Release Notes
Released on 2026-10-08.
Enhancements
- Remove orphaned temporary build environments with
uv cache prune(#22171) - Accept PEP 508 marker operators directly before grouped expressions (#22309)
- Reject malformed requirements-file options instead of partially parsing or ignoring them (#22317)
- Show underlying filesystem and registry errors when managed Python uninstallation fails (#22362)
- Identify the invalid source URL in Python mirror errors (#22364)
Preview features
- Display preferred advisory IDs in
uv auditreports, prioritizing PYSEC, GHSA, then CVE identifiers (#22292)
Configuration
- Support custom installation mirrors for GraalPy (#22269)
- Support custom installation mirrors for Pyodide (#22271)
- Allow
UV_NO_CACHE=falseto overrideno-cache = truein configuration (#22324) - Report more precise error locations for invalid trusted-host ports and preview-feature list entries (#22144)
Performance
- Speed up later commands after creating an environment by warming its interpreter cache (#21304)
- Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages (#22246)
- Enforce resource limits when parsing package indexes and
--find-linkspages withastral-html(#22203) - Reduce standalone
uv-buildexecutable size by 7.5% by omitting unused Zstandard support (#22242) - Reduce uv's binary size by about 232 KB by simplifying configuration deserialization (#22144)
- Reduce Python download error formatting code size by sharing its formatter (#22141)
Bug fixes
- Verify supplied hashes even when hash presence is disabled with
--no-require-hashesorrequire-hashes = false(#22369) - Honor exact managed Python patch pins when creating script environments instead of following patch upgrades (#22360)
- Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected (#22237)
- Exclude optional dependencies from exports when their extras are activated only in incompatible environments (#22234)
- Give explicit
uv publish --trusted-publishingvalues precedence over configuration (#22279) - Allow
UV_OFFLINE=falseto overrideoffline = truein configuration (#22283) - Allow
UV_SYSTEM_CERTS=falseto overridesystem-certs = truein configuration (#22291) - Allow
uv auth loginover IPv6 loopback addresses (#22306) - Resolve GitHub dependencies whose Git references contain
#or%characters (#22281) - Recognize existing Pyodide interpreters as satisfying Pyodide Python requests (#22322)
- Preserve JSON output from
uv versionanduv self versionwith a single--quietflag (#22280) - Preserve trailing spaces and tabs in passwords returned by subprocess keyrings (#22284)
- Restore wheel incompatibility hints when
WHEELmetadata contains multiple expandedTag:rows (#22235) - Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies (#22302)
- Prevent workspace-cache assertion failures after modifying a project at the workspace root (#22236)
- Hide the ignored
--keyring-provideroption fromuv authhelp (#19520) - Report HTTP client setup failures directly when resolving unnamed
uv toolrequirements (#22320)
Documentation
- Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests (#22172)
- Fix stale links and descriptions in Rust crate documentation (#22311, #22361)
- Fix a typo in the
required-environmentsdocumentation (#22238)
Install uv 0.12.24
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"Download uv 0.12.24
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>