Release Notes
Released on 2026-09-17.
Python
- Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#21741)
Enhancements
- Verify downloaded wheels and source distributions against hashes supplied by package indexes (#21562)
- Allow
build-constraint-dependenciesentries to include hashes for verifying downloaded build dependencies (#21467) - Honor Darwin
platform_releasemarkers inrequired-environmentsusing macOS wheel deployment targets (#21766) - Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#21779)
Preview features
- Support
lock-without-metadataacross all dependency types while retainingpackage.metadatafor remote URL dependencies to enable offline validation (#21163) - Honor configured and command-line index settings, including credentials, in
uv upgrade(#21776) - Allow
uv checkto run in projects that are not managed by uv and outside workspaces (#21777) - Respect
--pythonandUV_PYTHONwhen selecting the Python version foruv check(#21744)
Bug fixes
- Redact Azure shared access signatures from displayed and logged URLs (#21755)
- Check archive sizes from
pylock.tomlbefore reusing cached distributions (#21609) - Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths (#20631)
- Use the bundled
uv_buildbackend only when its version matches active version pins (#21742) - Handle malformed index URLs without panicking when credentials are configured (#21784)
- Report a configuration error instead of panicking for proxy URLs without a host (#21781)
- Return a credential-redacted error instead of panicking when a URL cannot be converted to a path (#21783)
Install uv 0.12.16
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.ps1 | iex"Download uv 0.12.16
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>