NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #226 most downloaded on PyPI
An extremely fast Python package and project manager, written in Rust.
Last release today
03 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
322 releases · first in 2024
Add a diagnostic for uv add with standard library modules
Released on 2026-05-28.
uv add with standard library modules (#19572)uv workspace and its list subcommand in help output (#19533)ignore-error-codes when applicable (#19521)import-names and import-namespaces support to uv-build (PEP 794) (#19380)--no-editable-package flag to various commands (#19584)uv tool invocations (#19577)uv workspace metadata (#19122)uv venv --clear to remove non-virtual environments (#19595)tool.uv.conflicts (#19538)--env-file in uv run (#19567)--check-url (#19594)--find-links parsing (#19537)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.17/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.17/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
One column per month.
Add support for direct archive dependencies in Git
Released on 2026-05-21.
UV_NO_SYSTEM_CONFIG (#19476)uv-build (#19495)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.16/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.16/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix a TAR parser differential, see GHSA-3cv2-h65g-fgmm
Released on 2026-05-18.
required-environments in uv pip compile (#19378)Version::only_release_trimmed (#19425)[tool.uv.sources] credentials under uv sync --frozen (#19423)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.15/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Ignore top_level.txt entries in uninstall that are not valid Python identifiers
Released on 2026-05-12.
top_level.txt entries in uninstall that are not valid Python identifiers (#19340).env files in parent process (#19343)uv tree showing extra-conditional deps for packages required without extras (#19332)--no-build) during lock validation (#19366)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.14/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.14/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Include data files in editable builds
Released on 2026-05-10.
--require-hashes when installing from pylock.toml files (#19334)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.13/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.13/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add --no-editable support to uv pip install
Released on 2026-05-08.
--no-editable support to uv pip install (#19306)Respect --no-dev over UV_DEV=1 (#19313)
Don't suggest non-existent --no-frozen flag (#19290) (#19294)
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.12/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Accept legacy ID format from pre-0.11.9 cache entries
Released on 2026-05-06.
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.11/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Allow pre-release Python requests with non-zero patch versions
Released on 2026-05-05.
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.10/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Mark --native-tls and UV_NATIVE_TLS as deprecated
Released on 2026-05-04.
Note due to a timeout publishing to crates.io, the GitHub portion of this release was published manually by a maintainer using the artifacts built in CI. Consequently, GitHub attestations will not be available. Additionally, this release will not be fully published to crates.io. There should be no other effects.
This release includes a special release candidate for the next Python 3.14 patch release. Python 3.14 included a new garbage collection implementation, which reduced pause times but caused significant unexpected memory pressure in production environments. In 3.14.5 and 3.15, the previous garbage collection implementation will be restored.
We would greatly appreciate if you tested the 3.14.5rc1 version included in this release. The stable version is expected to be released soon and any feedback on potential issues would be helpful to the Python development team.
For more context, see the announcement, issue, and pull request.
Issues with the new release can be reported in the uv or CPython issue trackers.
libpython to match Linuxuv audit add reporting for adverse project statuses (#19128)requires-python pins a version (#18700)LockedFile::drop on Wine (#19229)top_level.txt in .egg-info (#19114)PYTHONHOME and only set __PYVENV_LAUNCHER__ for virtual environments (#19199)--native-tls and UV_NATIVE_TLS as deprecated (#18705)pytorch-triton-rocm to PyTorch ROCm docs (#19241)uv init creates git files / folders in the projects guide (#19183)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.9/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.9/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Remove deprecated license classifiers from uv-build and add Python 3.14 classifier
Released on 2026-04-27.
--python-downloads-json-url to python pin (#19092)pip uninstall -y (#19082)exclude-newer to be missing from the lockfile when exclude-newer-span is present (#19024)uv self version --short (#19019)SSL_CERT_DIR directory (#19018)exclude-newer and exclude-newer-package values in lockfiles (#19022, #19101)UV_PYTHON_NO_REGISTRY (#19035)UV_NO_PROJECT (#19052)UV_PYTHON_SEARCH_PATH for Python discovery PATH overrides (#19034)rust-toolchain.toml to uv-build sdist (#19131)uv lock on a pyproject.toml that only contains dependency-groups (#19087).python-version (#19102).tar.zst wheels (#19144)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.8/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.8/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Upgrade CPython build to 20260414 including an OpenSSL security upgrade
Released on 2026-04-15.
required-version mismatches (#18977)--exclude-newer hints (#18952)workspace metadata in linehaul data (#18966)uv sync --check failures (#18976)~= operators (#18960)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.7/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.7/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
This release resolves a low severity security advisory in which wheels with malformed RECORD entries could delete arbitrary files on uninstall. See GH
Released on 2026-04-09.
This release resolves a low severity security advisory in which wheels with malformed RECORD entries could delete arbitrary files on uninstall. See GHSA-pjjw-68hj-v9mw for details.
RECORD during installation (#18943)uv cache clean errors due to Win32 path normalization (#18856)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.6/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.6/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
uv audit: add context/warnings for ignored vulnerabilities
Released on 2026-04-08.
build_system.requires error message (#18911)exclude-newer to [[tool.uv.index]] (#18839)uv audit: add context/warnings for ignored vulnerabilities (#18905)PIP_COMPATIBILITY.md redirect file (#18928)uv init example-bare --bare examples (#18822, #18925)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.5/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.5/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add support for --upgrade-group
Released on 2026-04-07.
--upgrade-group (#18266)pyproject.toml dependencies (#18786)--locked and --frozen when script lockfile is missing (#18832)uv export extra resolution for workspace member and conflicting extras (#18888)exclude-newer values during uv tree --outdated (#18899)--exclude-newer in uv tool list --outdated (#18861)Cargo.lock in uv-build source distributions (#18831)--exclude-newer compares artifact upload times (#18830)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.4/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.4/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add progress bar for hashing phase in uv publish
Released on 2026-04-01.
uv workspace metadata with dependency information from the lock (#18356)/installers/uv/latest on the mirror (#18725)--ignore and --ignore-until-fixed to uv audit (#18737)blake2b hashes (#18794)powerpc64-unknown-linux-gnu from release build targets (#18800)uv pip check (#18742)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.3/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.3/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add a dedicated Windows PE editing error
Released on 2026-03-26.
uv self update fetch the manifest from the mirror first (#18679)uv self update success and failure messages with --quiet (#18645)uv run (#17890)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.2/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.2/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add missing hash verification for riscv64gc-unknown-linux-musl
Released on 2026-03-24.
riscv64gc-unknown-linux-musl (#18686)== Python version request ranges (#9697)--python <dir> in "Using arbitrary Python environments" (#6457)PS_MODULE_PATH and UV_WORKING_DIR (#18691)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.1/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.1/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13 which included some breaking changes to TLS certifi…
Released on 2026-03-23.
This release includes changes to the networking stack used by uv. While we think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so we have marked the change as breaking out of an abundance of caution.
The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13 which included some breaking changes to TLS certificate verification.
The following changes are included:
rustls-platform-verifier is used instead of rustls-native-certs and webpki for certificate verification
This change should have no effect unless you are using the native-tls option to enable reading system certificates.
rustls-platform-verifier delegates to the system for certificate validation (e.g., Security.framework on macOS) instead of eagerly loading certificates from the system and verifying them via webpki. The effects of this change will vary based on the operating system. In general, uv's certificate validation should now be more consistent with browsers and other native applications. However, this is the most likely cause of breaking changes in this release. Some previously failing certificate chains may succeed, and some previously accepted certificate chains may fail. In either case, we expect the validation to be more correct and welcome reports of regressions.
In particular, because more responsibility for validating the certificate is transferred to your system's security library, some features like CA constraints or revocation of certificates via OCSP and CRLs may now be used.
This change should improve performance when using system certificate on macOS, as uv no longer needs to load all certificates from the keychain at startup.
aws-lc is used instead of ring for a cryptography backend
There should not be breaking changes from this change. We expect this to expand support for certificate signature algorithms.
--native-tls is deprecated in favor of a new --system-certs flag
The --native-tls flag is still usable and has identical behavior to --system-certs.
This change was made to reduce confusion about the TLS implementation uv uses. uv always uses rustls not native-tls.
Building uv on x86-64 and i686 Windows requires NASM
NASM is required by aws-lc. If not found on the system, a prebuilt blob provided by aws-lc-sys will be used.
If you are not building uv from source, this change has no effect.
See the CONTRIBUTING guide for details.
Empty SSL_CERT_FILE values are ignored (for consistency with SSL_CERT_DIR)
See #18550 for details.
See the python-build-standalone release notes for details.
--service-format and --service-url to uv audit (#18571)uv tool list --outdated (#18586)uv export for workspace member packages with conflicts (#18635)FLASH_ATTENTION_SKIP_CUDA_BUILD guidance for flash-attn installs (#18473)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.0/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.0/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add support for using Python 3.6 interpreters
Released on 2026-03-19.
--no-emit-package (#18565)uv audit in the CLI help (#18540)uv python list (#18459)uv-docker-example (#18558)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.12/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fetch Ruff release metadata from an Astral mirror
Released on 2026-03-16.
--project to refer to a pyproject.toml directly and reduce to a warning on other files (#18513)SYSTEM_VERSION_COMPAT when querying interpreters on macOS (#18452)uv sync --active recreating active environments when UV_PYTHON_INSTALL_DIR is relative (#18398)-o requirements.txt in uv pip compile example (#12308)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.11/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add --outdated flag to uv tool list
Released on 2026-03-13.
--outdated flag to uv tool list (#18318)--project directory does not exist (#17714)uv init (#18417)uv cache clear an alias of uv cache clean (#18420)uv_build (#18419)uv audit output (#18392)uv audit (#18193)uv audit (#18394)uv tool install --force (#18399)uv export (#18433)Content-Type (#18334)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.10/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add fbgemm-gpu, fbgemm-gpu-genai, torchrec, and torchtune to the PyTorch list
Released on 2026-03-06.
fbgemm-gpu, fbgemm-gpu-genai, torchrec, and torchtune to the PyTorch list (#18338)uv_build settings without uv_build (#15750)/usr/lib/os-release on Linux system lookup failure (#18349)cargo auditable to include SBOM in uv builds (#18276)UV_VENV_RELOCATABLE (#18331)cp3-none-any (#17064)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.9/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.9/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add Docker images based on Docker Hardened Images
Released on 2026-03-03.
--exclude-newer filters out all versions of a package (#18217)uv_build direct build compatibility (#17902)UV_INIT_BARE environment variable for uv init (#18210)uv tool upgrade from installing excluded dependencies (#18022)pylock.toml files (#18227)--upgrade (#18226)uv tree orphaned roots and premature deduplication (#17212)after_script (#18206)curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.10.8/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix handling of junctions in Windows Containers on Windows
Released on 2026-02-27.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.7/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.7/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Apply lockfile marker normalization for fork markers
Released on 2026-02-24.
requires-python conflicting with .python-version (#18097)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.6/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.6/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add hint when named index is found in a parent config file
Released on 2026-02-23.
uv lock --frozen (#17859)pylock.toml wheels by tags and requires-python (#18081)uv publish (#17783)exclude-newer invalidates the lock file (#18100)--no-emit-workspace with --all-packages on single-member workspaces (#18098)UV_NO_DEFAULT_GROUPS rejecting truthy values like 1 (#18057)uv export formats (#17900)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.5/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.5/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Remove duplicate references to the affected paths when showing uv python errors
Released on 2026-02-17.
uv python errors (#18008)uv init / --name foo) (#17983)wheel and sdist files produced by the uv_build build backend (#18020)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.4/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.4/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Don't open file locks for writing
Released on 2026-02-16.
exclude-newer in uv format (#17651)target-workspace-discovery is enabled (#17965)uv format (#17977)cpython-3.1 is specified (#17972)--allow-existing with minor version links on Windows (#17978)u64::MAX in version segments to prevent overflow (#17985)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.3/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.3/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Deprecate unexpected ZIP compression methods
Released on 2026-02-10.
cargo-install failing due to missing uv-test dependency (#17954)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.2/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.2/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Don't panic on metadata read errors
Released on 2026-02-10.
sdist-vX/.git if it already exists (#17825)uv python update-shell over uv tool update-shell in Python docs (#17941)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.1/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.1/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
There are no breaking changes to `uv_build`. If you have an upper bound in your [build-system] table, you should update it, e.g., from <0.10.0 to <0.1…
Since we released uv 0.9.0 in October of 2025, we've accumulated various changes that improve correctness and user experience, but could break some workflows. This release contains those changes; many have been marked as breaking out of an abundance of caution. We expect most users to be able to upgrade without making changes.
This release also includes the stabilization of preview features. Python upgrades are now stable, including the uv python upgrade command, uv python install --upgrade, and automatically upgrading Python patch versions in virtual environments when a new version is installed. The add-bounds and extra-build-dependencies settings are now stable. Finally, the uv workspace dir and uv workspace list utilities for writing scripts against workspace members are now stable.
Require --clear to remove existing virtual environments in uv venv (#17757)
Previously, uv venv would prompt for confirmation before removing an existing virtual environment in interactive contexts, and remove it without confirmation in non-interactive contexts. Now, uv venv requires the --clear flag to remove an existing virtual environment. A warning for this change was added in uv 0.8.
You can opt out of this behavior by passing the --clear flag or setting UV_VENV_CLEAR=1.
Error if multiple indexes include default = true (#17011)
Previously, uv would silently accept multiple indexes with default = true and use the first one. Now, uv will error if multiple indexes are marked as the default.
You cannot opt out of this behavior. Remove default = true from all but one index.
Error when an explicit index is unnamed (#17777)
Explicit indexes can only be used via the [tool.uv.sources] table, which requires referencing the index by name. Previously, uv would silently accept unnamed explicit indexes, which could never be referenced. Now, uv will error if an explicit index does not have a name.
You cannot opt out of this behavior. Add a name to the explicit index or remove the entry.
Install alternative Python executables using their implementation name (#17756, #17760)
Previously, uv python install would install PyPy, GraalPy, and Pyodide executables with names like python3.10 into the bin directory. Now, these executables will be named using their implementation name, e.g., pypy3.10, graalpy3.10, and pyodide3.12, to avoid conflicting with CPython installations.
You cannot opt out of this behavior.
Respect global Python version pins in uv tool run and uv tool install (#14112)
Previously, uv tool run and uv tool install did not respect the global Python version pin (set via uv python pin --global). Now, these commands will use the global Python version when no explicit version is requested.
For uv tool install, if the tool is already installed, the Python version will not change unless --reinstall or --python is provided. If the tool was previously installed with an explicit --python flag, the global pin will not override it.
You can opt out of this behavior by providing an explicit --python flag.
Remove Debian Bookworm, Alpine 3.21, and Python 3.8 Docker images (#17755)
The Debian Bookworm and Alpine 3.21 images were replaced by Debian Trixie and Alpine 3.22 as defaults in uv 0.9. These older images are now removed. Python 3.8 images are also removed, as Python 3.8 is no longer supported in the Trixie or Alpine base images.
The following image tags are no longer published:
uv:bookworm, uv:bookworm-slimuv:alpine3.21uv:python3.8-*Use uv:debian or uv:trixie instead of uv:bookworm, uv:alpine or uv:alpine3.22 instead of uv:alpine3.21, and a newer Python version instead of uv:python3.8-*.
Drop PPC64 (big endian) builds (#17626)
uv no longer provides pre-built binaries for PPC64 (big endian). This platform appears to be largely unused and is only supported on a single manylinux version. PPC64LE (little endian) builds are unaffected.
Building uv from source is still supported for this platform.
Skip generating activate.csh for relocatable virtual environments (#17759)
Previously, uv venv --relocatable would generate an activate.csh script that contained hardcoded paths, making it incompatible with relocation. Now, the activate.csh script is not generated for relocatable virtual environments.
You cannot opt out of this behavior.
Require username when multiple credentials match a URL (#16983)
When using uv auth login to store credentials, you can register multiple username and password combinations for the same host. Previously, when uv needed to authenticate and multiple credentials matched the URL (e.g., when retrieving a token with uv auth token), uv would pick the first match. Now, uv will error instead.
You cannot opt out of this behavior. Include the username in the request, e.g., uv auth token --username foo example.com.
Avoid invalidating the lockfile versions after an exclude-newer change (#17721)
Previously, changing the exclude-newer setting would cause package versions to be upgraded, ignoring the lockfile entirely. Now, uv will only change package versions if they are no longer within the exclude-newer range.
You can restore the previous behavior by using --upgrade or --upgrade-package to opt-in to package version changes.
Upgrade uv format to Ruff 0.15.0 (#17838)
uv format now uses Ruff 0.15.0, which uses the 2026 style guide. See the blog post for details.
The formatting of code is likely to change. You can opt out of this behavior by requesting an older Ruff version, e.g., uv format --version 0.14.14.
Update uv crate test features to use test- as a prefix (#17860)
This change only affects redistributors of uv. The Cargo features used to gate test dependencies, e.g., pypi, have been renamed with a test- prefix for clarity, e.g., test-pypi.
uv python upgrade and uv python install --upgrade (#17766)
When installing Python versions, an intermediary directory without the patch version attached will be created, and virtual environments will be transparently upgraded to new patch versions.
See the Python version documentation for more details.
uv add --bounds and the add-bounds configuration option (#17660)
This does not come with any behavior changes. You will no longer see an experimental warning when using uv add --bounds or add-bounds in configuration.
uv workspace list and uv workspace dir (#17768)
This does not come with any behavior changes. You will no longer see an experimental warning when using these commands.
extra-build-dependencies (#17767)
This does not come with any behavior changes. You will no longer see an experimental warning when using extra-build-dependencies in configuration.
There are no breaking changes to uv_build. If you have an upper bound in your [build-system] table, you should update it, e.g., from <0.10.0 to <0.11.0.
pyx.dev as a target in uv auth commands despite PYX_API_URL differing (#17856)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.10.0/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.10.0/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Allow comma-separated values for --extra option
Released on 2026-02-04.
--extra option (#17525)UV_HTTP_TIMEOUT error message (#17493)uv publish when using pyx (#17832)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.30/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.30/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add wheel-tag-style aliases for manylinux platform names
Released on 2026-02-03.
uv version --bump dev similar to pre-release bumps (#17796)uv publish server errors (#17787)uv publish trace logs (#17784)base and default conda environment names (#17758)PYTHONHOME inheritance when spawning different Python versions (#17821)EqualStar and NotEqualStar operators (#17751)system-configuration in sandboxes (#17829)--help (#17745)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.29/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.29/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Update CPython to use OpenSSL 3.5.5 which includes fixes for high severity CVEs (python-build-standalone#960)
Released on 2026-01-29.
default = true (#17713)uv.exe exits when uvw.exe or uvx.exe is killed (#17500)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.28/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.28/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add -t shortform for --target to uv pip subcommands
Released on 2026-01-26.
-t shortform for --target to uv pip subcommands (#17501)uv pip freeze --exclude flag (#17045)--system and --no-system in uv venv (#17647)uv pip compile attempt to download a specified --python-version if it can. (#17249)exclude-newer-package (#17665)uv python upgrade (#17653)SSL_CERT_FILE is a directory (#17503)--locked to install cargo-xwin in guide (#17530)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.27/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.27/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add a hint to update uv when a managed Python download is not found
Released on 2026-01-15.
--no-sources-package (#14910)METADATA.json and WHEEL.json in uv build backend (#15510)pyproject.toml examples for more system-level settings (#17462)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.26/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.26/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Upgrade Tcl/Tk used by CPython to 9.0
Released on 2026-01-13.
--compile-bytecode to uv python install and uv python upgrade to compile the standard library (#17088)exclude-newer per package (#16854)WM_SETTINGCHANGE on uv tool update-shell (#17404)uv run target (#17423)tool@latest version (#17448)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.25/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.25/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix handling of UV_NO_SYNC=1 uv run ...
Released on 2026-01-09.
UV_NO_SYNC=1 uv run ... (#17391)--no-cache (#17387)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.24/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.24/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Only write portable paths in RECORD files
Released on 2026-01-09.
RECORD files (#17339)UV_PYTHON_BIN_DIR and UV_TOOL_BIN_DIR (#17367)armv8l as an alias for armv7l in platform tag parsing (#17384)index.md suggestion to llms.txt (#17362)uv run uses inexact syncing by default (#17366)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.23/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.23/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Use a dedicated error message when lockfile can't be found
Released on 2026-01-06.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.22/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.22/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Fix regression where zstd distribution hashes were not considered valid
Released on 2025-12-30.
python install --default documentation (#9826)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.21/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.21/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
The 0.9.19 release failed to publish to crates.io and GitHub Releases, but was successfully published to PyPI, the GitHub Container Registry, and Dock
Released on 2025-12-29.
The 0.9.19 release failed to publish to crates.io and GitHub Releases, but was successfully published to PyPI, the GitHub Container Registry, and DockerHub. This is a re-release of 0.9.19, with the internal crate versions incremented to resolve the crates.io publish failure. The changelog entries for 0.9.19 are reproduced here.
uv pip compile to install missing python interpreters in cases where it would otherwise fail (#17216)uv init --bare --script (#17162)--torch-backend in uv tool commands (#17117)--no-binary and --only-binary (#17185)uv sync with JSON output format (#16981)String allocations in deserialization (#17221)UV_PYTHON_DOWNLOAD_MIRROR in uv python list (#16673)pylock.toml files (#17119)- in pip constraints, overrides, and excludes (#17188)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.20/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.20/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Nothing published for this version
Add value hints to command line arguments to improve shell completion accuracy
Released on 2025-12-16.
uv publish (#17096)uv publish (#17130)python3.x-alpine3.23 (#17100)--torch-backend in [tool.uv] (#17116)@latest requests (#17114)EntryType for file entries in tar (#17043)pyproject.toml index username in lockfile comparison (#16995)uv add with UV_GIT_LFS set (#17127)exclude-newer into optional string (#17121)exclude-newer* (#17079)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.18/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.18/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add torch-tensorrt and torchao to the PyTorch list
Released on 2025-12-09.
torch-tensorrt and torchao to the PyTorch list (#17053)--verbose in uv tool run (#17020)exclude-newer (a.k.a., dependency cooldowns) (#16814)source-exclude reference docs (#16832)UV_NO_DEV in Docker installs (#17030)UV_VERSION in docs for GitLab CI/CD (#17040)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.17/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.17/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add a 5m default timeout to acquiring file locks to fail faster on deadlock
Released on 2025-12-06.
debug subcommand to uv pip announcing its intentional absence (#16966)uv add --script (#16954)uv self update (#16838)--no-binary et al in uv pip compile (#16956)--target and --prefix in uv pip list, uv pip freeze, and uv pip show (#16955)uv workspace metadata (#16988)uv auth helper --protocol bazel command (#16886)tool.uv.build-backend.module-name but emit warnings (#16928)--project flag help text to indicate project discovery (#16965)COPY over ADD for simple cases (#16883)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.16/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.16/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Continuing the unfortunate chain of disrupted releases, this release failed due to an error publishing new PEP 740 attestations to PyPI. The release w
Released on 2025-12-02.
Continuing the unfortunate chain of disrupted releases, this release failed due to an error publishing new PEP 740 attestations to PyPI. The release workflow was re-run after removing the PEP 740 attestations (see #16944) and our GitHub and PyPI artifacts were published as normal, but the crates.io publish completed in the first run and does not match the 0.9.15 tag — instead, the crates were published at commit https://github.com/astral-sh/uv/commit/e7af5838bbd3fe00d45b0ae6f399975846dbf41b. The only difference is the inclusion of https://github.com/astral-sh/uv/pull/16885.
--torch-backend=auto (#16919)UV_HIDE_BUILD_OUTPUT to omit build logs (#16885)uv-trampoline-builder builds from crates.io by moving bundled executables (#16922)NO_COLOR and always show the command as a header when paging uv help output (#16908)0o666 permissions for flock files instead of 0o777 (#16845)astral-tl to v0.7.10 (#16887)" to narrow down a regression causing hangs in metadata retrieval (#16938)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.15/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.15/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Bump astral-tl to v0.7.10 to enable SIMD for HTML parsing
Released on 2025-12-01.
astral-tl to v0.7.10 to enable SIMD for HTML parsing (#16887).zshenv over creating a new one in tool update-shell (#16866)-e flags in uv add (#16882)UV_WORKING_DIR over UV_WORKING_DIRECTORY for consistency (#16884)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.14/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.14/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Revert "Allow --with-requirements to load extensionless inline-metadata scripts" to fix reading of requirements files from streams
Released on 2025-11-26.
--with-requirements to load extensionless inline-metadata scripts" to fix reading of requirements files from streams (#16861)Requires-Python and required environments (#16824)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.13/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.13/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Due to a permission error during publish to `crates.io`, this release was partially published and manually finished. Consequently, crates.io temporari
Released on 2025-11-24.
Due to a permission error during publish to crates.io, this release was partially published and manually finished. Consequently, crates.io temporarily did not include all of the artifacts and the GitHub Release was published by a maintainer instead of GitHub Actions. The artifacts from GitHub Actions were used without alteration. The GitHub release attestations for the artifacts are not available for this release.
--with-requirements to load extensionless inline-metadata scripts (#16744)uv publish (#16731)uv export from overwriting pyproject.toml (#16745)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.12/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.12/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Due to rate limiting during publish to `crates.io`, this release was partially published and manually finished. Consequently, crates.io temporarily di
Released on 2025-11-20.
Due to rate limiting during publish to crates.io, this release was partially published and manually finished. Consequently, crates.io temporarily did not include all of the artifacts and the GitHub Release was published by a maintainer instead of GitHub Actions. The artifacts from GitHub Actions were used without alteration. The GitHub release attestations for the artifacts are not available for this release.
See the python-build-standalone release notes for details.
uv init author serialization via toml_edit inline tables (#16778)pyproject.toml (#16734)always-authenticate when running under Dependabot (#16773)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.11/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.11/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Enforce UTF‑8-encoded license files during uv build
Released on 2025-11-17.
SSL_CERT_DIR (#16473)uv build (#16699)project.license-files glob matches nothing (#16697)pip install --target (and sync) install Python if necessary (#16694)python_downloads_json_url in pre-release Python version warnings (#16737)uv python --python-downloads-json-url (#16542)--upgrade in uv python install (#16676)python install --default for pre-release Python versions (#16706)uv workspace list to list workspace members (#16691)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.10/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.10/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Deprecate use of --project in uv init
Released on 2025-11-12.
--project in uv init (#16674)uv version --bump (#16555).rcdata to store metadata (#15068)--only-emit-workspace and similar variants to uv export (#16681)UV_NO_DEFAULT_GROUPS environment variable (#16645)torch-model-archiver and torch-tb-profiler from PyTorch backend (#16655)CMD path in FastAPI Dockerfile (#16701)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.9/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.9/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Accept multiple packages in uv export
Released on 2025-11-07.
uv export (#16603)uv sync (#16543)uv cache size command (#16032)+gil to require a GIL-enabled interpreter (#16537)uv init error for invalid directory names (#16554)uv build -h (#16632)UV_NO_GROUP as an environment variable (#16529)UV_NO_SOURCES as an environment variable (#15883)--check and --locked to be used together in uv lock (#16538)default-groups in schema (#16575)nvidia-smi (#15460)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.8/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.8/uv-installer.ps1 | iex"
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
You can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
Add Windows x86-32 emulation support to interpreter architecture checks
Released on 2025-10-30.
uv auth token output (#16504)--check flag (#16521)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.7/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.7/uv-installer.ps1 | iex"
This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Py
Released on 2025-10-29.
This release contains an upgrade to Astral's fork of async_zip, which addresses potential sources of ZIP parsing differentials between uv and other Python packaging tooling. See GHSA-pqhf-p39g-3x64 for additional details.
--clear to uv build to remove old build artifacts (#16371)--no-create-gitignore to uv build (#16369)pip install --system when externally managed (#16392)uv lock --check with outdated lockfile will print that --check was passed, instead of --locked (#16322)uv init template for Maturin (#16449)uv python upgrade (#16420)--find-links distributions (#16446)uv export --frozen when the lockfile is outdated (#16407)uv tree when --package is used with circular dependencies (#15908)pip freeze --quiet (#16491)uv auth login pyx.dev retries to 60s (#16498)uv add --group ... -r ... (#16490)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.6/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.6/uv-installer.ps1 | iex"
This release contains an upgrade to astral-tokio-tar, which addresses a vulnerability in tar extraction on malformed archives with mismatching size in…
Released on 2025-10-21.
This release contains an upgrade to astral-tokio-tar, which addresses a vulnerability in tar extraction on malformed archives with mismatching size information between the ustar header and PAX extensions. While the astral-tokio-tar advisory has been graded as "high" due its potential broader impact, the specific impact to uv is low due to a lack of novel attacker capability. Specifically, uv only processes tar archives from source distributions, which already possess the capability for full arbitrary code execution by design, meaning that an attacker gains no additional capabilities through astral-tokio-tar.
Regardless, we take the hypothetical risk of parser differentials very seriously. Out of an abundance of caution, we have assigned this upgrade an advisory: https://github.com/astral-sh/uv/security/advisories/GHSA-w476-p2h3-79g9
astral-tokio-tar to 0.5.6 to address a parsing differential (#16387)uv pip install failure if the --system flag is used to select an externally managed interpreter (#16318)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.5/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.5/uv-installer.ps1 | iex"
Add auto-detection for Intel GPU on Windows
Released on 2025-10-17.
uv auth token output (#16345)curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.4/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.4/uv-installer.ps1 | iex"
Obfuscate secret token values in logs
Released on 2025-10-14.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.3/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.3/uv-installer.ps1 | iex"
Avoid inferring check URLs for pyx in uv publish
Released on 2025-10-10.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/astral-sh/uv/releases/download/0.9.2/uv-installer.sh | sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/astral-sh/uv/releases/download/0.9.2/uv-installer.ps1 | iex"
Your coding agent can read these notes before it upgrades. Set up the MCP server →