Tags: DiamondLightSource/python-copier-template
Tags
chore(deps): update astral-sh/setup-uv action to v10 (#369) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.0` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0) ##### Changes Another breaking release, directly after v9.0.0 but we think the added security justifies that. ##### Extra security by default If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events: - `pull_request_target` - `workflow_run` - `release` You can read the full reasoning in [#​984](https://redirect.github.com/astral-sh/setup-uv/issues/984) ##### `version: latest-known` ```yaml - name: Install the latest version of uv known to setup-uv uses: astral-sh/setup-uv@v10.0.0 with: version: "latest-known" ``` This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security. ##### Read python version from `.tool-versions` ```yaml - name: Install uv based on the version defined in .tool-versions and also set python uses: astral-sh/setup-uv@v10.0.0 with: version-file: "pyproject.toml" ``` Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file) ##### 🚨 Breaking changes - Disable automatic caching for sensitive events [@​eifinger](https://redirect.github.com/eifinger) ([#​992](https://redirect.github.com/astral-sh/setup-uv/issues/992)) ##### 🐛 Bug fixes - Reject paths in .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007)) ##### 🚀 Enhancements - Read Python version from .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​996](https://redirect.github.com/astral-sh/setup-uv/issues/996)) - Add latest-known version selector [@​eifinger](https://redirect.github.com/eifinger) ([#​993](https://redirect.github.com/astral-sh/setup-uv/issues/993)) ##### 🧰 Maintenance - Require pull requests for Dependabot rollups [@​eifinger](https://redirect.github.com/eifinger) ([#​1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005)) - ci: pin Alpine container image [@​eifinger](https://redirect.github.com/eifinger) ([#​995](https://redirect.github.com/astral-sh/setup-uv/issues/995)) - chore: update known checksums for 0.12.3 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​991](https://redirect.github.com/astral-sh/setup-uv/issues/991)) - chore: update known checksums for 0.12.2 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​985](https://redirect.github.com/astral-sh/setup-uv/issues/985)) - chore: update known checksums for 0.12.1 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​982](https://redirect.github.com/astral-sh/setup-uv/issues/982)) - chore: update known checksums for 0.12.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​981](https://redirect.github.com/astral-sh/setup-uv/issues/981)) - chore: update known checksums for 0.11.31/0.11.32 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​972](https://redirect.github.com/astral-sh/setup-uv/issues/972)) ##### 📚 Documentation - docs: update version references to v9.0.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​971](https://redirect.github.com/astral-sh/setup-uv/issues/971)) ##### ⬆️ Dependency updates - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013)) - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004)) - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​994](https://redirect.github.com/astral-sh/setup-uv/issues/994)) - chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​976](https://redirect.github.com/astral-sh/setup-uv/issues/976)) - chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​980](https://redirect.github.com/astral-sh/setup-uv/issues/980)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update codecov/codecov-action action to v7 (#355) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [codecov/codecov-action](https://redirect.github.com/codecov/codecov-action) | action | major | `v5` → `v7` | --- ### Release Notes <details> <summary>codecov/codecov-action (codecov/codecov-action)</summary> ### [`v7.0.0`](https://redirect.github.com/codecov/codecov-action/releases/tag/v7.0.0) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v7.0.0...v7.0.0)⚠️ Due to migration issues with keybase, we are unable to update our keys under the `codecovsecurity` account. We have deleted the account and are using `codecovsecops` with the original gpg key ##### What's Changed - ci: remove Enforce License Compliance workflow by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1950](https://redirect.github.com/codecov/codecov-action/pull/1950) - chore(release): 7.0.0 by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1957](https://redirect.github.com/codecov/codecov-action/pull/1957) **Full Changelog**: <codecov/codecov-action@v6.0.1...v7.0.0> ### [`v7`](https://redirect.github.com/codecov/codecov-action/compare/v6.0.2...v7.0.0) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v6.0.2...v7.0.0) ### [`v6.0.2`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.2) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v6.0.1...v6.0.2) This is a copy of the `v7.0.0` release to make updates easier ##### What's Changed - ci: remove Enforce License Compliance workflow by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1950](https://redirect.github.com/codecov/codecov-action/pull/1950) - chore(release): 7.0.0 by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1957](https://redirect.github.com/codecov/codecov-action/pull/1957) **Full Changelog**: <codecov/codecov-action@v6.0.1...v6.0.2> ### [`v6.0.1`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.1) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v6...v6.0.1) ##### What's Changed - fix: prevent template injection in run: steps (VULN-1652) by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1947](https://redirect.github.com/codecov/codecov-action/pull/1947) - chore(release): 6.0.1 by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1949](https://redirect.github.com/codecov/codecov-action/pull/1949) **Full Changelog**: <codecov/codecov-action@v6.0.0...v6.0.1> ### [`v6.0.0`](https://redirect.github.com/codecov/codecov-action/releases/tag/v6.0.0) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v6...v6) #####⚠️ This version introduces support for node24 which make cause breaking changes for systems that do not currently support node24.⚠️ ##### What's Changed - Revert "Revert "build(deps): bump actions/github-script from 7.0.1 to 8.0.0"" by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1929](https://redirect.github.com/codecov/codecov-action/pull/1929) - Th/6.0.0 by [@​thomasrockhu-codecov](https://redirect.github.com/thomasrockhu-codecov) in [#​1928](https://redirect.github.com/codecov/codecov-action/pull/1928) **Full Changelog**: <codecov/codecov-action@v5.5.4...v6.0.0> ### [`v6`](https://redirect.github.com/codecov/codecov-action/compare/v5.5.5...v6) [Compare Source](https://redirect.github.com/codecov/codecov-action/compare/v5.5.5...v6) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
fix: Force uv to manage python itself (#335) By default uv will use a system installed version of python when available. We don't want this as later in the Dockerfile we require /python to exist which it wont if uv has used a system installed version. This will happen if the requested version of python is the same as the default version in the base image. https://docs.astral.sh/uv/concepts/python-versions/#requiring-or-disabling-managed-python-versions
feat: Add a global cache for uv, pre-commit and global venv (#307) Supercedes #304 and #305 by adding a global volume that contains: - pre-commit cache - uv cache - uv managed python cache - the venvs for all the projects This allows us to use hardlink mode which makes it even faster, and avoid the issue of anonymous volumes in devcontainers being left dangling. Added docs to say that there is now a global venv for the container, which is different for how it would look without any environment variables set
PreviousNext