0.12.10
Added 1
- Attempt to revoke short-lived PyPI trusted-publishing tokens after uv publish completes, including when publishing fails
Changed 4
- Omit exclude-newer-package settings for packages outside the resolution from uv.lock with the missing-exclude-newer-package-lock preview feature
- Show terminal dependency cycles in uv tree --invert output
- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification
- Speed up uv publish by hashing each artifact in a single blocking task and reusing the buffer across reads
Fixed 5
- Prevent --locked from failing when exclude-newer-package settings differ only for packages outside the resolution
- Allow uv lock --check to reuse a lockfile when an absolute exclude-newer cutoff is moved later
- Allow uv lock --check to reuse a lockfile when a package-specific exclude-newer cutoff is disabled
- Require an explicit --name when uv init would infer a project name reserved for a Python interpreter
- Write package-specific exclude-newer cutoffs to uv.lock in a deterministic order
From uv
Release Notes
Released on 2026-09-04.
Enhancements
- Attempt to revoke short-lived PyPI trusted-publishing tokens after
uv publishcompletes, including when publishing fails (#21423)
Preview features
- Omit
exclude-newer-packagesettings for packages outside the resolution fromuv.lockwith themissing-exclude-newer-package-lockpreview feature (#21455) - Show terminal dependency cycles in
uv tree --invertoutput (#21404)
Performance
- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification (#21399)
- Speed up
uv publishby hashing each artifact in a single blocking task and reusing the buffer across reads (#21389)
Bug fixes
- Prevent
--lockedfrom failing whenexclude-newer-packagesettings differ only for packages outside the resolution (#21454) - Allow
uv lock --checkto reuse a lockfile when an absoluteexclude-newercutoff is moved later (#19571) - Allow
uv lock --checkto reuse a lockfile when a package-specificexclude-newercutoff is disabled (#21450) - Require an explicit
--namewhenuv initwould infer a project name reserved for a Python interpreter (#21395) - Write package-specific
exclude-newercutoffs touv.lockin a deterministic order (#21453)
Install uv 0.12.10
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.ps1 | iex"
Download uv 0.12.10
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>