astral-sh/uv 发布 0.11.33
uv 0.11.33 发布,增强减小二进制体积、Pyodide 安装优化;预览功能包括 uv check 脚本检查、恶意软件检查;修复依赖拆分、exclude-newer 解析等 Bug。
中文处理结果
发布说明
发布于 2026-07-28。
增强
预览功能
- 除非传递
--script,否则uv check中不检查任何脚本 (#20676) - 在缓存复用前检查锁定的工具是否存在恶意软件 (#20301)
- 写入和读取不含
package.metadata的锁定文件 (#20688, #20691, #20685, #20695)
Bug 修复
安装 uv 0.11.33
通过 shell 脚本安装预构建二进制
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.sh | sh
通过 powershell 脚本安装预构建二进制
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.ps1 | iex"
下载 uv 0.11.33
原始正文
astral-sh/uv released 0.11.33
Release Notes
Released on 2026-07-28.
Enhancements
- Abort panics in release builds for smaller uv binaries (#20271)
- Use
.tar.gzarchives for Pyodide installs (#20667)
Preview features
- Avoid checking any scripts in
uv checkunless--scriptis passed (#20676) - Check locked tools for malware before cache reuse (#20301)
- Write and read
package.metadata-free lockfiles (#20688, #20691, #20685, #20695)
Bug fixes
- Correctly split dependencies into production and optional markers (#20671)
- Fix discrepancies in argument parsing of exclude-newer (#20679)
- Cleanup managed Python temporary directory on error (#20752)
Install uv 0.11.33
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.ps1 | iex"
Download uv 0.11.33
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>