Release Notes
Released on 2026-08-31.
Enhancements
- Warn about invalid tool directories and continue upgrading valid tools with
uv tool upgrade --all(#21368)
Preview features
- Deduplicate identical files within and across cached wheels with the
content-addressed-cachepreview feature (#21327) - Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files (#21340)
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk (#21344)
Performance
- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once (#21379)
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal (#21373)
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks (#21377)
- Speed up warm resolutions by reducing repeated marker interner work (#21300)
Bug fixes
- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with
--require-hashes(#21348) - Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled (#21366)
- Redact Azure shared access signature (
sig) query parameters from displayed URLs (#21360) - Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery (#21341)
Other changes
- Update
astral-tokio-tarto 0.7.0 and use effective sizes when tracking extracted hard links (#21346)
Install uv 0.12.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.ps1 | iex"Download uv 0.12.8
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>