Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 15, 2025

Bumps astral-sh/setup-uv from 7.1.5 to 7.1.6.

Release notes

Sourced from astral-sh/setup-uv's releases.

v7.1.6 🌈 add OS version to cache key to prevent binary incompatibility

Changes

This release will invalidate your cache existing keys!

The os version e.g. ubuntu-22.04 is now part of the cache key. This prevents failing builds when a cache got populated with wheels built with different tools (e.g. glibc) than are present on the runner where the cache got restored.

🐛 Bug fixes

  • feat: add OS version to cache key to prevent binary incompatibility @​eifinger (#716)

🧰 Maintenance

⬆️ Dependency updates

Commits
  • 681c641 Bump actions/checkout from 5.0.0 to 6.0.1 (#712)
  • 2e85713 Bump actions/setup-node from 6.0.0 to 6.1.0 (#715)
  • 58b6d7b fix: add OS version to cache key to prevent binary incompatibility (#716)
  • e8b52af chore: update known checksums for 0.9.17 (#714)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Dec 15, 2025
Copy link
Member

@amrit110 amrit110 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ All checks passed. Auto-approving bot PR.

🤖 AI Engineering Maintenance Bot - Maintaining Vector Institute Repositories built by AI Engineering

@amrit110
Copy link
Member

🎉 All checks passed! This PR will be automatically merged.

🤖 AI Engineering Maintenance Bot - Maintaining Vector Institute Repositories built by AI Engineering

@amrit110
Copy link
Member

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-7.1.6 branch from 4dd522c to be03bf2 Compare December 18, 2025 05:21
@amrit110
Copy link
Member

@dependabot rebase

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 18, 2025

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@amrit110
Copy link
Member

🔧 Analyzing and fixing: run-code-check...

🤖 AI Engineering Maintenance Bot

@amrit110
Copy link
Member

🔧 Automated fix applied

Fixed unknown failures after dependency updates.

✓ Successfully fixed unknown failures - Modified 0 files - Executed 52 agent actions - (11 tool_call, 4 reasoning, 20 error, 17 info)

CI checks will re-run automatically.

📊 View detailed trace on dashboard | Raw trace

🤖 AI Engineering Maintenance Bot

@amrit110
Copy link
Member

@dependabot recreate

Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 7.1.5 to 7.1.6.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v7.1.5...v7.1.6)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 7.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/github_actions/astral-sh/setup-uv-7.1.6 branch from ec9e198 to a857e0a Compare December 18, 2025 13:24
Security update:
- Update filelock from 3.20.0 to 3.20.1 (fixes CVE GHSA-w853-jp5j-5j7f)

Severity: Critical

The vulnerability is a Time-of-Check-Time-of-Use (TOCTOU) race condition
that allows local attackers to corrupt or truncate arbitrary user files
through symlink attacks. The fix adds O_NOFOLLOW flag on Unix/Linux/macOS
and adds GetFileAttributesW API check on Windows to prevent symlink following.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <[email protected]>
@amrit110 amrit110 merged commit 4b4da2f into main Dec 19, 2025
11 checks passed
@amrit110
Copy link
Member

All checks passed! This PR will be automatically merged.

AI Engineering Maintenance Bot - Maintaining Vector Institute Repositories built by AI Engineering

@amrit110 amrit110 deleted the dependabot/github_actions/astral-sh/setup-uv-7.1.6 branch December 19, 2025 22:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants