astral-sh/uv 发布 0.12.8
uv 0.12.8 发布:增强工具升级警告,预览内容寻址缓存,多项性能优化和错误修复。
中文处理结果
发布说明
发布于 2026-08-31。
增强
- 使用
uv tool upgrade --all时,警告无效工具目录并继续升级有效工具 (#21368)
预览功能
- 使用
content-addressed-cache预览功能,在缓存 wheel 内和跨 wheel 去重相同文件 (#21327) - 通过跨文件重用哈希缓冲区,减少提取内容寻址 wheel 时的分配 (#21340)
- 通过批量读取硬链接计数,加速 macOS 上内容寻址缓存清理 (#21344)
性能
- 防止并发 uv 进程多次下载和提取同一远程 wheel (#21379)
- 通过在遍历期间索引包,加速大型锁文件的依赖图构建 (#21373)
- 将索引锁文件遍历扩展到导出、依赖树、审计和新鲜度检查 (#21377)
- 通过减少重复的标记 interner 工作,加速热解析 (#21300)
错误修复
- 使用
--require-hashes安装时,不信任仅从 wheel 元数据中发现的直接 URL 的哈希 (#21348) - 使用兼容的 Azure 存储 API 版本进行匿名和认证请求,允许在公共访问禁用时进行凭据重试 (#21366)
- 从显示的 URL 中编辑 Azure 共享访问签名(
sig)查询参数 (#21360) - 将一级工作区成员 glob 下的项目视为独立项目,而不是中止工作区发现 (#21341)
其他更改
- 更新
astral-tokio-tar至 0.7.0,并在跟踪提取的硬链接时使用有效大小 (#21346)
安装 uv 0.12.8
通过 shell 脚本安装预构建二进制
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.sh | sh
通过 powershell 脚本安装预构建二进制
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.ps1 | iex"
下载 uv 0.12.8
原始正文
astral-sh/uv released 0.12.8
Release Notes
Released on 2026-08-31.
Enhancements
- Warn about invalid tool directories and continue upgrading valid tools with
uv tool upgrade --all(#21368)
Preview features
- Deduplicate identical files within and across cached wheels with the
content-addressed-cachepreview feature (#21327) - Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files (#21340)
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk (#21344)
Performance
- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once (#21379)
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal (#21373)
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks (#21377)
- Speed up warm resolutions by reducing repeated marker interner work (#21300)
Bug fixes
- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with
--require-hashes(#21348) - Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled (#21366)
- Redact Azure shared access signature (
sig) query parameters from displayed URLs (#21360) - Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery (#21341)
Other changes
- Update
astral-tokio-tarto 0.7.0 and use effective sizes when tracking extracted hard links (#21346)
Install uv 0.12.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.ps1 | iex"
Download uv 0.12.8
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>