NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #905 most downloaded on PyPI
The uv build backend
Last release 3 days ago
15 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
156 releases · first in 2025
One column per month.
The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13 which included some breaking changes to TLS certifi…
Released on 2026-03-23.
This release includes changes to the networking stack used by uv. While we think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so we have marked the change as breaking out of an abundance of caution.
The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13 which included some breaking changes to TLS certificate verification.
The following changes are included:
rustls-platform-verifier is used instead of rustls-native-certs and webpki for certificate verification
This change should have no effect unless you are using the native-tls option to enable reading system certificates.
rustls-platform-verifier delegates to the system for certificate validation (e.g., Security.framework on macOS) instead of eagerly loading certificates from the system and verifying them via webpki. The effects of this change will vary based on the operating system. In general, uv's certificate validation should now be more consistent with browsers and other native applications. However, this is the most likely cause of breaking changes in this release. Some previously failing certificate chains may succeed, and some previously accepted certificate chains may fail. In either case, we expect the validation to be more correct and welcome reports of regressions.
In particular, because more responsibility for validating the certificate is transferred to your system's security library, some features like CA constraints or revocation of certificates via OCSP and CRLs may now be used.
This change should improve performance when using system certificate on macOS, as uv no longer needs to load all certificates from the keychain at startup.
aws-lc is used instead of ring for a cryptography backend
There should not be breaking changes from this change. We expect this to expand support for certificate signature algorithms.
--native-tls is deprecated in favor of a new --system-certs flag
The --native-tls flag is still usable and has identical behavior to --system-certs.
This change was made to reduce confusion about the TLS implementation uv uses. uv always uses rustls not native-tls.
Building uv on x86-64 and i686 Windows requires NASM
NASM is required by aws-lc. If not found on the system, a prebuilt blob provided by aws-lc-sys will be used.
If you are not building uv from source, this change has no effect.
See the CONTRIBUTING guide for details.
Empty SSL_CERT_FILE values are ignored (for consistency with SSL_CERT_DIR)
See #18550 for details.
See the python-build-standalone release notes for details.
--service-format and --service-url to uv audit (#18571)uv tool list --outdated (#18586)uv export for workspace member packages with conflicts (#18635)FLASH_ATTENTION_SKIP_CUDA_BUILD guidance for flash-attn installs (#18473)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.0/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.0/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add support for using Python 3.6 interpreters
Released on 2026-03-19.
--no-emit-package (#18565)uv audit in the CLI help (#18540)uv python list (#18459)uv-docker-example (#18558)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.12/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fetch Ruff release metadata from an Astral mirror
Released on 2026-03-16.
--project to refer to a pyproject.toml directly and reduce to a warning on other files (#18513)SYSTEM_VERSION_COMPAT when querying interpreters on macOS (#18452)uv sync --active recreating active environments when UV_PYTHON_INSTALL_DIR is relative (#18398)-o requirements.txt in uv pip compile example (#12308)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.11/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add --outdated flag to uv tool list
Released on 2026-03-13.
--outdated flag to uv tool list (#18318)--project directory does not exist (#17714)uv init (#18417)uv cache clear an alias of uv cache clean (#18420)uv_build (#18419)uv audit output (#18392)uv audit (#18193)uv audit (#18394)uv tool install --force (#18399)uv export (#18433)Content-Type (#18334)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.10/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add fbgemm-gpu, fbgemm-gpu-genai, torchrec, and torchtune to the PyTorch list
Released on 2026-03-06.
fbgemm-gpu, fbgemm-gpu-genai, torchrec, and torchtune to the PyTorch list (#18338)uv_build settings without uv_build (#15750)/usr/lib/os-release on Linux system lookup failure (#18349)cargo auditable to include SBOM in uv builds (#18276)UV_VENV_RELOCATABLE (#18331)cp3-none-any (#17064)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.9/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.9/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add Docker images based on Docker Hardened Images
Released on 2026-03-03.
--exclude-newer filters out all versions of a package (#18217)uv_build direct build compatibility (#17902)UV_INIT_BARE environment variable for uv init (#18210)uv tool upgrade from installing excluded dependencies (#18022)pylock.toml files (#18227)--upgrade (#18226)uv tree orphaned roots and premature deduplication (#17212)after_script (#18206)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix handling of junctions in Windows Containers on Windows
Released on 2026-02-27.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.7/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.7/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Apply lockfile marker normalization for fork markers
Released on 2026-02-24.
requires-python conflicting with .python-version (#18097)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.6/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.6/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add hint when named index is found in a parent config file
Released on 2026-02-23.
uv lock --frozen (#17859)pylock.toml wheels by tags and requires-python (#18081)uv publish (#17783)exclude-newer invalidates the lock file (#18100)--no-emit-workspace with --all-packages on single-member workspaces (#18098)UV_NO_DEFAULT_GROUPS rejecting truthy values like 1 (#18057)uv export formats (#17900)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.5/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.5/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Remove duplicate references to the affected paths when showing uv python errors
Released on 2026-02-17.
uv python errors (#18008)uv init / --name foo) (#17983)wheel and sdist files produced by the uv_build build backend (#18020)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.4/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.4/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Don't open file locks for writing
Released on 2026-02-16.
exclude-newer in uv format (#17651)target-workspace-discovery is enabled (#17965)uv format (#17977)cpython-3.1 is specified (#17972)--allow-existing with minor version links on Windows (#17978)u64::MAX in version segments to prevent overflow (#17985)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.3/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.3/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Deprecate unexpected ZIP compression methods
Released on 2026-02-10.
cargo-install failing due to missing uv-test dependency (#17954)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.2/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.2/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Don't panic on metadata read errors
Released on 2026-02-10.
sdist-vX/.git if it already exists (#17825)uv python update-shell over uv tool update-shell in Python docs (#17941)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.1/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.1/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
There are no breaking changes to `uv_build`. If you have an upper bound in your [build-system] table, you should update it, e.g., from <0.10.0 to <0.1…
Since we released uv 0.9.0 in October of 2025, we've accumulated various changes that improve correctness and user experience, but could break some workflows. This release contains those changes; many have been marked as breaking out of an abundance of caution. We expect most users to be able to upgrade without making changes.
This release also includes the stabilization of preview features. Python upgrades are now stable, including the uv python upgrade command, uv python install --upgrade, and automatically upgrading Python patch versions in virtual environments when a new version is installed. The add-bounds and extra-build-dependencies settings are now stable. Finally, the uv workspace dir and uv workspace list utilities for writing scripts against workspace members are now stable.
Require --clear to remove existing virtual environments in uv venv (#17757)
Previously, uv venv would prompt for confirmation before removing an existing virtual environment in interactive contexts, and remove it without confirmation in non-interactive contexts. Now, uv venv requires the --clear flag to remove an existing virtual environment. A warning for this change was added in uv 0.8.
You can opt out of this behavior by passing the --clear flag or setting UV_VENV_CLEAR=1.
Error if multiple indexes include default = true (#17011)
Previously, uv would silently accept multiple indexes with default = true and use the first one. Now, uv will error if multiple indexes are marked as the default.
You cannot opt out of this behavior. Remove default = true from all but one index.
Error when an explicit index is unnamed (#17777)
Explicit indexes can only be used via the [tool.uv.sources] table, which requires referencing the index by name. Previously, uv would silently accept unnamed explicit indexes, which could never be referenced. Now, uv will error if an explicit index does not have a name.
You cannot opt out of this behavior. Add a name to the explicit index or remove the entry.
Install alternative Python executables using their implementation name (#17756, #17760)
Previously, uv python install would install PyPy, GraalPy, and Pyodide executables with names like python3.10 into the bin directory. Now, these executables will be named using their implementation name, e.g., pypy3.10, graalpy3.10, and pyodide3.12, to avoid conflicting with CPython installations.
You cannot opt out of this behavior.
Respect global Python version pins in uv tool run and uv tool install (#14112)
Previously, uv tool run and uv tool install did not respect the global Python version pin (set via uv python pin --global). Now, these commands will use the global Python version when no explicit version is requested.
For uv tool install, if the tool is already installed, the Python version will not change unless --reinstall or --python is provided. If the tool was previously installed with an explicit --python flag, the global pin will not override it.
You can opt out of this behavior by providing an explicit --python flag.
Remove Debian Bookworm, Alpine 3.21, and Python 3.8 Docker images (#17755)
The Debian Bookworm and Alpine 3.21 images were replaced by Debian Trixie and Alpine 3.22 as defaults in uv 0.9. These older images are now removed. Python 3.8 images are also removed, as Python 3.8 is no longer supported in the Trixie or Alpine base images.
The following image tags are no longer published:
uv:bookworm, uv:bookworm-slimuv:alpine3.21uv:python3.8-*Use uv:debian or uv:trixie instead of uv:bookworm, uv:alpine or uv:alpine3.22 instead of uv:alpine3.21, and a newer Python version instead of uv:python3.8-*.
Drop PPC64 (big endian) builds (#17626)
uv no longer provides pre-built binaries for PPC64 (big endian). This platform appears to be largely unused and is only supported on a single manylinux version. PPC64LE (little endian) builds are unaffected.
Building uv from source is still supported for this platform.
Skip generating activate.csh for relocatable virtual environments (#17759)
Previously, uv venv --relocatable would generate an activate.csh script that contained hardcoded paths, making it incompatible with relocation. Now, the activate.csh script is not generated for relocatable virtual environments.
You cannot opt out of this behavior.
Require username when multiple credentials match a URL (#16983)
When using uv auth login to store credentials, you can register multiple username and password combinations for the same host. Previously, when uv needed to authenticate and multiple credentials matched the URL (e.g., when retrieving a token with uv auth token), uv would pick the first match. Now, uv will error instead.
You cannot opt out of this behavior. Include the username in the request, e.g., uv auth token --username foo example.com.
Avoid invalidating the lockfile versions after an exclude-newer change (#17721)
Previously, changing the exclude-newer setting would cause package versions to be upgraded, ignoring the lockfile entirely. Now, uv will only change package versions if they are no longer within the exclude-newer range.
You can restore the previous behavior by using --upgrade or --upgrade-package to opt-in to package version changes.
Upgrade uv format to Ruff 0.15.0 (#17838)
uv format now uses Ruff 0.15.0, which uses the 2026 style guide. See the blog post for details.
The formatting of code is likely to change. You can opt out of this behavior by requesting an older Ruff version, e.g., uv format --version 0.14.14.
Update uv crate test features to use test- as a prefix (#17860)
This change only affects redistributors of uv. The Cargo features used to gate test dependencies, e.g., pypi, have been renamed with a test- prefix for clarity, e.g., test-pypi.
uv python upgrade and uv python install --upgrade (#17766)
When installing Python versions, an intermediary directory without the patch version attached will be created, and virtual environments will be transparently upgraded to new patch versions.
See the Python version documentation for more details.
uv add --bounds and the add-bounds configuration option (#17660)
This does not come with any behavior changes. You will no longer see an experimental warning when using uv add --bounds or add-bounds in configuration.
uv workspace list and uv workspace dir (#17768)
This does not come with any behavior changes. You will no longer see an experimental warning when using these commands.
extra-build-dependencies (#17767)
This does not come with any behavior changes. You will no longer see an experimental warning when using extra-build-dependencies in configuration.
There are no breaking changes to uv_build. If you have an upper bound in your [build-system] table, you should update it, e.g., from <0.10.0 to <0.11.0.
pyx.dev as a target in uv auth commands despite PYX_API_URL differing (#17856)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.0/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.0/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Allow comma-separated values for --extra option
Released on 2026-02-04.
--extra option (#17525)UV_HTTP_TIMEOUT error message (#17493)uv publish when using pyx (#17832)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.30/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.30/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add wheel-tag-style aliases for manylinux platform names
Released on 2026-02-03.
uv version --bump dev similar to pre-release bumps (#17796)uv publish server errors (#17787)uv publish trace logs (#17784)base and default conda environment names (#17758)PYTHONHOME inheritance when spawning different Python versions (#17821)EqualStar and NotEqualStar operators (#17751)system-configuration in sandboxes (#17829)--help (#17745)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.29/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.29/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Update CPython to use OpenSSL 3.5.5 which includes fixes for high severity CVEs (python-build-standalone#960)
Released on 2026-01-29.
default = true (#17713)uv.exe exits when uvw.exe or uvx.exe is killed (#17500)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.28/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.28/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add -t shortform for --target to uv pip subcommands
Released on 2026-01-26.
-t shortform for --target to uv pip subcommands (#17501)uv pip freeze --exclude flag (#17045)--system and --no-system in uv venv (#17647)uv pip compile attempt to download a specified --python-version if it can. (#17249)exclude-newer-package (#17665)uv python upgrade (#17653)SSL_CERT_FILE is a directory (#17503)--locked to install cargo-xwin in guide (#17530)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.27/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.27/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add a hint to update uv when a managed Python download is not found
Released on 2026-01-15.
--no-sources-package (#14910)METADATA.json and WHEEL.json in uv build backend (#15510)pyproject.toml examples for more system-level settings (#17462)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.26/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.26/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Upgrade Tcl/Tk used by CPython to 9.0
Released on 2026-01-13.
--compile-bytecode to uv python install and uv python upgrade to compile the standard library (#17088)exclude-newer per package (#16854)WM_SETTINGCHANGE on uv tool update-shell (#17404)uv run target (#17423)tool@latest version (#17448)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.25/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.25/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix handling of UV_NO_SYNC=1 uv run ...
Released on 2026-01-09.
UV_NO_SYNC=1 uv run ... (#17391)--no-cache (#17387)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.24/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.24/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Only write portable paths in RECORD files
Released on 2026-01-09.
RECORD files (#17339)UV_PYTHON_BIN_DIR and UV_TOOL_BIN_DIR (#17367)armv8l as an alias for armv7l in platform tag parsing (#17384)index.md suggestion to llms.txt (#17362)uv run uses inexact syncing by default (#17366)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.23/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.23/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Use a dedicated error message when lockfile can't be found
Released on 2026-01-06.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.22/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.22/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix regression where zstd distribution hashes were not considered valid
Released on 2025-12-30.
python install --default documentation (#9826)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.21/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.21/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
The 0.9.19 release failed to publish to crates.io and GitHub Releases, but was successfully published to PyPI, the GitHub Container Registry, and Dock
Released on 2025-12-29.
The 0.9.19 release failed to publish to crates.io and GitHub Releases, but was successfully published to PyPI, the GitHub Container Registry, and DockerHub. This is a re-release of 0.9.19, with the internal crate versions incremented to resolve the crates.io publish failure. The changelog entries for 0.9.19 are reproduced here.
uv pip compile to install missing python interpreters in cases where it would otherwise fail (#17216)uv init --bare --script (#17162)--torch-backend in uv tool commands (#17117)--no-binary and --only-binary (#17185)uv sync with JSON output format (#16981)String allocations in deserialization (#17221)UV_PYTHON_DOWNLOAD_MIRROR in uv python list (#16673)pylock.toml files (#17119)- in pip constraints, overrides, and excludes (#17188)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.20/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.20/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Nothing published for this version
Add value hints to command line arguments to improve shell completion accuracy
Released on 2025-12-16.
uv publish (#17096)uv publish (#17130)python3.x-alpine3.23 (#17100)--torch-backend in [tool.uv] (#17116)@latest requests (#17114)EntryType for file entries in tar (#17043)pyproject.toml index username in lockfile comparison (#16995)uv add with UV_GIT_LFS set (#17127)exclude-newer into optional string (#17121)exclude-newer* (#17079)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.18/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.18/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add torch-tensorrt and torchao to the PyTorch list
Released on 2025-12-09.
torch-tensorrt and torchao to the PyTorch list (#17053)--verbose in uv tool run (#17020)exclude-newer (a.k.a., dependency cooldowns) (#16814)source-exclude reference docs (#16832)UV_NO_DEV in Docker installs (#17030)UV_VERSION in docs for GitLab CI/CD (#17040)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.17/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.17/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add a 5m default timeout to acquiring file locks to fail faster on deadlock
Released on 2025-12-06.
debug subcommand to uv pip announcing its intentional absence (#16966)uv add --script (#16954)uv self update (#16838)--no-binary et al in uv pip compile (#16956)--target and --prefix in uv pip list, uv pip freeze, and uv pip show (#16955)uv workspace metadata (#16988)uv auth helper --protocol bazel command (#16886)tool.uv.build-backend.module-name but emit warnings (#16928)--project flag help text to indicate project discovery (#16965)COPY over ADD for simple cases (#16883)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.16/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.16/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Continuing the unfortunate chain of disrupted releases, this release failed due to an error publishing new PEP 740 attestations to PyPI. The release w
Released on 2025-12-02.
Continuing the unfortunate chain of disrupted releases, this release failed due to an error publishing new PEP 740 attestations to PyPI. The release workflow was re-run after removing the PEP 740 attestations (see #16944) and our GitHub and PyPI artifacts were published as normal, but the crates.io publish completed in the first run and does not match the 0.9.15 tag — instead, the crates were published at commit https://github.com/astral-sh/uv/commit/e7af5838bbd3fe00d45b0ae6f399975846dbf41b. The only difference is the inclusion of https://github.com/astral-sh/uv/pull/16885.
--torch-backend=auto (#16919)UV_HIDE_BUILD_OUTPUT to omit build logs (#16885)uv-trampoline-builder builds from crates.io by moving bundled executables (#16922)NO_COLOR and always show the command as a header when paging uv help output (#16908)0o666 permissions for flock files instead of 0o777 (#16845)astral-tl to v0.7.10 (#16887)" to narrow down a regression causing hangs in metadata retrieval (#16938)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.15/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.15/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Bump astral-tl to v0.7.10 to enable SIMD for HTML parsing
Released on 2025-12-01.
astral-tl to v0.7.10 to enable SIMD for HTML parsing (#16887).zshenv over creating a new one in tool update-shell (#16866)-e flags in uv add (#16882)UV_WORKING_DIR over UV_WORKING_DIRECTORY for consistency (#16884)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.14/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.14/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Revert "Allow --with-requirements to load extensionless inline-metadata scripts" to fix reading of requirements files from streams
Released on 2025-11-26.
--with-requirements to load extensionless inline-metadata scripts" to fix reading of requirements files from streams (#16861)Requires-Python and required environments (#16824)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.13/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.13/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Due to a permission error during publish to `crates.io`, this release was partially published and manually finished. Consequently, crates.io temporari
Released on 2025-11-24.
Due to a permission error during publish to crates.io, this release was partially published and manually finished. Consequently, crates.io temporarily did not include all of the artifacts and the GitHub Release was published by a maintainer instead of GitHub Actions. The artifacts from GitHub Actions were used without alteration. The GitHub release attestations for the artifacts are not available for this release.
--with-requirements to load extensionless inline-metadata scripts (#16744)uv publish (#16731)uv export from overwriting pyproject.toml (#16745)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.12/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Due to rate limiting during publish to `crates.io`, this release was partially published and manually finished. Consequently, crates.io temporarily di
Released on 2025-11-20.
Due to rate limiting during publish to crates.io, this release was partially published and manually finished. Consequently, crates.io temporarily did not include all of the artifacts and the GitHub Release was published by a maintainer instead of GitHub Actions. The artifacts from GitHub Actions were used without alteration. The GitHub release attestations for the artifacts are not available for this release.
See the python-build-standalone release notes for details.
uv init author serialization via toml_edit inline tables (#16778)pyproject.toml (#16734)always-authenticate when running under Dependabot (#16773)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.11/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Enforce UTF‑8-encoded license files during uv build
Released on 2025-11-17.
SSL_CERT_DIR (#16473)uv build (#16699)project.license-files glob matches nothing (#16697)pip install --target (and sync) install Python if necessary (#16694)python_downloads_json_url in pre-release Python version warnings (#16737)uv python --python-downloads-json-url (#16542)--upgrade in uv python install (#16676)python install --default for pre-release Python versions (#16706)uv workspace list to list workspace members (#16691)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.10/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Deprecate use of --project in uv init
Released on 2025-11-12.
--project in uv init (#16674)uv version --bump (#16555).rcdata to store metadata (#15068)--only-emit-workspace and similar variants to uv export (#16681)UV_NO_DEFAULT_GROUPS environment variable (#16645)torch-model-archiver and torch-tb-profiler from PyTorch backend (#16655)CMD path in FastAPI Dockerfile (#16701)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.9/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.9/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Accept multiple packages in uv export
Released on 2025-11-07.
uv export (#16603)uv sync (#16543)uv cache size command (#16032)+gil to require a GIL-enabled interpreter (#16537)uv init error for invalid directory names (#16554)uv build -h (#16632)UV_NO_GROUP as an environment variable (#16529)UV_NO_SOURCES as an environment variable (#15883)--check and --locked to be used together in uv lock (#16538)default-groups in schema (#16575)nvidia-smi (#15460)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.8/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.8/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add Windows x86-32 emulation support to interpreter architecture checks
Released on 2025-10-30.
uv auth token output (#16504)--check flag (#16521)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.7/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.7/uv-installer.ps1 | iex"
This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Py
Released on 2025-10-29.
This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Python packaging tooling. See GHSA-pqhf-p39g-3x64 for additional details.
--clear to uv build to remove old build artifacts (#16371)--no-create-gitignore to uv build (#16369)pip install --system when externally managed (#16392)uv lock --check with outdated lockfile will print that --check was passed, instead of --locked (#16322)uv init template for Maturin (#16449)uv python upgrade (#16420)--find-links distributions (#16446)uv export --frozen when the lockfile is outdated (#16407)uv tree when --package is used with circular dependencies (#15908)pip freeze --quiet (#16491)uv auth login pyx.dev retries to 60s (#16498)uv add --group ... -r ... (#16490)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.6/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.6/uv-installer.ps1 | iex"
This release contains an upgrade to astral-tokio-tar, which addresses a vulnerability in tar extraction on malformed archives with mismatching size in…
Released on 2025-10-21.
This release contains an upgrade to astral-tokio-tar, which addresses a vulnerability in tar extraction on malformed archives with mismatching size information between the ustar header and PAX extensions. While the astral-tokio-tar advisory has been graded as "high" due its potential broader impact, the specific impact to uv is low due to a lack of novel attacker capability. Specifically, uv only processes tar archives from source distributions, which already possess the capability for full arbitrary code execution by design, meaning that an attacker gains no additional capabilities through astral-tokio-tar.
Regardless, we take the hypothetical risk of parser differentials very seriously. Out of an abundance of caution, we have assigned this upgrade an advisory: https://github.com/astral-sh/uv/security/advisories/GHSA-w476-p2h3-79g9
astral-tokio-tar to 0.5.6 to address a parsing differential (#16387)uv pip install failure if the --system flag is used to select an externally managed interpreter (#16318)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.5/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.5/uv-installer.ps1 | iex"
Add auto-detection for Intel GPU on Windows
Released on 2025-10-17.
uv auth token output (#16345)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.4/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.4/uv-installer.ps1 | iex"
Obfuscate secret token values in logs
Released on 2025-10-14.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.3/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.3/uv-installer.ps1 | iex"
Avoid inferring check URLs for pyx in uv publish
Released on 2025-10-10.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.2/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.2/uv-installer.ps1 | iex"
Fix pylock.toml config conflict error messages
Released on 2025-10-09.
UV_UPLOAD_HTTP_TIMEOUT and respect UV_HTTP_TIMEOUT in uploads (#16040)UV_WORKING_DIRECTORY for setting --directory (#16125)Scripts directory (#16206)requires-python (#15927)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.1/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.1/uv-installer.ps1 | iex"
This breaking release is primarily motivated by the release of Python 3.14, which contains some breaking changes (we recommend reading the "What's new…
Released on 2025-10-07.
This breaking release is primarily motivated by the release of Python 3.14, which contains some breaking changes (we recommend reading the "What's new in Python 3.14" page). uv may use Python 3.14 in cases where it previously used 3.13, e.g., if you have not pinned your Python version and do not have any Python versions installed on your machine. While we think this is uncommon, we prefer to be cautious. We've included some additional small changes that could break workflows.
See our Python 3.14 blog post for some discussion of features we're excited about!
There are no breaking changes to uv_build. If you have an upper bound in your [build-system] table, you should update it.
Python 3.14 is now the default stable version
The default Python version has changed from 3.13 to 3.14. This applies to Python version installation when no Python version is requested, e.g., uv python install. By default, uv will use the system Python version if present, so this may not cause changes to general use of uv. For example, if Python 3.13 is installed already, then uv venv will use that version. If no Python versions are installed on a machine and automatic downloads are enabled, uv will now use 3.14 instead of 3.13, e.g., for uv venv or uvx python. This change will not affect users who are using a .python-version file to pin to a specific Python version.
Allow use of free-threaded variants in Python 3.14+ without explicit opt-in (#16142)
Previously, free-threaded variants of Python were considered experimental and required explicit opt-in (i.e., with 3.14t) for usage. Now uv will allow use of free-threaded Python 3.14+ interpreters without explicit selection. The GIL-enabled build of Python will still be preferred, e.g., when performing an installation with uv python install 3.14. However, e.g., if a free-threaded interpreter comes before a GIL-enabled build on the PATH, it will be used. This change does not apply to free-threaded Python 3.13 interpreters, which will continue to require opt-in.
Use Python 3.14 stable Docker images (#16150)
Previously, the Python 3.14 images had an -rc suffix, e.g., python:3.14-rc-alpine or
python:3.14-rc-trixie. Now, the -rc suffix has been removed to match the stable
upstream images. The -rc images tags will no longer be
updated. This change should not break existing workflows.
Upgrade Alpine Docker image to Alpine 3.22
Previously, the uv:alpine Docker image was based on Alpine 3.21. Now, this image is based on Alpine 3.22. The previous image can be recovered with uv:alpine3.21 and will continue to be updated until a future release.
Upgrade Debian Docker images to Debian 13 "Trixie"
Previously, the uv:debian and uv:debian-slim Docker images were based on Debian 12 "Bookworm". Now, these images are based on Debian 13 "Trixie". The previous images can be recovered with uv:bookworm and uv:bookworm-slim and will continue to be updated until a future release.
Fix incorrect output path when a trailing / is used in uv build (#15133)
When using uv build in a workspace, the artifacts are intended to be written to a dist directory in the workspace root. A bug caused workspace root determination to fail when the input path included a trailing / causing the dist directory to be placed in the child directory. This bug has been fixed in this release. For example, uv build child/ is used, the output path will now be in <workspace root>/dist/ rather than <workspace root>/child/dist/.
uv python upgrade / install output when there is a no-op for one request (#16158)uv tool upgrade can’t move the tool (#16081)uv python upgrade requests (#16160)uv python upgrade replacement of installed binaries on pre-release to stable (#16159)uv pip compile args in layout.md (#16155)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.0/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.0/uv-installer.ps1 | iex"
Emit a message on cache clean and prune when lock is held
Released on 2025-10-06.
cache clean and prune when lock is held (#16138)--force flag for uv cache prune (#16137)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.24/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.24/uv-installer.ps1 | iex"
Build s390x on stable Rust compiler version
Released on 2025-10-03.
s390x on stable Rust compiler version (#16082)UV_SKIP_WHEEL_FILENAME_CHECK to allow installing invalid wheels (#16046)--no-sources (#16094)--no-color on the CLI (#16044)uv pip tree output (#16078)_CONDA_ROOT in reference (#16114)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.23/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.23/uv-installer.ps1 | iex"
Upgrade astral-tokio-tar to 0.5.5 which hardens tar archive extraction
Released on 2025-09-23.
astral-tokio-tar to 0.5.5 which hardens tar archive extraction (#16004)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.22/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.22/uv-installer.ps1 | iex"
Refresh lockfile when --refresh is provided
+Released on 2025-09-23.
--refresh is provided (#15994)Add support for S3 request signing (#15925)
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.21/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.21/uv-installer.ps1 | iex"
Add --force flag for uv cache clean
Released on 2025-09-22.
--force flag for uv cache clean (#15992)freethreaded+debug Python downloads in uv python list (#15985)uv run and uvx (#15990)package level conflicts to the conflicting dependencies docs (#15963)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.20/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.20/uv-installer.ps1 | iex"
See the python-build-standalone release notes for more details.
Released on 2025-09-19.
See the python-build-standalone release notes for more details.
uv cache clean parallel process safe (#15888)platform_machine marker for win_arm64 platform tag (#15921)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.19/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.19/uv-installer.ps1 | iex"
Deprecate tool.uv.dev-dependencies
Released on 2025-09-17.
uv init defaults for native build backend cache keys (#15705)pyproject.toml target does not exist for dependency groups (#15831)--no-clear to uv venv to disable removal prompts (#15795)--only-group and --extra flags (#15788)[project] to be missing from a pyproject.toml (#14113)base and root as base environments (#15682)uv_build is skipped (#15898)_CONDA_ROOT to detect Conda base environments (#15680)uv publish upload form (#15794)uv sync (#15881)tool.uv.dev-dependencies (#15469)native-auth feature (#15872)uv sync --no-sources not switching from editable to registry installations (#15234)@latest (#15827)triton as a torch backend package (#15910)UV_INSECURE_NO_ZIP_VALIDATION=1 in duplicate header errors (#15912)NO_PROXY support (#15816)requires-python (#14282)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.18/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.18/uv-installer.ps1 | iex"
Improve error message for HTTP validation in auth services
Released on 2025-09-10.
PYX_API_URL when suggesting uv auth login on 401 (#15774)uv init --script (#15747)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.17/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.17/uv-installer.ps1 | iex"
Due to a bug in the release process for the new loongarch64 support (see #15762), this release was partially published and manually finished. Conseque
Due to a bug in the release process for the new loongarch64 support (see #15762), this release was partially published and manually finished. Consequently, the uv_build artifacts were uploaded to PyPI with a PAT instead of via OIDC and the GitHub Release was published by a maintainer instead of GitHub Actions. The artifacts from GitHub Actions were used without alteration. The uv artifacts were not affected. There should be no consequences from this; we just want to be transparent about the provenance of the artifacts.
--editable to override editable = false annotations (#15712)editable = false for workspace sources (#15708)--with-requirements and --requirements (#12763)match-runtime target is optional (#15671)uv auth (#15743)uv publish (#15759)uv auth commands take a URL (#15664)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.16/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.16/uv-installer.ps1 | iex"
Upgrade SQLite 3.50.4 in CPython builds for CVE-2025-6965 (see also python/cpython#137134)
uv auth commands for credential management (#15570)uv auth commands (#15636)uv tree --show-sizes to show package sizes (#15531)--python-platform riscv64-unknown-linux (#15630)--python-platform to uv run and uv tool (#15515)uv publish --dry-run (#15638)extra-build-dependencies (#15622)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.15/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.15/uv-installer.ps1 | iex"
Add managed CPython distributions for aarch64 musl
--python-platform to uv pip check (#15486)UV_ISOLATED (#15428)--no-install-local option to uv sync, uv add and uv export (#15328)uv pip CLI (#15453){version} on uv format failure (#15527)uv format to prevent races (#15551)--project in uv format (#15438)uv format in the project root (#15440)WHEEL and METADATA reads in installed distributions (#15489)venv in current working directory (#15537)uv publish checks (#15545)uv venv (#15538)CLICOLOR_FORCE=1 when calling build backends (#15472)uvw.exe needs to be removed (#15536)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.14/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.14/uv-installer.ps1 | iex"
Add --no-install-* arguments to uv add
--no-install-* arguments to uv add (#15375)uv init (#15377)uv format command (#15017)extra-build-dependencies if match-runtime is explicitly false (#15420)triton to torch-backend manifest (#15405)uv_build wheel hashes (#15400)--upgrade-package on the command-line as overriding upgrade = false in configuration (#15395)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.13/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.13/uv-installer.ps1 | iex"
Improve performance of zstd in Python 3.14
See the python-build-standalone release notes for details.
aarch64-pc-windows-msvc target for python-platform (#15347)uv tool update-shell (#15356)buildpack-deps:trixie, debian:trixie-slim, alpine:3.22 (#15351)match-runtime = true for dynamic packages (#15292)uv cache clean instead of clear (#15313)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.12/uv-installer.ps1 | iex"
Add Debian 13 trixie to published Docker images
extra-build-dependencies hint for any missing module on build failure (#15252)reqwest clients to RegistryClient (#15281)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.11/uv-installer.ps1 | iex"
Add support for installing Pyodide versions
aarch64 (#14399)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.8.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.8.10/uv-installer.ps1 | iex"
Your coding agent can read these notes before it upgrades. Set up the MCP server →