Skip to content

ci: bump astral-sh/setup-uv from v6 to v8.0.0#2043

Merged
KRRT7 merged 1 commit into
mainfrom
deps/setup-uv-v8
Apr 9, 2026
Merged

ci: bump astral-sh/setup-uv from v6 to v8.0.0#2043
KRRT7 merged 1 commit into
mainfrom
deps/setup-uv-v8

Conversation

@KRRT7
Copy link
Copy Markdown
Contributor

@KRRT7 KRRT7 commented Apr 9, 2026

Summary

  • Bumps astral-sh/setup-uv from v6 to v8.0.0 across all 21 workflow files
  • v8 uses immutable releases only (no major/minor tags like @v8) per upstream security policy — prevents supply chain attacks via tag rewriting

Test plan

  • Unit tests pass
  • E2E tests pass (uv installs correctly)

v8 uses immutable releases (no major/minor tags) for supply chain
security. Pinning to exact version tag per upstream recommendation.
@github-actions github-actions Bot added the workflow-modified This PR modifies GitHub Actions workflows label Apr 9, 2026
@KRRT7 KRRT7 merged commit cf59523 into main Apr 9, 2026
16 of 18 checks passed
@KRRT7 KRRT7 deleted the deps/setup-uv-v8 branch April 9, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

workflow-modified This PR modifies GitHub Actions workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant