astral-sh/uv 发布 0.12.9
uv 0.12.9 发布:支持 CPython 3.15.0rc2,新增 --no-locked/--no-frozen 标志,优化冷安装性能,修复多项安全与并发问题。
中文处理结果
发布说明
发布于 2026-09-01。
Python
增强
- 添加
--no-locked和--no-frozen标志,用于在单次调用中禁用由UV_LOCKED和UV_FROZEN启用的锁定模式(#21408) - 在警告和错误中报告确切的命令行锁定模式标志(#21402)
性能
- 通过将每个流式 ZIP 归档解压为单个阻塞任务并跨文件复用缓冲区,加速冷 wheel 安装(#21372)
错误修复
- 更新
async_http_range_reader至 0.11.1,以解决从不可信 wheel 读取元数据范围时可能存在的内存安全问题(#21401) - 当重定向跨认证领域时移除敏感头,包括更改 URL 方案的同一主机重定向(#21382)
- 从重试诊断中编辑签名 URL 中的机密,包括嵌套请求错误(#21381)
- 赋予
--locked、--frozen、--check和--check-exists优先于冲突的UV_LOCKED和UV_FROZEN值(#21396) - 防止并发 uv 进程冗余解压相同的本地或源码构建 wheel(#21400)
安装 uv 0.12.9
通过 shell 脚本安装预构建二进制
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
通过 powershell 脚本安装预构建二进制
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
下载 uv 0.12.9
原始正文
astral-sh/uv released 0.12.9
Release Notes
Released on 2026-09-01.
Python
Enhancements
- Add
--no-lockedand--no-frozento disable lock modes enabled byUV_LOCKEDandUV_FROZENfor a single invocation (#21408) - Report the exact command-line lock-mode flag in warnings and errors (#21402)
Performance
- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#21372)
Bug fixes
- Update
async_http_range_readerto 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#21401) - Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#21382)
- Redact secrets in signed URLs from retry diagnostics, including nested request errors (#21381)
- Give
--locked,--frozen,--check, and--check-existsprecedence over conflictingUV_LOCKEDandUV_FROZENvalues (#21396) - Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#21400)
Install uv 0.12.9
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
Download uv 0.12.9
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>