Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-uv for openSUSE:Factory checked in at 2026-09-29 17:52:48 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-uv (Old) and /work/SRC/openSUSE:Factory/.python-uv.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-uv" Tue Sep 29 17:52:48 2026 rev:128 rq:1381348 version:0.12.20 Changes: -------- --- /work/SRC/openSUSE:Factory/python-uv/python-uv.changes 2026-09-28 10:44:13.791365004 +0200 +++ /work/SRC/openSUSE:Factory/.python-uv.new.383539/python-uv.changes 2026-09-29 17:54:48.268795436 +0200 @@ -1,0 +2,35 @@ +Tue Sep 29 07:41:14 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 0.12.20: + * Reuse lockfiles when dependency declarations are semantically + equivalent + * Restore the previous HTTP cache-write scheduling: the batched + writes added in 0.12.15 caused severe cache-revalidation stalls + on ext4 + * Apply --require-hashes and --verify-hashes to every repeated + requirement instead of only the first + * Restore pyproject.toml if uv upgrade fails or is interrupted + * No longer panic on an always-false constraint while trace + logging, on whitespace-only non-ASCII requirements, on + unrecognized managed Python implementation directories or on + managed Python sysconfig paths that merely start with /install; + a UTF-16 requirements file holding only a byte-order mark now + counts as empty + * Preserve second-line encoding declarations in wheel scripts + with CRLF shebangs, and keep searching XDG_CONFIG_DIRS after + empty entries + * --no-build can build metadata for first-party workspace + projects, and --all-packages honors the project exclusion + flags + * Preview features around pylock.toml, lockfile normalization + and tool-install-locks + * Many more fixes and improvements; see upstream's release notes + for the full list +- Refresh the vendored dependencies (tokio-rustls 0.26.5 -> + 0.26.6, zerocopy and zerocopy-derive 0.8.58 -> 0.8.59; all + three are linked into the binary), the licence set is unchanged +- Not affected by CVE-2026-25800 (boo#1273366, boo#1273367): + quinn and quinn-proto are vendored but not linked into the + shipped binary, as uv builds reqwest without its http3 feature + +------------------------------------------------------------------- Old: ---- python-uv-0.12.19.tar.gz New: ---- python-uv-0.12.20.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-uv.spec ++++++ --- /var/tmp/diff_new_pack.PZlvTz/_old 2026-09-29 17:54:52.224960610 +0200 +++ /var/tmp/diff_new_pack.PZlvTz/_new 2026-09-29 17:54:52.227960735 +0200 @@ -36,7 +36,7 @@ %global build_rustflags -C linker=clang -C link-arg=-fuse-ld=%{_bindir}/mold -C link-arg=-Wl,-z,relro,-z,now -C debuginfo=2 -C incremental=false -C strip=none %endif Name: %{origname}%{psuffix} -Version: 0.12.19 +Version: 0.12.20 Release: 0 Summary: A Python package installer and resolver, written in Rust # Legal-Review-Notice: uv itself is "Apache-2.0 OR MIT", but the binary ++++++ python-uv-0.12.19.tar.gz -> python-uv-0.12.20.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-uv/python-uv-0.12.19.tar.gz /work/SRC/openSUSE:Factory/.python-uv.new.383539/python-uv-0.12.20.tar.gz differ: char 22, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/python-uv/vendor.tar.zst /work/SRC/openSUSE:Factory/.python-uv.new.383539/vendor.tar.zst differ: char 7, line 1
