astral-sh/uv 发布 0.12.12
uv 0.12.12 发布:macOS 与 Windows 可执行文件及 uv、uv_build wheel 现已代码签名,并修复 exclude-newer 相关缺陷。
中文处理结果
发布说明
发布于 2026-09-09。
我们 macOS 和 Windows 发布归档中的可执行文件,以及 uv 和 uv_build wheel,现在都已进行代码签名。macOS 可执行文件使用 Apple Developer ID 证书签名,并经过 Apple 公证。Windows 可执行文件带有来自 Azure Artifact Signing 的带时间戳的 Authenticode 签名。这样可以验证发布者和二进制完整性,支持基于发布者的允许列表,并应能减少安全警告和杀毒软件误报。
缺陷修复
- 将
exclude-newer截止时间之后上传的发行版排除在锁文件和生成的需求哈希之外(#21539)
安装 uv 0.12.12
通过 shell 脚本安装预编译二进制
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
通过 powershell 脚本安装预编译二进制
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
下载 uv 0.12.12
原始正文
astral-sh/uv released 0.12.12
Release Notes
Released on 2026-09-09.
The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.
Bug fixes
- Exclude distributions uploaded after the
exclude-newercutoff from lockfiles and generated requirement hashes (#21539)
Install uv 0.12.12
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
Download uv 0.12.12
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>