semgrep-app semgrep-app Bot Jul 28, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608.

🚀 Fixed in commit cf0c0d7 🚀

Comment thread .github/workflows/test_prereleases.yml Outdated
Co-authored-by: Grzegorz Bokota <bokota+github@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

@Czaki
Czaki merged commit 10bdb93 into develop Jul 31, 2026
59 checks passed
@Czaki
Czaki deleted the dependabot/github_actions/develop/astral-sh/setup-uv-8.3.2 branch July 31, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code skip check PR title skip spellcheking PR title

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant