Skip to content

Tags: DiamondLightSource/python-copier-template

Tags

5.4.0

Toggle 5.4.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(deps): update astral-sh/setup-uv action to v10 (#369)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v9.0.0` → `v10.0.0` |

---

### Release Notes

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

###
[`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0):
🌈 Disable automatic caching for sensitive events and new QOL features

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0)

##### Changes

Another breaking release, directly after v9.0.0 but we think the added
security justifies that.

##### Extra security by default

If you use the default `enable-cache: auto` this will now **DISABLE THE
CACHE** to protect against cache poisoning for the following events:

- `pull_request_target`
- `workflow_run`
- `release`

You can read the full reasoning in
[#&#8203;984](https://redirect.github.com/astral-sh/setup-uv/issues/984)

##### `version: latest-known`

```yaml
- name: Install the latest version of uv known to setup-uv
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version: "latest-known"
```

This will now install the latest version with a checksum that is known
by this action. The [known `uv`
checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts)
are automatically updated but will take a release of this action to take
effect. You won't be always using the latest & greatest but you will
have an extra level of security.

##### Read python version from `.tool-versions`

```yaml
- name: Install uv based on the version defined in .tool-versions and also set python
  uses: astral-sh/setup-uv@v10.0.0
  with:
    version-file: "pyproject.toml"
```

Will now also set the python version if it is defined in
`.tool-versions`. You can read the details [in the
docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)

##### 🚨 Breaking changes

- Disable automatic caching for sensitive events
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;992](https://redirect.github.com/astral-sh/setup-uv/issues/992))

##### 🐛 Bug fixes

- Reject paths in .tool-versions
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007))

##### 🚀 Enhancements

- Read Python version from .tool-versions
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;996](https://redirect.github.com/astral-sh/setup-uv/issues/996))
- Add latest-known version selector
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;993](https://redirect.github.com/astral-sh/setup-uv/issues/993))

##### 🧰 Maintenance

- Require pull requests for Dependabot rollups
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005))
- ci: pin Alpine container image
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;995](https://redirect.github.com/astral-sh/setup-uv/issues/995))
- chore: update known checksums for 0.12.3
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;991](https://redirect.github.com/astral-sh/setup-uv/issues/991))
- chore: update known checksums for 0.12.2
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;985](https://redirect.github.com/astral-sh/setup-uv/issues/985))
- chore: update known checksums for 0.12.1
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;982](https://redirect.github.com/astral-sh/setup-uv/issues/982))
- chore: update known checksums for 0.12.0
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;981](https://redirect.github.com/astral-sh/setup-uv/issues/981))
- chore: update known checksums for 0.11.31/0.11.32
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;972](https://redirect.github.com/astral-sh/setup-uv/issues/972))

##### 📚 Documentation

- docs: update version references to v9.0.0
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;971](https://redirect.github.com/astral-sh/setup-uv/issues/971))

##### ⬆️ Dependency updates

- chore(deps): roll up Dependabot updates
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013))
- chore(deps): roll up Dependabot updates
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004))
- chore(deps): roll up Dependabot updates
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;994](https://redirect.github.com/astral-sh/setup-uv/issues/994))
- chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0
@&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
([#&#8203;976](https://redirect.github.com/astral-sh/setup-uv/issues/976))
- chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
@&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
([#&#8203;980](https://redirect.github.com/astral-sh/setup-uv/issues/980))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

5.3.0

Toggle 5.3.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(deps): update codecov/codecov-action action to v7 (#355)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[codecov/codecov-action](https://redirect.github.com/codecov/codecov-action)
| action | major | `v5` → `v7` |

---

### Release Notes

<details>
<summary>codecov/codecov-action (codecov/codecov-action)</summary>

###
[`v7.0.0`](https://redirect.github.com/codecov/codecov-action/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v7.0.0...v7.0.0)

⚠️ Due to migration issues with keybase, we are unable to update our
keys under the `codecovsecurity` account. We have deleted the account
and are using `codecovsecops` with the original gpg key

##### What's Changed

- ci: remove Enforce License Compliance workflow by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1950](https://redirect.github.com/codecov/codecov-action/pull/1950)
- chore(release): 7.0.0 by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1957](https://redirect.github.com/codecov/codecov-action/pull/1957)

**Full Changelog**:
<codecov/codecov-action@v6.0.1...v7.0.0>

###
[`v7`](https://redirect.github.com/codecov/codecov-action/compare/v6.0.2...v7.0.0)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v6.0.2...v7.0.0)

###
[`v6.0.2`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.2)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v6.0.1...v6.0.2)

This is a copy of the `v7.0.0` release to make updates easier

##### What's Changed

- ci: remove Enforce License Compliance workflow by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1950](https://redirect.github.com/codecov/codecov-action/pull/1950)
- chore(release): 7.0.0 by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1957](https://redirect.github.com/codecov/codecov-action/pull/1957)

**Full Changelog**:
<codecov/codecov-action@v6.0.1...v6.0.2>

###
[`v6.0.1`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.1)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v6...v6.0.1)

##### What's Changed

- fix: prevent template injection in run: steps (VULN-1652) by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1947](https://redirect.github.com/codecov/codecov-action/pull/1947)
- chore(release): 6.0.1 by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1949](https://redirect.github.com/codecov/codecov-action/pull/1949)

**Full Changelog**:
<codecov/codecov-action@v6.0.0...v6.0.1>

###
[`v6.0.0`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v6...v6)

##### ⚠️ This version introduces support for node24 which make cause
breaking changes for systems that do not currently support node24. ⚠️

##### What's Changed

- Revert "Revert "build(deps): bump actions/github-script from 7.0.1 to
8.0.0"" by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1929](https://redirect.github.com/codecov/codecov-action/pull/1929)
- Th/6.0.0 by
[@&#8203;thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov)
in
[#&#8203;1928](https://redirect.github.com/codecov/codecov-action/pull/1928)

**Full Changelog**:
<codecov/codecov-action@v5.5.4...v6.0.0>

###
[`v6`](https://redirect.github.com/codecov/codecov-action/compare/v5.5.5...v6)

[Compare
Source](https://redirect.github.com/codecov/codecov-action/compare/v5.5.5...v6)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

5.2.0

Toggle 5.2.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: Use Ubuntu 26.04 (resolute) for devcontainer (#345)

Also includes additional tools:

* gh
* glab
* just
* lazygit
* nodejs

5.1.0

Toggle 5.1.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat: Add support for python 3.14 to copier template (#341)

Addresses #315 

Updates python-copier-template to add python 3.14 to the template.

As discussed in the issue, support for the existing 3.11 oldest python
version is retained to increase the number of supported pythons to 4
versions.

5.0.3

Toggle 5.0.3's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: Force uv to manage python itself (#335)

By default uv will use a system installed version of python when
available. We don't want this as later in the Dockerfile we require
/python to exist which it wont if uv has used a system installed
version. This will happen if the requested version of python is the same
as the default version in the base image.

https://docs.astral.sh/uv/concepts/python-versions/#requiring-or-disabling-managed-python-versions

5.0.2

Toggle 5.0.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: tox / pyright python environment (#320)

Use native tox environment variable expansion to pass $VIRTUAL_ENV Fix
whitespace

5.0.1

Toggle 5.0.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: Better handling of large files (#317)

Whitelists the uv.lock file for the large files check, rather than
allowing all files to increase in size.
This also allows for the case (e.g. blueapi) where the uv.lock file is
>1000kB.

5.0.0

Toggle 5.0.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: Add application to component_type choices (#314)

Fixes #308

5.0.0a5

Toggle 5.0.0a5's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat!: Add renovate (#311)

Need to add some release notes on renovate to the release

An example PR it makes: bluesky/ophyd-async#1109

5.0.0a4

Toggle 5.0.0a4's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat: Add a global cache for uv, pre-commit and global venv (#307)

Supercedes #304 and #305 by adding a global volume that contains:
- pre-commit cache
- uv cache
- uv managed python cache
- the venvs for all the projects

This allows us to use hardlink mode which makes it even faster, and
avoid the issue of anonymous volumes in devcontainers being left
dangling. Added docs to say that there is now a global venv for the
container, which is different for how it would look without any
environment variables set