uv 0.11.33

0.11.33
Added 1
  • Check locked tools for malware before cache reuse
Changed 4
  • Abort panics in release builds for smaller uv binaries
  • Use .tar.gz archives for Pyodide installs
  • Avoid checking any scripts in uv check unless --script is passed
  • Write and read package.metadata-free lockfiles
Fixed 3
  • Correctly split dependencies into production and optional markers
  • Fix discrepancies in argument parsing of exclude-newer
  • Cleanup managed Python temporary directory on error
Release Notes

Released on 2026-07-28.

Enhancements
  • Abort panics in release builds for smaller uv binaries (#20271)
  • Use .tar.gz archives for Pyodide installs (#20667)
Preview features
  • Avoid checking any scripts in uv check unless --script is passed (#20676)
  • Check locked tools for malware before cache reuse (#20301)
  • Write and read package.metadata-free lockfiles (#20688, #20691, #20685, #20695)
Bug fixes
  • Correctly split dependencies into production and optional markers (#20671)
  • Fix discrepancies in argument parsing of exclude-newer (#20679)
  • Cleanup managed Python temporary directory on error (#20752)
Install uv 0.11.33
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.ps1 | iex"
Download uv 0.11.33
FilePlatformChecksum
uv-aarch64-apple-darwin.tar.gzApple Silicon macOSchecksum
uv-x86_64-apple-darwin.tar.gzIntel macOSchecksum
uv-aarch64-pc-windows-msvc.zipARM64 Windowschecksum
uv-i686-pc-windows-msvc.zipx86 Windowschecksum
uv-x86_64-pc-windows-msvc.zipx64 Windowschecksum
uv-aarch64-unknown-linux-gnu.tar.gzARM64 Linuxchecksum
uv-i686-unknown-linux-gnu.tar.gzx86 Linuxchecksum
uv-powerpc64le-unknown-linux-gnu.tar.gzPPC64LE Linuxchecksum
uv-riscv64gc-unknown-linux-gnu.tar.gzRISCV Linuxchecksum
uv-s390x-unknown-linux-gnu.tar.gzS390x Linuxchecksum
uv-x86_64-unknown-linux-gnu.tar.gzx64 Linuxchecksum
uv-armv7-unknown-linux-gnueabihf.tar.gzARMv7 Linuxchecksum
uv-aarch64-unknown-linux-musl.tar.gzARM64 MUSL Linuxchecksum
uv-i686-unknown-linux-musl.tar.gzx86 MUSL Linuxchecksum
uv-riscv64gc-unknown-linux-musl.tar.gzRISCV MUSL Linuxchecksum
uv-x86_64-unknown-linux-musl.tar.gzx64 MUSL Linuxchecksum
uv-arm-unknown-linux-musleabihf.tar.gzARMv6 MUSL Linux (Hardfloat)checksum
uv-armv7-unknown-linux-musleabihf.tar.gzARMv7 MUSL Linuxchecksum
Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
View original

Upgraded? How did it go?

Discussion