Release Notes
Released on 2026-09-28.
Enhancements
- Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
- Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)
Preview features
- Write normalized requirement declarations with the
lockfile-normalizationpreview feature (#21951) - Honor synthetic default groups when installing or syncing from
pylock.toml(#22003) - Resolve local paths in exported
pylock.tomlfiles relative to the output file (#22042) - Install each package only once when repeated
tool-install-locksrequirements resolve to the same package (#22000) - Reuse
lock-without-metadatalockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055) - Use consistent root-package paths in
uv workspace metadataanduv tree --format jsonoutput (#22050)
Configuration
- Continue searching
XDG_CONFIG_DIRSafter empty entries (#21987)
Performance
- Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)
Bug fixes
- Apply hash constraints to every repeated requirement under
--require-hashesand--verify-hashes(#21996) - Allow metadata builds for first-party workspace projects under
--no-build(#21988) - Honor project exclusion flags with
--all-packages, including--no-install-projectand--no-emit-project(#21994) - Restore
pyproject.tomlifuv upgradefails or is interrupted (#21983) - Generate working Nushell activation scripts for relocatable virtual environments (#21979)
- Prevent commands from running and changing state after displaying
--show-settings(#21989) - Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
- Ignore unrecognized managed-Python implementation directories during
uv python listanduv python upgradeinstead of panicking (#22033) - Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with
/install(#22036) - Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
- Avoid a resolver panic when trace logging an always-false constraint (#22034)
Install uv 0.12.20
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.ps1 | iex"Download uv 0.12.20
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>