Skip to content

chore(deps): Bump astral-sh/setup-uv from 8.2.0 to 9.0.0 - #84

Merged
CryptoJones merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0
Aug 2, 2026
Merged

CryptoJones merged 1 commit into
mainfrom
dependabot/github_actions/astral-sh/setup-uv-9.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps astral-sh/setup-uv from 8.2.0 to 9.0.0.

Release notes

Sourced from astral-sh/setup-uv's releases.

v9.0.0 🌈 Change prune-cache default to false

Changes

This release disables the default cache cache pruning to ease the load on the PyPi infrastructure. Since users might experience more GitHub Actions cache usage which might result in higher costs this is marked as a breaking change. To read more on why we did this (now) you can read the detailed analysis and reasoning in #967

Besides this big breaking change we also have a small bugfix while building caches for linux distributions that behave a big different than the "big ones" and a speed up in version resolution by only reading the version manifest until a matching version is found saving runtime and network bandwith.

🚨 Breaking changes

🐛 Bug fixes

  • fix: fall back to distribution ID when os-release has no version field @​cxzhong (#961)

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits
  • c771a70 chore(deps): roll up Dependabot updates (#970)
  • 2f537ca chore: update known checksums for 0.11.30 (#968)
  • 2269552 Speed up version client by partial response reads (#807)
  • 47a7f4f Change prune-cache default to false (#967)
  • 71966ef chore(deps): roll up Dependabot updates (#962)
  • f12b1f0 fix: fall back to distribution ID when os-release has no version field (#961)
  • ecd24dd chore: update known checksums for 0.11.29 (#960)
  • 6a19136 docs: update version references to v8.3.2 (#949)
  • 11f9893 chore: roll up Dependabot updates (#948)
  • f798556 docs: update version references to v8.3.1 (#946)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.2.0 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@fac544c...c771a70)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 24, 2026
@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated the tooling used by automated quality checks and security validation.
    • Existing linting, type checking, testing, conformance, installation, and security workflows remain unchanged.

Walkthrough

The CI workflow updates the pinned astral-sh/setup-uv action from v8.2.0 to v9.0.0 in the lint, typecheck, test, conformance, core-install, and security jobs.

Changes

CI uv setup

Layer / File(s) Summary
Update setup-uv pins
.github/workflows/ci.yml
The six CI jobs use the pinned v9.0.0 setup-uv action; subsequent job logic remains unchanged.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Suggested reviewers: cryptojones

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the dependency bump from setup-uv 8.2.0 to 9.0.0.
Description check ✅ Passed The description directly matches the change and provides relevant release notes for the upgrade.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/astral-sh/setup-uv-9.0.0

Comment @coderabbitai help to get the list of available commands.

@coderabbitai
coderabbitai Bot requested a review from CryptoJones July 24, 2026 14:06

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Line 30: Set prune-cache: true on every cached setup-uv step in
.github/workflows/ci.yml at lines 30, 48, 68, 94, 120, and 150, preserving cache
pruning consistently across all CI jobs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f4d16683-eee4-410d-bbc8-5935e0bfe2d5

📥 Commits

Reviewing files that changed from the base of the PR and between 6feb38c and 54f20f8.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: Test (py3.12)
  • GitHub Check: Analyze (python)
  • GitHub Check: Core install (no tui extra)

Comment thread .github/workflows/ci.yml
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Install uv
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀 Performance & Scalability | 🔵 Trivial

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Workflow uses =="
rg -n 'astral-sh/setup-uv@|enable-cache|prune-cache' .github/workflows/ci.yml

echo
echo "== Relevant workflow slice =="
cat -n .github/workflows/ci.yml | sed -n '1,220p'

Repository: CryptoJones/PerplexityAgent

Length of output: 8961


🌐 Web query:

astral-sh setup-uv v9.0.0 prune-cache default false release notes

💡 Result:

The release of setup-uv v9.0.0 introduced a significant breaking change by setting the default value for the prune-cache input to false [1]. Previously, this setting defaulted to true, which caused the action to prune pre-built wheels from the cache after every run, leading to unnecessary re-downloads from the PyPI infrastructure [2][1]. By changing the default to false, the setup-uv action now preserves the cache by default to reduce load on PyPI, though this may result in higher GitHub Actions cache usage for users [1]. This change was explicitly made to address inefficiencies in CI workflows where pre-built wheels were being discarded and re-downloaded repeatedly [2][1]. Users should be aware that this change is considered breaking because it alters resource consumption patterns in CI environments [1].

Citations:


Preserve or explicitly set prune-cache on the setup-uv steps.

v9.0.0 now defaults prune-cache to false, so these jobs will retain more cache data unless you opt back into pruning. If that increased cache usage is unintended, set prune-cache: true on each cached setup-uv step.

📍 Affects 1 file
  • .github/workflows/ci.yml#L30-L30 (this comment)
  • .github/workflows/ci.yml#L48-L48
  • .github/workflows/ci.yml#L68-L68
  • .github/workflows/ci.yml#L94-L94
  • .github/workflows/ci.yml#L120-L120
  • .github/workflows/ci.yml#L150-L150
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml at line 30, Set prune-cache: true on every cached
setup-uv step in .github/workflows/ci.yml at lines 30, 48, 68, 94, 120, and 150,
preserving cache pruning consistently across all CI jobs.

@CryptoJones
CryptoJones merged commit 1136a0b into main Aug 2, 2026
25 of 31 checks passed
@CryptoJones
CryptoJones deleted the dependabot/github_actions/astral-sh/setup-uv-9.0.0 branch August 2, 2026 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant