Skip to content

chore(deps): update docker - #263

Merged
jeckersb merged 1 commit into
mainfrom
bootc-renovate/docker
Sep 21, 2026
Merged

jeckersb merged 1 commit into
mainfrom
bootc-renovate/docker

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
astral-sh/uv patch 0.12.130.12.17
block/goose minor v1.50.1v1.51.0
kani-verifier minor 0.67.00.68.0
nextest-rs/nextest patch 0.9.1440.9.145
rust-nightly patch nightly-2026-09-14nightly-2026-09-20

Release Notes

astral-sh/uv (astral-sh/uv)

v0.12.17

Compare Source

Released on 2026-09-18.

Enhancements
  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#​21780)
Preview features
  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#​21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#​20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#​21821)
  • Apply uv check lock modes when retrieving workspace metadata (#​21821)
Performance
  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#​21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#​21810)
Bug fixes
  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#​21825)
Documentation
  • Clarify the 0.12.14 and 0.12.15 release notes (#​21817)

v0.12.16

Compare Source

Released on 2026-09-17.

Python
  • Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#​21741)
Enhancements
  • Verify downloaded wheels and source distributions against hashes supplied by package indexes (#​21562)
  • Allow build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#​21467)
  • Honor Darwin platform_release markers in required-environments using macOS wheel deployment targets (#​21766)
  • Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#​21779)
Preview features
  • Support lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#​21163)
  • Honor configured and command-line index settings, including credentials, in uv upgrade (#​21776)
  • Allow uv check to run in projects that are not managed by uv and outside workspaces (#​21777)
  • Respect --python and UV_PYTHON when selecting the Python version for uv check (#​21744)
Bug fixes
  • Redact Azure shared access signatures from displayed and logged URLs (#​21755)
  • Check archive sizes from pylock.toml before reusing cached distributions (#​21609)
  • Keep user-authored local dependency paths relative in lockfiles when backend metadata reports absolute paths (#​20631)
  • Use the bundled uv_build backend only when its version matches active version pins (#​21742)
  • Handle malformed index URLs without panicking when credentials are configured (#​21784)
  • Report a configuration error instead of panicking for proxy URLs without a host (#​21781)
  • Return a credential-redacted error instead of panicking when a URL cannot be converted to a path (#​21783)

v0.12.15

Compare Source

Released on 2026-09-15.

Performance
  • Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes (#​21675)
Bug fixes
  • Fix regressions in 0.12.14 when installing to symlinked destinations or using uv pip install --target . (#​21699)

v0.12.14

Compare Source

Released on 2026-09-15.

Enhancements
  • Resume interrupted downloads with HTTP Range requests when supported (#​21570)
  • Use a consistent format for error rendering (#​17110)
  • Render error and warning causes with compact cause: labels (#​21599, #​21603)
  • Show underlying causes and hints in user warnings (#​21565)
  • Show resolver hints for failed uv tool upgrade operations (#​21566)
Preview features
  • Export multiple dependency selections from a shared lockfile in one uv export --batch invocation with the batch-export preview feature (#​21618)
Performance
  • Speed up dependency resolution from local wheelhouses by reading wheel metadata in a single blocking task (#​21619)
  • Speed up cold resolution against large package indexes by parsing Simple API responses in bounded background workers (#​21593)
  • Speed up warm-cache resolution by decoding fresh HTTP cache entries in the cache-read task (#​21621)
Bug fixes
  • Select releases that satisfy required-environments within each resolver fork instead of combining incompatible wheel coverage across forks (#​21672)
  • Install packages with paths longer than MAX_PATH on Windows systems without long-path support enabled (#​21625)
  • Prevent uv python install from overwriting valid unmanaged Python symlinks with relative targets on Unix (#​21639)
  • Redact credentials and signatures from missing-path-segment URL errors (#​21616)
  • Avoid exceeding the configured retry budget when cached HTTP responses fail revalidation (#​21640)
  • Prefer bin/python over bin/python3 when discovering interpreters in Unix environments (#​21559)
  • Classify package-operation exit codes by their underlying cause: return 1 for expected failures and 2 for recognized operational and internal failures (#​17110)
  • Suppress managed-Python fallback warnings under --quiet (#​21565)
  • Keep failed uv tool upgrade errors visible with -q while suppressing them with -qq (#​21566)
block/goose (block/goose)

v1.51.0

Compare Source

✨ Features
  • Route Desktop to state-machine loop via ACP prompt meta #​11247
  • EUrouter as a declarative provider #​11619
  • Connect external backend ACP socket to redirect-resolved backend URL #​11829
  • GPT-live API support #​12011
  • Operator allowlist for gateway pairing #​11979
  • Opt-in terminal bell when a turn finishes or approval is needed #​10182
  • Report real cause of external backend connection failures #​11828
  • Scope Toolshim to custom providers #​11414
🐛 Bug Fixes
  • Treat auto-compact 100% as disabled #​11932
  • Validate recipes consistently in scheduler #​11561
  • MCP preferred version and HTTP retries #​12066
  • Require Developer extension for doctor command #​11437
  • Keep streamed thinking ahead of text and tool calls #​11837
  • Preserved-thinking compliance for Anthropic provider layer #​11836
  • Context management dependency resolution #​11768
  • Stop mapping Astra Off to reasoning.effort none #​11976
  • Return failure for interrupted headless runs #​11938
  • Send session ID header for OpenCode Go #​11944
  • Pair Google functionResponse names with preceding request #​11888
  • Show output for failed tool calls in desktop #​11940
  • Translate session actions menu in missing locales #​11894
  • Stop re-nudging on every tool call for goals #​11697
  • Bound image response bodies in developer extension #​11411
  • Bind MCP app tools to extension owners #​11416
  • Protect gateway pairing codes #​11427
  • Bound local audio resampling for dictation #​11379
  • Restrict session storage permissions #​11613
  • Build recipes from one validated snapshot #​11612
  • Filter scheduled session content #​11603
  • Stream chat completions by default for LiteLLM #​11870
🔧 Improvements
  • Preserve resource links that cannot be inlined in ACP #​11941
  • Remove planning mode from the CLI #​12061
  • Remove create recipe command in CLI #​11942
  • RTL support for chat content #​11851
  • Use 词元/詞元 for model tokens in Chinese localization #​11945
  • Guard recipe-before-inference ordering on scheduled runs #​11502
📚 Documentation
model-checking/kani (kani-verifier)

v0.68.0

What's Changed
New Contributors

Full Changelog: model-checking/kani@kani-0.67.0...kani-0.68.0

nextest-rs/nextest (nextest-rs/nextest)

v0.9.145: cargo-nextest 0.9.145

Compare Source

Changed
  • Configuration diagnostics now name the file each setting came from. For example, cargo nextest show-config version shows which file specified the nextest-version requirement, and cargo nextest show-config test-groups shows which file each override was defined in.

    For now, this is most useful when tool-specific config files are in play, but upcoming work to support local configuration files also benefits from this. (#​3580, #​3584)

  • Config file paths in errors and warnings are now displayed relative to the directory nextest is invoked from, following typical CLI conventions. Previously, parse errors showed absolute paths and warnings showed paths relative to the workspace root. In stylized output, config file paths are now colored as well. (#​3568, #​3570, #​3577)

Fixed
  • Per-test overrides and setup and wrapper scripts defined in a profile's inheritance chain are now applied. Previously, only the selected profile's own overrides and those in profile.default were consulted, so overrides in intermediate profiles were silently skipped. As part of this change, a profile that does not set default-filter now inherits it from the nearest ancestor that does, rather than always from profile.default. (#​3585)

  • A default-filter set by a tool config file is now respected when the repository config does not set one. Previously, the tool's filter was ignored and all() was used. (#​3592)

  • Profile inheritance cycles that span multiple config files, such as a tool config file redefining a profile that the repository config inherits from, are now detected and reported as errors. Previously, cycles were only detected within a single file. (#​3588)

  • Passing --tool-config-file more than once for the same tool name now produces an error. Previously, nextest panicked internally. (#​3589)

  • The hint shown when a command requires an experimental feature that isn't enabled now points at the correct config file path when nextest is run from a subdirectory of the workspace, from outside the workspace, or with an explicit --config-file. (#​3565)

  • On Unix platforms where the Rust standard library cannot create pipes with FD_CLOEXEC set atomically (most notably Apple platforms), a test could inherit a sibling test's capture pipe if the two were spawned concurrently. The sibling was then reported as having leaked handles after it exited. Nextest now creates capture pipes itself and coordinates pipe creation with process spawning, so that spawns no longer inherit stray pipes. (#​3553)

    An upcoming design document will go over how nextest spawns processes in detail, including more information about this workaround.

    Thanks gaborbernat for your first contribution!


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "on sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
@bootc-bot
bootc-bot Bot force-pushed the bootc-renovate/docker branch from a30b776 to cecdd15 Compare September 20, 2026 02:34
@jeckersb

Copy link
Copy Markdown
Contributor

Failure is:

#13 26.88 Importing GPG key 0x75716059:
#13 26.88  Userid     : "GitHub CLI <opensource+cli@github.com>"
#13 26.88  Fingerprint: 2C61 0620 1985 B60E 6C7A C873 23F3 D4EA 7571 6059
#13 26.88  From       : https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x23F3D4EA75716059
#13 26.88 warning: Certificate 23F3D4EA75716059:
#13 26.88   The certificate is expired: The primary key is not live, because Expired on 2026-09-05T12:43:48Z
#13 26.88   Subkey 23F3D4EA75716059 is expired: The primary key is not live, because Expired on 2026-09-05T12:43:48Z
#13 26.88   Certificate does not have any usable signing keys
#13 26.88 Key imported successfully
#13 26.90 Import of key(s) didn't help, wrong key(s)?
#13 26.90 The downloaded packages were saved in cache until the next successful transaction.
#13 26.90 You can remove cached packages by executing 'dnf clean packages'.
#13 26.90 Public key for gh_2.101.0_linux_amd64.rpm is not installed. Failing package is: gh-2.101.0-1.x86_64
#13 26.90  GPG Keys are configured as: https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x23F3D4EA75716059
#13 26.91 Error: GPG check FAILED
#13 26.93 Command exited with non-zero status 123

Looks like we probably need to update which key we're using somewhere

@jeckersb

Copy link
Copy Markdown
Contributor

xref cli/cli#13118

@jeckersb

Copy link
Copy Markdown
Contributor

➡️ #267

@jeckersb
jeckersb merged commit 616c6bf into main Sep 21, 2026
19 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant