NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #226 most downloaded on PyPI
An extremely fast Python package and project manager, written in Rust.
Last release today
03 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
322 releases · first in 2024
Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile
Released on 2026-10-03.
uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#22018)uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#22007)uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#22016)uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#22017, #22018)win_amd64 wheels instead of building from source (#22099)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>One column per month.
Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
Released on 2026-10-01.
--offline option from uv publish help (#22124)--no-default-groups in uv audit (#22090)uv audit or uv tool audit runs offline and hide the unsupported option from help (#22114)UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#22098)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.22/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.22/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Update CPython to use OpenSSL 3.5.9
Released on 2026-09-29.
[manifest] tables from lockfiles that contain only manifest subtables (#22070)uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#22004, #22068)uv python pin --rm from removing a global .python-versions file without --global (#21992)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Reuse lockfiles when dependency declarations are semantically equivalent
Released on 2026-09-28.
lockfile-normalization preview feature (#21951)pylock.toml (#22003)pylock.toml files relative to the output file (#22042)tool-install-locks requirements resolve to the same package (#22000)lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)uv workspace metadata and uv tree --format json output (#22050)XDG_CONFIG_DIRS after empty entries (#21987)--require-hashes and --verify-hashes (#21996)--no-build (#21988)--all-packages, including --no-install-project and --no-emit-project (#21994)pyproject.toml if uv upgrade fails or is interrupted (#21983)--show-settings (#21989)uv python list and uv python upgrade instead of panicking (#22033)/install (#22036)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Update GraalPy 3.13.0 to build 25.4.4
Released on 2026-09-24.
uv publish errors (#21934)build-lazy-imports preview feature (#21967)uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#21913)1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#21931).ok files in dependencies (#21891)python_version markers when parsing their serialized form (#21939)FlatDistributions export and its BTreeMap conversion for downstream resolvers (#21965)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>This release addresses GHSA-2cv4-cqwr-gwf7 , which is a path traversal weakness during wheel installation on Windows. No other platforms are affected
Released on 2026-09-22.
This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.
--output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#21893)--check to uv pip install and uv pip sync to report planned changes without modifying the environment (#21844)get_requires_for_build_* hooks correctly in build errors (#21881)uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#21880)uv_build editable wheel creation by omitting compression from temporary wheels (#21918)uv add, uv remove, or uv version fails or is interrupted (#21860, #21856)dependency-metadata when checking whether installed requirements are satisfied (#21843)? (#21920)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.18/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.18/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports
Released on 2026-09-18.
minimum-libc-version (#21651)pylock.toml files whose wheel filenames do not match their declared package names or versions (#20746)uv workspace metadata read-only unless --sync is provided (#21821)uv check lock modes when retrieving workspace metadata (#21821)required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#21825)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.17/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.17/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add Pyodide 314.0.7, 0.29.5, and 0.27.8
Released on 2026-09-17.
build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#21467)platform_release markers in required-environments using macOS wheel deployment targets (#21766)lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#21163)uv upgrade (#21776)uv check to run in projects that are not managed by uv and outside workspaces (#21777)--python and UV_PYTHON when selecting the Python version for uv check (#21744)pylock.toml before reusing cached distributions (#21609)uv_build backend only when its version matches active version pins (#21742)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.16/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes
Released on 2026-09-15.
0.12.14 when installing to symlinked destinations or using uv pip install --target . (#21699)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.15/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.15/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Resume interrupted downloads with HTTP Range requests when supported
Released on 2026-09-15.
cause: labels (#21599, #21603)uv tool upgrade operations (#21566)uv export --batch invocation with the batch-export preview feature (#21618)required-environments within each resolver fork instead of combining incompatible wheel coverage across forks (#21672)MAX_PATH on Windows systems without long-path support enabled (#21625)uv python install from overwriting valid unmanaged Python symlinks with relative targets on Unix (#21639)bin/python over bin/python3 when discovering interpreters in Unix environments (#21559)1 for expected failures and 2 for recognized operational and internal failures (#17110)--quiet (#21565)uv tool upgrade errors visible with -q while suppressing them with -qq (#21566)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.14/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.14/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Verify hashes when downloading PEP 658 metadata sidecars
Released on 2026-09-10.
ty exclusions when uv check automatically selects members of a virtual workspace (#21555)core-metadata over legacy aliases in JSON index responses (#21563)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.13/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple D
Released on 2026-09-09.
The executables in our macOS and Windows release archives and uv and uv_build wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.
exclude-newer cutoff from lockfiles and generated requirement hashes (#21539)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Generate missing artifact hashes when exporting pylock.toml files to ensure they conform to PEP 751
Released on 2026-09-08.
pylock.toml files to ensure they conform to PEP 751 (#20146)pylock.toml artifact hash tables are empty, which will be rejected in a future uv release (#21462)uv pip install --no-deps finds the requested packages already installed (#21523)uv.lock before reading their metadata or running their build backends (#21223)=== under both --verify-hashes and --require-hashes (#21543).python-version and .python-versions files (#21529)VIRTUAL_ENV mismatch warnings for uv add --no-sync, uv remove --no-sync, and uv add --frozen (#21496)uv python list cannot query an interpreter (#21498)exclude-newer examples (#21534)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.11/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Attempt to revoke short-lived PyPI trusted-publishing tokens after uv publish completes, including when publishing fails
Released on 2026-09-04.
uv publish completes, including when publishing fails (#21423)exclude-newer-package settings for packages outside the resolution from uv.lock with the missing-exclude-newer-package-lock preview feature (#21455)uv tree --invert output (#21404)uv publish by hashing each artifact in a single blocking task and reusing the buffer across reads (#21389)--locked from failing when exclude-newer-package settings differ only for packages outside the resolution (#21454)uv lock --check to reuse a lockfile when an absolute exclude-newer cutoff is moved later (#19571)uv lock --check to reuse a lockfile when a package-specific exclude-newer cutoff is disabled (#21450)--name when uv init would infer a project name reserved for a Python interpreter (#21395)exclude-newer cutoffs to uv.lock in a deterministic order (#21453)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add CPython 3.15.0rc2 ( #21413 , #21415 )
Released on 2026-09-01.
--no-locked and --no-frozen to disable lock modes enabled by UV_LOCKED and UV_FROZEN for a single invocation (#21408)async_http_range_reader to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#21401)--locked, --frozen, --check, and --check-exists precedence over conflicting UV_LOCKED and UV_FROZEN values (#21396)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Warn about invalid tool directories and continue upgrading valid tools with uv tool upgrade --all
Released on 2026-08-31.
uv tool upgrade --all (#21368)content-addressed-cache preview feature (#21327)--require-hashes (#21348)sig) query parameters from displayed URLs (#21360)astral-tokio-tar to 0.7.0 and use effective sizes when tracking extracted hard links (#21346)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.8/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Replace managed Python installations when upgrading to a newer build of the same version
Released on 2026-08-27.
s390x, ppc64le, and loongarch64 targets for cross-platform dependency resolution (#21313)UV_AZURE_ENDPOINT_URL (#21318)content-addressed-cache preview feature (#19693)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.7/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Update CPython to use OpenSSL 3.5.8 and libffi 3.4.8 #21295 )
Released on 2026-08-25.
uv_build requirements to source-distribution builds (#21078)uv workspace metadata --sync --exact to remove packages outside the selected resolution (#21117)artifact-hash-filtering preview feature to make uv pip compile --generate-hashes honor --only-binary and --no-binary (#21235)exclude-newer cutoffs when uv check selects its ty executable (#21227)tar-codec source-distribution errors when the base interpreter is outside a bin directory (#21146)uv build and non-editable first-party workspace packages when no-build is enabled (#21294)uv tool upgrade when the tool receipt references the same index (#21275)uv sync (#21264).py as local script paths (#21144)cache-keys entries (#21137)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.6/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.6/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add CPython 3.10.21, 3.11.16, and 3.12.14
Released on 2026-08-14.
--index and --default-index to select configured package indexes by name with the index-by-name preview feature (#17455)cache-physical-space on filesystems that do not support physical-space accounting (#21133)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Prefer post-quantum key exchange and enable opt-in TLS diagnostics
Released on 2026-08-13.
Requires-Python: >= 3.5.* (#21012)uv check --no-install-project and respect UV_NO_INSTALL_PROJECT to install dependencies without building or installing the project (#21085)uv check honor uv's color and progress settings, including quiet mode (#21086)pythonw.exe launchers for virtual environments created from managed Python minor-version links (#19235)uv lock to proceed when .venv is an unusable project environment (#21068)fork-strategy when ordering forks created from environments or existing lockfile resolution-markers (#21000)!=3.11.*, !=3.12.* in uv.lock (#21045)uv add updates it (#21008)PYTHONEXECUTABLE and __PYVENV_LAUNCHER__ overrides (#21075)uv version --bump values (#21076)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add --output-format to select automatic, human-readable, or raw-byte output for uv cache size
Released on 2026-08-07.
--output-format to select automatic, human-readable, or raw-byte output for uv cache size (#20992)uv workspace metadata --quiet while suppressing diagnostics (#20991)uv workspace metadata JSON output (#20990)--python-pin to --pin-python in the uv init --bare example (#20876)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Ensure diagnostic hints end with a newline to prevent malformed terminal output
Released on 2026-08-05.
uv tool audit (#20921)cache-physical-space preview feature (#20925)UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#20926)uv.lock parsing for wheel entries (#20881)uv.lock parsing for source distribution entries (#20882)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.2/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.2/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add package-specific pre-release policies with --prerelease-package
Released on 2026-07-31.
--prerelease-package (#20837)activate.xsh) (#19740)uv add --index when updating pyproject.toml (#20817)uv check with --fix (#20793)uv check (#20742)uv tool update-shell and uv python update-shell exit (#20842)--find-links paths in requirements files relative to the containing file (#20832)uv tool list --outdated (#20770)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.1/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.1/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>There are no breaking changes to the configuration of the uv build backend . If your [build-system] table includes an upper bound on uv_build , update…
Released on 2026-07-28.
Since we released uv 0.11.0 in March, we've accumulated changes that improve correctness, safety, and compatibility with specifications, but could break some workflows. This release contains those changes; many have been marked as breaking out of an abundance of caution.
We expect most users to be able to upgrade without making changes.
There are no breaking changes to the configuration of the uv build backend. If your [build-system] table includes an upper bound on uv_build, update it to allow uv_build 0.12, e.g., uv_build>=0.11.32,<0.13.
Define build systems by default with uv init (#19197)
Projects created with uv init now declare a build system and are packaged by default. This was the default project layout all the way back in v0.3, but we found that the use of the hatchling build system was confusing to newcomers and consequently dropped use of a build system by default in v0.4. Since then, we've created our own build system (uv_build) with tight integration with uv and are excited to restore the default to a best-practice project layout.
Previously, uv init example created an unpackaged layout containing main.py and a pyproject.toml without a build system. The project could declare dependencies but was not itself installed into its virtual environment.
Now, uv init example defines a [build-system] using uv_build, places application source code in src/example, and includes a [project.scripts] entry named example. Defining a build system allows the project to be imported from tests or other code, installed as a dependency, and run as a command:
$ uv init example
$ cd example
$ uv run example
Hello from example!Existing projects are unaffected. Use uv init --no-package example to create the previous unpackaged layout without a build system.
See the project creation documentation for more details.
This stabilizes the packaged-init preview feature.
Reject unsupported source distribution and wheel archive formats (#18927)
PEP 625 requires source distributions to use .tar.gz archives. Previously, uv also accepted legacy formats such as .tar.bz2 and .tar.xz. Those formats are now rejected, including when referenced by an existing lockfile. Legacy .zip source distributions remain supported for backwards compatibility.
Wheels and other ZIP archives can no longer contain entries compressed with bzip2, LZMA, or XZ. Entries must use the stored, DEFLATE, or zstd compression methods.
Removing support for uncommon compression methods reduces uv's compression dependencies and the attack surface exposed when processing untrusted packages.
You cannot opt out of this behavior. If you depend on a legacy source distribution that uses an unsupported format, we recommend rebuilding it as a .tar.gz archive and regenerating any lockfile containing references to the legacy archive.
Reject wheel files that could replace the Python interpreter (#20748, #20749)
uv already rejected wheel entry points named python, but case variants such as Python were still accepted. On case-insensitive filesystems, including common macOS and Windows setups, these entry points could overwrite the virtual environment's interpreter.
Wheels could also place interpreter files in their .data/scripts directory or in paths such as .data/data/bin/python, bypassing the entry-point check and replacing the interpreter during installation.
uv now rejects case-insensitive variants of reserved interpreter names and wheel data files that would be installed over an interpreter. This includes names such as Python, python.py, and Python.exe, along with other reserved interpreter names and their versioned variants.
You cannot opt out of these checks. Rename conflicting entry points or wheel data files and rebuild the affected wheel.
Prefer stable releases before falling back to pre-releases (#19993)
A dependency can introduce a pre-release requirement after resolution starts. uv previously required each package's pre-release eligibility to be known before resolution began: the default if-necessary-or-explicit mode allowed them for direct requirements that explicitly requested a pre-release, or for packages that only published pre-releases.
This meant that a pre-release requirement discovered in a dependency's metadata, e.g., example>=2.0.0b1, would fail to resolve even when a compatible pre-release existed. To resolve it, you had to add that dependency as a direct requirement or allow pre-releases across your entire dependency graph.
The default mode is now if-necessary. uv tries stable candidates first and falls back to pre-releases when no stable candidate satisfies the active constraints. Like pip, uv now supports pre-release requirements discovered transitively, but can select different versions than previous uv releases when both stable and pre-release candidates are available.
You can opt out of automatic pre-release selection with --prerelease disallow. Alternatively, --prerelease allow considers pre-releases without first preferring stable releases, and --prerelease explicit only allows them for direct requirements that mention a pre-release.
The old if-necessary-or-explicit mode distinguished between explicitly requested pre-releases and packages with no stable releases. That distinction is unnecessary now that if-necessary handles both cases, including transitive requirements. The old name remains available as an alias but is deprecated and will be removed in a future release.
Respect --require-hashes directives in requirements.txt (#19336)
Previously, uv pip install and uv pip sync warned about --require-hashes inside a requirements.txt file but still installed dependencies without checking their hashes. Now, the directive enables hash-checking mode, just as if --require-hashes had been passed on the command line.
For example, this requirements file is no longer accepted because the requirement is neither pinned nor hashed:
--require-hashes
anyio
You cannot opt out while the directive is present. Pin every requirement with == and provide its hash, or remove --require-hashes if hash checking is not intended.
Reject MD5-only hashes in hash-checking mode (#20758)
Previously, uv pip install --require-hashes and uv pip sync --require-hashes accepted requirements whose only available digest used MD5. MD5 is not collision-resistant, so relying on it undermined installations that require hash verification and differed from pip's behavior.
Hash-checking mode now requires at least one secure digest for every requirement. For example, the following requirement is rejected unless a secure hash, such as SHA-256, is also supplied:
anyio==4.0.0 --hash=md5:420d85e19168705cdf0223621b18831a
A secure hash can be supplied directly on the requirement or in a matching constraints file. Ordinary hash verification without --require-hashes continues to support MD5.
You cannot opt out while hash checking is required. Regenerate affected hashes with SHA-256 or another supported secure hash.
Reject invalid pylock.toml files and artifacts (#20402, #20440, #20443)
uv now validates additional requirements from the pylock.toml specification:
packages array must be present. Previously, uv interpreted a missing array as an empty lockfile, so uv pip sync could uninstall an environment instead of rejecting malformed input. An explicitly empty packages = [] array remains valid.pylock.toml or a single-name variant such as pylock.dev.toml. Names such as pylock..toml and pylock.foo.bar.toml are rejected.size, the downloaded or cached artifact must match. Previously, an incorrect size was accepted when the hash was correct. Sizes reported by package indexes remain advisory.You cannot opt out of these checks. Regenerate malformed lockfiles, rename invalid filenames, and either correct or remove an incorrect optional size value.
Honor explicit certificate overrides even when no certificates can be loaded (#20741, #20767)
Previously, uv ignored SSL_CERT_FILE or SSL_CERT_DIR values that pointed to missing or inaccessible paths, empty files or directories, or sources without valid certificates. Instead, it fell back to its default trust roots, potentially allowing HTTPS connections that the configured override was intended to reject.
Now, any non-empty SSL_CERT_FILE or SSL_CERT_DIR value replaces uv's default certificate roots, even when no valid certificates can be loaded. In that case, HTTPS requests fail because no certificates are trusted. This applies to package downloads and remote scripts, including GitHub Gists.
Fix or unset the certificate override. Unsetting it restores the default trust store; empty environment-variable values continue to be ignored.
Support pip-compatible --cert handling in uv pip (#20418)
The uv pip interface now accepts --cert <path>, e.g.:
$ uv pip install --cert ./company-ca.pem exampleAs in pip, the provided PEM bundle replaces all other certificate sources for that invocation, including system certificates and SSL_CERT_FILE or SSL_CERT_DIR. This change has no effect unless you pass --cert. Include the necessary certificate authorities in the bundle.
--cert is only supported by uv pip commands; other uv commands continue to use their existing certificate configuration.
Discover projects relative to the script passed to uv run (#20225)
Previously, uv run project/script.py discovered its project from the current directory, even when the script belonged to another project. uv now starts project and workspace discovery from the script's directory instead.
For example, running uv run other-project/script.py now uses other-project and its dependencies. This fixes scripts that previously failed because their own dependencies were not installed, but can select a different environment than before.
You can opt out of script-relative discovery by selecting a project explicitly, e.g., uv run --project . other-project/script.py.
This stabilizes the target-workspace-discovery preview feature.
Require --force before clearing a directory that is not a virtual environment (#20225)
uv venv --clear previously removed any existing target directory, even if it was not a virtual environment. uv emitted a warning but still deleted the directory and its contents. Now, uv refuses to clear directories that do not contain a virtual environment.
You can opt out of this safety check by explicitly passing --force, e.g., uv venv --clear --force ./not-a-virtualenv.
This stabilizes the venv-safe-clear preview feature.
Reject --project when initializing a project (#20225)
--project selects an existing project, so it is not meaningful when initializing a new one. Previously, uv init --project example warned and initialized example anyway; if a positional path was also provided, --project was ignored.
This usage is now an error. Use uv init example to initialize a project at the requested path, or uv init --directory example to change the working directory first.
This stabilizes the init-project-flag preview feature.
Reject missing or invalid --project paths (#20225)
uv previously warned when --project referred to a missing directory or a file other than pyproject.toml, but then attempted to continue. This could produce confusing errors later or run against an unintended project.
Now, uv run --project missing python fails immediately instead of continuing. You cannot opt out of this behavior. Create the directory first or select an existing project. Passing --project path/to/pyproject.toml remains supported and selects the file's parent directory.
This stabilizes the project-directory-must-exist preview feature.
Skip distributions with non-normalized filenames when publishing (#20225)
Distribution filenames must use normalized package names and versions. For example, a wheel for version 1.01.0 should be named example-1.1.0-py3-none-any.whl, not example-1.01.0-py3-none-any.whl.
Previously, uv publish warned about non-normalized filenames but still attempted to upload them. It now skips the affected wheels and source distributions instead.
You cannot opt out of this behavior. Rebuild distributions with normalized filenames before publishing.
This stabilizes the publish-require-normalized preview feature.
Classify Conda environments named base and root by their paths (#20225)
Conda environments named base or root were previously assumed to be the base Conda environment, even when they were ordinary child environments. uv now recognizes child Conda environments named base or root based on their paths, as it already does for other names.
You can opt out of automatic interpreter selection by requesting an interpreter explicitly with --python /path/to/python.
This stabilizes the special-conda-env-names preview feature.
Reject broken .venv symlinks during environment discovery (#20433)
Previously, uv could ignore a broken .venv symlink and continue searching parent directories for another virtual environment. As a result, commands such as uv pip install could unexpectedly modify an unrelated ancestor environment.
uv now stops at a broken .venv symlink and reports its exact path. Errors encountered while reading virtual environment metadata, including permission failures, are also reported immediately instead of being ignored.
You cannot opt out of this behavior. Repair or remove the broken .venv symlink and correct any permissions that prevent uv from inspecting the environment.
Reinstall matching installed Python patch versions instead of upgrading implicitly (#20659)
Before Python upgrades were supported, uv python install 3.12 --reinstall doubled as a way to install the latest Python 3.12 patch release. Now that --upgrade is available, --reinstall reinstalls the matching patch releases that are already present.
For example, if Python 3.12.6 and 3.12.7 are installed, uv python install 3.12 --reinstall reinstalls both versions instead of installing the latest available 3.12 release.
You can recover the previous upgrade behavior with uv python install 3.12 --upgrade. Combine --upgrade --reinstall to reinstall only the latest patch.
Require --upgrade-group to name an existing dependency group (#18957)
Previously, uv lock --upgrade-group docs silently succeeded even if no docs dependency group existed. uv now validates the requested group against the project, its workspace members, and workspace-level dependency groups.
You cannot opt out of this behavior. Correct the group name or add it to [dependency-groups]. Legacy tool.uv.dev-dependencies still satisfies --upgrade-group dev.
Resolve relative indexes and find-links against --directory (#20740)
The --directory option changes the directory in which uv operates. Previously, relative index and find-links paths supplied on the command line were still resolved against the original working directory.
uv now resolves --index, --default-index, --index-url, --extra-index-url, and --find-links relative to the directory selected by --directory. For example:
$ uv add --directory project --index ./packages exampleThis now uses project/packages instead of ./packages in the original working directory. Absolute paths and indexes loaded from configuration files are unaffected.
To preserve the previous target, pass an absolute path or adjust the relative path, e.g., --index ../packages.
Preserve absolute paths provided to uv add (#18402)
uv add previously converted every local dependency into a project-relative path, even when the original request used an absolute path or a literal file:// URL. It now preserves the form of the request in pyproject.toml and uv.lock:
$ uv add ../library # remains relative
$ uv add /projects/library # remains absoluteAbsolute paths make a project less portable. Use a relative path to avoid recording an absolute path. URLs containing expanded variables retain their existing relative-path behavior.
Remove older PyPy distributions that are only available as bzip2 archives (#20423)
Older PyPy patch releases that are only distributed as .tar.bz2 archives are no longer available through uv python install. These releases require unsupported bzip2 archives.
The latest PyPy release for each supported Python minor version is available as a gzip-compressed archive and remains supported. For example, uv python list 3.10 --all-versions still includes the latest PyPy 3.10 release, but older bzip2-only patch releases are omitted.
You cannot opt out of this behavior. Request a newer PyPy patch release instead.
Omit excluded-package comments when annotations are disabled (#20085)
uv pip compile --no-annotate suppresses comments describing the generated requirements file. Previously, a footer listing packages excluded with --unsafe-package was still included, even though annotations were disabled. That footer is now omitted.
You can recover the footer by removing --no-annotate.
TOML 1.0-compatible source distributions (#20225)
uv_build now writes a TOML 1.0-compatible pyproject.toml when building source distributions, allowing older Python build frontends to consume projects that use newer TOML syntax. The original project file remains available in the archive as pyproject.toml.orig.
This stabilizes the toml-backwards-compatibility preview feature.
Automatic open-file limit adjustment on Unix (#20225)
On Linux and macOS, uv now attempts to raise the soft open-file limit at startup toward the hard limit, capped at 1,048,576 descriptors. The new limit also applies to subprocesses and reduces failures caused by running out of file descriptors. If the limit cannot be raised, uv continues running with the existing limit.
This stabilizes the adjust-ulimit preview feature.
uv upgrade to target multiple packages, upgrade all production dependencies, and exclude selected dependencies (#20338)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.0/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.0/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Abort panics in release builds for smaller uv binaries
Released on 2026-07-28.
.tar.gz archives for Pyodide installs (#20667)uv check unless --script is passed (#20676)package.metadata-free lockfiles (#20688, #20691, #20685, #20695)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.33/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Add --package and --all-packages selection to uv check
Released on 2026-07-23.
--package and --all-packages selection to uv check (#20628)uv upgrade to update multiple marker-specific declarations of the same package (#20335)uv lock --check and commands using --locked (#20646)uv lock --refresh (#20634)uv workspace metadata by default (#20643)Requires-Python is discovered only from distribution metadata (#20586)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Allow workspace sources to reference members in another workspace by path
Released on 2026-07-21.
.venv files containing paths to centralized project environments (#20022)hash-algorithm setting for lockfile generation (#20605)audit.malware-check and audit.malware-check-url settings (#20587)--emit-build-options for unsupported uv pip compile --emit-options (#20582)uv_build settings for in-tree build backends (#20153)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Allow uv workspace metadata --sync to target the active virtual environment with --active
Released on 2026-07-20.
uv workspace metadata --sync to target the active virtual environment with --active (#20500)exclude-newer (#20460)toml_writer (#20450)extends-environment paths in pyvenv.cfg on Unix (#20466)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.30/uv-installer.sh | shpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.30/uv-installer.ps1 | iex"The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>Use gzip-compressed artifacts for PyPy downloads
Released on 2026-07-15.
uv tree (#19978)pylock.toml (#20393)uv audit --service-url values instead of panicking (#20374)uv sync operations (#20364)uv tree, uv export, uv format, and uv audit (#20359)pylock.toml (#20391)uv pip freeze output (#20395)uv pip install --strict has nothing to install (#20388)platlib when purelib is missing (#20405).egg-info files as legacy package metadata (#20403)pylock.toml artifact URLs instead of panicking (#20373)--no-build behavior for editable requirements (#20234)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.29/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.29/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
This release updates our ZIP library, astral-async-zip, to v0.0.20, which includes 15 changes that harden our ZIP handling against parser differential
Released on 2026-07-07.
This release updates our ZIP library, astral-async-zip, to v0.0.20, which includes 15 changes that harden our ZIP handling against parser differentials. uv may reject ZIP archives with malformed or ambiguous content that were previously accepted.
See the upstream commits for a full list of changes.
-q and -qq (#20163)uv build errors (#20159)uv pip install (#19914)--upgrade when upgrade-package is configured (#19955)uv tree in dependency-group-only projects (#20167)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.28/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.28/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Continue on ignored errors when fetching wheel metadata
Released on 2026-07-06.
--python-downloads-json-url (#16749)uv workspace list --scripts (#20099)requires-python specifiers in Simple API parsing (#20104)packages table for pylock.toml (#20145)uv pip tree (#20062)uv add --index updates an existing index URL (#19818)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.27/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.27/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Adapt uv to IDs-only PubGrub dependencies
Released on 2026-06-30.
ForkMap::contains (#20023)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.26/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.26/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
This release updates our tar library, astral-tokio-tar, to v0.6.3, which includes over 20 changes that harden our tar handling against parser differen
Released on 2026-06-26.
This release updates our tar library, astral-tokio-tar, to v0.6.3, which includes over 20 changes that harden our tar handling against parser differentials. uv may reject source distributions with malformed or ambiguous content that were previously accepted.
See the upstream commits for a full list of changes.
tool.uv.environments (#19933)uv workspace list --scripts (#20009)uv venv (#19912)uv check (#19884)uv check (#19995)uv check --script (#19989)uv build if the cache dir is enclosed (#19991)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.25/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.25/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Make project environments relocatable under preview
Released on 2026-06-23.
exclude-newer (#19934)activate.fish and broaden Fish version support (#19856)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.24/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.24/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Revert "Fix transparent Python upgrades in project environments" to mitigate unintended breakage in pre-commit-uv
Released on 2026-06-19.
pre-commit-uv (#19925)pyproject.toml would be treated as standalone projects (#19926)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.23/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.23/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Publish wheels before sdists in uv publish
Released on 2026-06-18.
uv publish (#19831)TY and RUFF env vars for providing paths for binaries used by uv format and uv check (#19821)uv.toml and pyproject.toml (#18437)uv check --no-sync (#19909)--script to uv check and uv metadata (#19860)workspace metadata (#19862)uv audit output (#19872)include-group entries that have additional fields (#19866)backend-paths exist when building sdists (#19834)pylock.toml files do not have an unsupported a lock-version (#19869)packages.requires-python of a pylock.toml (#19868)uv to be recursively invoked by PEP 517 build hooks (#19879)credentials.toml files (#19815)uv pip list (#19867)uv tree --invert (#19910)uv venv in a project (#19837)uv tree (#19905)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.22/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.22/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add environment.root to uv workspace metadata --sync
Released on 2026-06-11.
environment.root to uv workspace metadata --sync (#19760)uv upgrade to update a single dependency constraint (#19738)uv workspace metadata payload in ty check (#19763)uv init (#17841)uv python list (#18684)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.21/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.21/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add --emit-index-url and --emit-find-links to uv export
Released on 2026-06-10.
--emit-index-url and --emit-find-links to uv export (#18370)--find-links support for uv pip list (#16103)uv python install (#19691)UV_NO_INSTALL_PROJECT, UV_NO_INSTALL_WORKSPACE, UV_NO_INSTALL_LOCAL (#19323)VIRTUAL_ENV through cygpath inside fish on Windows (#19703)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.20/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.20/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Always compute SHA256 for remote distributions
Released on 2026-06-03.
--isolated in uv check (#19666)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.19/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.19/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix performance regression in unzip of local wheels
Released on 2026-06-01.
uv check to run ty from uv (#19605)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.18/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.18/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Your coding agent can read these notes before it upgrades. Set up the MCP server →