Commit Graph
100 Commits
Author SHA1 Message Date
Kevin StillhammerandGitHub 0f6ec07aaf docs: replace copilot instructions with AGENTS.md (#794)
## Summary
- replace the root `AGENTS.md` symlink with a real file
- move the agent instructions out of `.github/copilot-instructions.md`
into `AGENTS.md`
- trim the content down to concise, repo-specific guidance and add a
short repository orientation

## Testing
- not run (docs-only change)
2026-03-10 18:32:16 +01:00
Kevin StillhammerandGitHub 821e5c9815 docs: add cross-client dependabot rollup skill (#793)
## Summary
- add a reusable skill for the Dependabot PR rollup workflow
- place it under `.agents/skills/` for cross-client discovery
- keep the skill aligned with the Agent Skills standard and
client-agnostic

## Details
- adds `.agents/skills/dependabot-pr-rollup/SKILL.md`
- documents the workflow for:
  - finding open Dependabot PRs
  - comparing PR heads to their base branch
  - replaying only net dependency changes in a fresh worktree
  - running `npm run all`
  - optionally committing, pushing, and opening a PR

## Notes
- `.agents/skills/` is the shared interoperability location used across
multiple coding agents
- no code changes
- tests not run (documentation-only skill)
2026-03-10 18:16:24 +01:00
Kevin StillhammerandGitHub 6ee6290f1c chore(deps): bump versions (#792)
## Summary
- replicate the currently open Dependabot dependency updates in a single
branch
- update `smol-toml` to `^1.6.0`
- update `@biomejs/biome` to `2.3.8`
- regenerate `package-lock.json` and bundled `dist` output

## Notes
- `main` already includes the open Octokit Dependabot bumps, so those
PRs required no additional net changes here
- the open `smol-toml` Dependabot PR currently resolves to `^1.6.0`,
which is what this branch mirrors

## Validation
- `npm run all`
2026-03-10 17:49:45 +01:00
Kevin StillhammerandGitHub fe3617d6e9 Delete .github/workflows/dependabot-build.yml (#789)
Too many security issues and complex setup. Using a Skill instead
2026-03-07 12:12:14 +01:00
Kevin StillhammerandGitHub 2ff70eebcc Harden Dependabot build workflow (#788)
## Summary
- keep the Dependabot build workflow single-job, but harden it a bit
- replace `git-auto-commit-action` with explicit `git` commands and
step-scoped push auth
- add concurrency, a timeout, stricter Dependabot gating, and a guard
for moved PR heads

## Why
The workflow currently fails in the commit step because
`actions/checkout` uses `persist-credentials: false`, but
`git-auto-commit-action` later tries to push via `origin` without any
credentials:

```
fatal: could not read Username for 'https://github.com': No such device or address
```

This change fixes that failure while keeping credentials scoped to the
push step instead of persisting them for the whole job.

## Details
- require `github.event.pull_request.user.login == 'dependabot[bot]'`
- also require the PR head repo to match `github.repository`
- also require the head ref to start with `dependabot/`
- check out the exact PR head SHA
- run `npm ci --ignore-scripts`
- disable git hooks before commit
- skip the dist commit if the PR head moved during the run

## Validation
- `actionlint .github/workflows/dependabot-build.yml`
2026-03-07 12:05:51 +01:00
Kevin StillhammerandGitHub 02182fa02a fix: warn instead of error when no python to cache (#762)
Fixes: #754
2026-02-06 16:00:33 +01:00
Kevin StillhammerandGitHub 78cebeceac fix: use --clear to create venv (#761)
Fixes: https://github.com/astral-sh/setup-uv/issues/758
2026-02-06 10:48:26 +01:00
Kevin StillhammerandGitHub b6b8e2cd6a refactor: tilde-expansion tests as unittests and no self-hosted tests (#760) 2026-02-06 10:37:43 +01:00
Kevin StillhammerandGitHub 3511ff7054 feat: add venv-path input for activate-environment (#746)
Allow customizing the venv location while preserving working-directory
semantics via --directory.

Supersedes: #736
2026-02-04 08:40:32 +01:00
Kevin StillhammerandGitHub 8512ad0289 Clarify impact of using actions/setup-python (#732)
Closes: #724
2026-01-12 18:00:39 +01:00
Kevin StillhammerandGitHub 61cb8a9741 add outputs python-version and python-cache-hit (#728)
This commit splits up the "normal" cache containing the dependencies and
the "python" cache containing the python binaries. This will lead to a
one-time invalidation of caches.

Closes: #713
2026-01-06 18:06:29 +01:00
Kevin StillhammerandGitHub 11050edb83 fix: use uv_build backend for old-python-constraint-project (#729)
The test-no-python-version test was failing because hatchling's
dependency on pathspec was incompatible with Python 3.9,
causing a TypeError during the build process.

Fixed by switching from hatchling to uv_build backend
(0.9.22-0.10.0 range) which is fully compatible with
Python 3.9. The uv.lock file is updated to reflect the
new build backend and latest compatible versions of dependencies.
2026-01-06 17:41:21 +01:00
Kevin StillhammerandGitHub 58b6d7b303 fix: add OS version to cache key to prevent binary incompatibility (#716)
## Summary

- Adds OS name and version (e.g., `ubuntu-22.04`, `macos-14`,
`windows-2022`) to cache keys to prevent binary incompatibility when
GitHub updates runner images
- Fixes issue where cached uv binaries compiled against older
glibc/library versions fail on newer runner OS versions

## Changes

- Added `getOSNameVersion()` function to `src/utils/platforms.ts` with
OS-specific detection for Linux (via `/etc/os-release`), macOS (Darwin
kernel version mapping), and Windows
- Updated cache key format to include OS version, bumped `CACHE_VERSION`
to `"2"`
- Added `cache-key` output to expose the generated cache key for
debugging
- Added `test-cache-key-os-version` job testing across multiple OS
versions
- Updated `docs/caching.md` with cache key documentation

Closes #703
2025-12-13 17:25:42 +01:00
Kevin StillhammerandGitHub 93202d8fbe bump dependencies (#709) 2025-12-07 18:56:35 +01:00
Kevin StillhammerandGitHub 5ce090076d set biome files.maxSize to 2MiB (#708)
Account for large known checksums
2025-12-07 17:54:20 +01:00
Kevin StillhammerandGitHub 4180991cd9 allow cache-local-path w/o enable-cache (#707)
Fixes: #705
2025-12-07 17:52:54 +01:00
Kevin StillhammerandGitHub 1e862dfacb Wait 50ms before exit to fix libuv bug (#689)
Fixes: #686
2025-11-21 09:00:37 +01:00
Kevin StillhammerandGitHub 5a7eac68fb use old undici and ES2022 target for act support (#678) 2025-11-10 19:48:23 +01:00
Kevin StillhammerandGitHub 85856786d1 Bump dependencies (#664) 2025-10-26 15:59:34 +01:00
Kevin StillhammerandGitHub cb6c0a53d9 Change version in docs to v7 (#647) 2025-10-16 08:23:23 +02:00
Kevin StillhammerandGitHub dffc6292f2 Use working-directory to detect empty workdir (#645)
Fixes: #642
2025-10-16 08:21:58 +02:00
Kevin StillhammerandGitHub b1daf91f4e Update lockfile with latest npm (#636) 2025-10-13 13:15:28 +02:00
Kevin StillhammerandGitHub 3259c6206f Bump deps (#633) 2025-10-12 20:47:54 +02:00
Kevin StillhammerandGitHub bf8e8ed895 Split up documentation (#632)
Closes: #558
2025-10-12 20:27:08 +02:00
Kevin StillhammerandGitHub a5129e99f4 Add copilot-instructions.md (#630) 2025-10-11 19:18:50 +02:00
Kevin StillhammerandGitHub d18bcc753a Add value of UV_PYTHON_INSTALL_DIR to path (#628)
Closes: #610
2025-10-11 18:42:06 +02:00
Kevin StillhammerandGitHub bd1f875aba Set output venv when activate-environment is used (#627)
Closes: #622
2025-10-11 15:17:25 +02:00
Kevin StillhammerandGitHub e0249f1599 Fall back to PR for updating known versions (#623) 2025-10-10 17:23:48 +02:00
Kevin StillhammerandGitHub eb1897b8dc Bump dependencies (#613) 2025-10-07 21:44:39 +02:00
Kevin StillhammerandGitHub 535dc2664c Respect UV_CACHE_DIR and cache-dir (#612)
Fixes: #583
2025-10-07 16:08:30 +02:00
Kevin StillhammerandGitHub f610be5ff9 Use --force when pruning cache (#611)
To prevent waiting forever on other running uv processes
2025-10-07 09:42:14 +02:00
Kevin StillhammerandGitHub 3deccc0075 Use node24 instead of node20 (#608) 2025-10-07 08:44:57 +02:00
Kevin StillhammerandGitHub d9ee7e2f26 Remove deprecated input server-url (#607) 2025-10-03 19:48:56 +02:00
Kevin StillhammerandGitHub 51c3328db2 Fix test-uv-no-modify-path (#604) 2025-10-02 20:52:56 +02:00
Kevin StillhammerandGitHub f2859da213 Respect UV_NO_MODIFY_PATH (#603)
Fixes: #519
2025-10-02 17:54:15 +02:00
Kevin StillhammerandGitHub 82f21a54fe Don't assume all test passed if cancelled (#599) 2025-09-30 20:05:38 +02:00
Kevin StillhammerandGitHub d8a37f6566 Shortcut to latest version for minimum version specifier (#598)
This is faster than downloading all available versions from GitHub to
determine the highest matching version.

Fixes: #585
2025-09-30 19:55:27 +02:00
Kevin StillhammerandGitHub d0cc045d04 Always show prune cache output (#597) 2025-09-30 17:05:27 +02:00
Kevin StillhammerandGitHub 07f2cb5db9 persist credentials for version update (#584) 2025-09-23 08:28:27 +02:00
Kevin StillhammerandGitHub b75a909f75 bump deps (#569) 2025-09-14 13:04:41 +00:00
Kevin StillhammerandGitHub dc724a12b6 Add inputs restore-cache and save-cache (#568)
Closes: #555
2025-09-14 14:55:08 +02:00
Kevin StillhammerandGitHub 7edac99f96 Ignore deps starting with uv when finding uv version (#492)
Fixes: #489
2025-07-18 06:10:43 +00:00
Kevin StillhammerandGitHub de545d4421 Bump dependencies (#487) 2025-07-17 18:30:31 +00:00
Kevin StillhammerandGitHub b75ff7d7b8 Add input version-file (#486)
Closes: #411
2025-07-17 20:22:18 +02:00
Kevin StillhammerandGitHub 790df8f465 Revert "Set expected cache dir drive to C: on windows (#451)" (#460)
This reverts commit 60ecb381b4.
2025-06-24 11:16:40 +02:00
Kevin StillhammerandGitHub 445689ea25 Use latest version from manifest-file (#458)
If a manifest-file is supplied the default value of the version input
(latest) will get the latest version available in the manifest. That
might not be the actual latest version available in the official uv
repo.
2025-06-19 21:23:43 +02:00
Kevin StillhammerandGitHub a02a550bdd Look for version-manifest.json relative to action path (#456)
Fixes: #455
2025-06-18 23:09:13 +02:00
Kevin StillhammerandGitHub 60cc2b4585 Add input manifest-file (#454)
Adds capability to maintain custom uv builds or to override the default
sources
2025-06-18 20:33:20 +00:00
Kevin StillhammerandGitHub 60ecb381b4 Set expected cache dir drive to C: on windows (#451)
Seems like the temp folder got moved to the C: drive
2025-06-17 09:40:23 +02:00
Kevin StillhammerandGitHub c19c1b1ffd Check that all jobs are in all-tests-passed.needs (#432) 2025-05-27 18:25:00 +02:00
Kevin StillhammerandGitHub f0ec1fc3b3 Bump dependencies (#424) 2025-05-23 09:57:11 +02:00
Kevin StillhammerandGitHub e3d2ea5ff3 Purge cache in cache key (#423)
Fixes: #416
2025-05-23 09:43:52 +02:00
Kevin StillhammerandGitHub 0e9cccb4b0 Fix path to known-checksums.ts (#404) 2025-05-08 09:37:11 +02:00
Kevin StillhammerandGitHub b87cce2fc5 Fix update-known-versions workflow argument (#401)
Use version-manifest.json instead of .ts
2025-05-04 07:10:02 +00:00
Kevin StillhammerandGitHub 9641fcd493 Fix update-known-versions workflow (#400)
Add missing argument versionsManifestFilePath
2025-05-04 09:01:52 +02:00
Kevin StillhammerandGitHub a4f1f549e9 Create version-manifest.json on uv release (#399) 2025-05-03 19:51:16 +02:00
Kevin StillhammerandGitHub ced7c1dde4 Run infrastructure workflows on arm runners (#396)
Use more efficient runners to save resources. Every bit counts.
2025-05-01 20:22:40 +02:00
Kevin StillhammerandGitHub 6b9c6063ab Bump dependencies (#389) 2025-04-29 22:50:17 +02:00
Kevin StillhammerandGitHub ef6bcdff59 Fix default cache dependency glob (#388)
The new default in v6 used illegal patterns and therefore didn't match
requirements files

Fixes: #385
2025-04-29 22:42:06 +02:00
Kevin StillhammerandGitHub c7f87aa956 bump to v6 in README (#382) 2025-04-24 15:29:56 +02:00
Kevin StillhammerandGitHub aadfaf08d6 Change default cache-dependency-glob (#352)
To support more users by default we should support popular dependency
file formats. A quick GitHub search shows ~40k uses of `constraint.txt`
and ~16k uses of `requirements.in`.

Closes: #261
2025-04-24 15:18:27 +02:00
Kevin StillhammerandGitHub a0f9da6273 No default UV_CACHE_DIR on selfhosted runners (#380)
Closes: #371
2025-04-24 15:17:56 +02:00
Kevin StillhammerandGitHub ec4c691628 new inputs activate-environment and working-directory (#381)
venv activation was implicit when python-version was supplied. This now
only happens when activate-environment is true. working-directory
controls where we work and thus also where the .venv will be created

Closes: #351
Closes: #271
Closes: #251
Closes: #211
2025-04-24 15:17:35 +02:00
Kevin StillhammerandGitHub fb3a0a97fa log info on venv activation (#375)
Make sure we get more info by default instead of just exiting with 1
Contributes to: #374
2025-04-17 21:02:21 +02:00
Kevin StillhammerandGitHub d4b2f3b6ec Make sure uv installed by setup-uv is first in PATH (#373)
Fixes: #372
2025-04-16 10:31:45 +00:00
Kevin StillhammerandGitHub 839076380b Fix pep440 identifier instead of specifier (#358) 2025-03-31 06:49:49 +00:00
Kevin StillhammerandGitHub 0c5e2b8115 Add pep440 to docs header (#355) 2025-03-30 16:25:01 +00:00
Kevin StillhammerandGitHub 794ea9455c Add support for pep440 version identifiers (#353)
Fixes: #264
2025-03-30 18:00:56 +02:00
Kevin StillhammerandGitHub 224dce1d79 Add link to supported glob patterns (#348)
Closes: #346
2025-03-27 10:34:21 +00:00
Kevin StillhammerandGitHub 22695119d7 Add uv-path and uvx-path output (#341)
Closes: #338
2025-03-21 13:44:23 +01:00
Kevin StillhammerandGitHub 1fb7cdfc29 Merge workflows and add all-tests-passed (#331) 2025-03-19 16:51:30 +01:00
Kevin StillhammerandGitHub 72002e8b87 Fix wrong warning message in FAQ (#337) 2025-03-19 11:12:56 +00:00
Kevin StillhammerandGitHub 389b596663 Set required workflow permissions (#329) 2025-03-18 15:21:29 +01:00
Kevin StillhammerandGitHub 04c950a723 Add workflow_dispatch triggers to every workflow (#326)
Allows for easier testing.
2025-03-18 15:04:58 +01:00
Kevin StillhammerandGitHub d02c4c2d68 Bump dependencies (#324) 2025-03-17 10:32:59 +01:00
Kevin StillhammerandGitHub a4fd982317 Inline action-update-semver (#323)
What the action does is easily inlined. This reduces the attack surface
of this repo.
2025-03-16 21:17:49 +00:00
Kevin StillhammerandGitHub a05a582c56 Warn when the workdir is empty (#322)
Closes: #306
2025-03-16 22:15:17 +01:00
Kevin StillhammerandGitHub 0e855c90d0 Remove apk add python3 for musl test (#319) 2025-03-12 09:27:54 +01:00
Kevin StillhammerandGitHub f94ec6bedd bump dependencies (#308) 2025-02-28 16:35:57 +00:00
Kevin StillhammerandGitHub 0313224678 Always fall back to anonymous download (#304)
Closes: #268
Closes: #305
2025-02-28 17:25:17 +01:00
Kevin StillhammerandGitHub 1edb52594c Add more debug logs (#297) 2025-02-21 11:10:37 +01:00
Kevin StillhammerandGitHub a4fbf7b827 Add FAQ on resolution strategy and cache not found warnings (#296)
Fixes: #294
2025-02-21 10:47:37 +01:00
Kevin StillhammerandGitHub e2e9087257 Support OS using musl (#284)
Fixes: #278
2025-02-17 10:32:34 +01:00
Kevin StillhammerandGitHub f95cd8710c Run update-known-checksums every night (#273) 2025-02-06 07:45:58 +00:00
Kevin StillhammerandGitHub 4db96194c3 Do not expect GITHUB_TOKEN to be set or valid (#262)
This fixes issues with GHES

Fixes: #221
2025-01-30 14:37:07 +01:00
Kevin StillhammerandGitHub 1c21f62d98 Fix TOC (#257) 2025-01-27 18:17:02 +01:00
Kevin StillhammerandGitHub 14dc0be27c Fallback if toml file parsing failed (#246) 2025-01-16 16:54:33 +01:00
Kevin StillhammerandGitHub b5f58b2abc Support toml spec 1.0.0 (#245)
iarna/toml is unmaintained.
Replaced by smol-toml which is maintained and has the same api

Fixes: #242
2025-01-16 16:38:18 +01:00
Kevin StillhammerandGitHub 4e3dbecc19 Add venv/bin as absolute path to PATH (#241)
Fixes: #239
2025-01-16 09:14:32 +00:00
Kevin StillhammerandGitHub 9fffe05b88 Add documentation for new inputs uv-file and pyproject-file (#235) 2025-01-13 14:32:41 +00:00
Kevin StillhammerandGitHub 5ce9ee0011 Detect required-version from config file (#233)
1. If defined use version input
2. If defined use uv-file input
3. If defined use pyproject-file input
4. Search for required-version in uv.toml in repo root
5. Search for required-version in pyproject.toml in repo root
6. Use latest

Closes: #215
2025-01-13 15:24:25 +01:00
Kevin StillhammerandGitHub 887a942a15 Set VIRTUAL_ENV to .venv instead of .venv/bin (#210)
Closes: #209
2024-12-23 17:45:21 +01:00
Kevin StillhammerandGitHub d174a24c07 Align use of actions/setup-python with uv docu (#207)
Closes: #197
2024-12-22 11:13:40 +00:00
Kevin StillhammerandGitHub 12c852e6ba Remove uv version from cache key (#206)
This approach was copied from setup-rye but uv now has the capability to
determine if a cache version is compatible. By removing it we will less
frequently invalidate the cache and thus save bandwidth

Closes: #203
2024-12-22 12:12:29 +01:00
Kevin StillhammerandGitHub 180f8b4439 Fix wrong cacheDependencyPathHash (#201)
Introduced in https://github.com/astral-sh/setup-uv/pull/200 and not
caught because the test is not needed for automerge to pass
2024-12-20 11:42:38 +01:00
Kevin StillhammerandGitHub e3fb95a689 Warn instead of fail for no-dependency-glob (#200)
Closes: #199
2024-12-20 10:32:52 +00:00
Kevin StillhammerandGitHub dd578776bb Auto activate venv when python-version is set (#194)
Closes: #124
2024-12-20 08:24:43 +01:00
Kevin StillhammerandGitHub 856099c958 Add python version to cache key (#187)
Closes: #182
2024-12-13 20:52:12 +01:00
Kevin StillhammerandGitHub e3017a763c Default to enable-cache: true on GitHub hosted runners (#193)
Closes: #54
2024-12-13 20:12:42 +01:00
Kevin StillhammerandGitHub 3460fe1a9a Always use api.github.com (#191)
The octokit client would default to the URL of enterprise instances and
then not be able to find the uv repo.

Closes: #188
2024-12-11 18:42:54 +01:00