Skip to content

chore(deps): update docker - #274

Open
bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/docker
Open

bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/docker

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
astral-sh/uv patch 0.12.19 → 0.12.23
block/goose minor v1.52.0 → v1.53.0
rust-nightly patch nightly-2026-09-27 → nightly-2026-10-03

Release Notes

astral-sh/uv (astral-sh/uv)

v0.12.23

Compare Source

Released on 2026-10-03.

Python
Preview features
  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#​22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#​22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#​22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#​22017, #​22018)
Bug fixes
  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#​22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#​22099)

v0.12.22

Compare Source

Released on 2026-10-01.

Python
  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#​22147)
Enhancements
  • Accept uppercase release suffixes in wheel platform tags (#​22113)
  • Record workspace-member default groups in lockfiles (#​22010, #​22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#​22044, #​22103)
  • Record default groups for non-project workspace roots in lockfiles (#​22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#​22104)
  • Format URLs and paths consistently in CLI messages (#​21937)
  • Hide the unsupported --offline option from uv publish help (#​22124)
Preview features
  • Honor --no-default-groups in uv audit (#​22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#​22114)
Configuration
  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#​22098)
Performance
  • Reduce uv's binary size by compressing embedded Python download metadata (#​22126)
Bug fixes
  • Verify unchanged requirements against existing lockfile hashes when relocking (#​22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#​22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#​22015)
  • Avoid false entry-point warnings for required workspace members (#​22112)
Other changes
  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#​22121)

v0.12.21

Compare Source

Released on 2026-09-29.

Python
  • Update CPython to use OpenSSL 3.5.9 (#​22076)
Enhancements
  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#​22070)
Preview features
  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#​22004, #​22068)
Bug fixes
  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#​21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#​22049)

v0.12.20

Compare Source

Released on 2026-09-28.

Enhancements
  • Reuse lockfiles when dependency declarations are semantically equivalent (#​21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#​21990)
Preview features
  • Write normalized requirement declarations with the lockfile-normalization preview feature (#​21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#​22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#​22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#​22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#​22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#​22050)
Configuration
  • Continue searching XDG_CONFIG_DIRS after empty entries (#​21987)
Performance
  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#​22051)
Bug fixes
  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#​21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#​21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#​21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#​21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#​21979)
  • Prevent commands from running and changing state after displaying --show-settings (#​21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#​21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#​22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#​22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#​22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#​22034)
block/goose (block/goose)

v1.53.0

Compare Source

✨ Features
  • Resizable Picture-in-Picture window for MCP Apps #​12417
  • Fetch model metadata from models.dev live with bundled fallback #​12560
  • Quoting action to append selected conversation text to composer #​12536
  • Lean ACP-only Goose binary #​11961
  • Model discovery API for GDK Provider #​12497
  • Meta Muse Code provider #​11765
  • Support for Opus 5.5, GPT-6-sol, GPT-6-luna #​12447
  • Session rename command in CLI #​12236
  • Show working directory in session remove command #​12232
  • GDK agent loop runs on wasm32 #​12569
🐛 Bug Fixes
  • Session naming and "none" reasoning effort for GPT-6.1-sol #​12605
  • Strip inert parameters from session snapshots in recipes #​11988
  • Preserve session context across reply lifecycle #​12516
  • Report max_tokens truncation and flush tool calls for Bedrock #​11872
  • Require a terminal for elicitation input in CLI #​12542
  • Keep tool results consecutive when OpenAI-compatible tool images are emitted #​12233
  • GDK tools with no args still advertise empty params input schema #​12527
  • Passing thinking effort to Ollama models #​12555
  • Estimate costs through canonical provider aliases #​11916
  • Resolve vision support from the canonical catalog for all providers #​12522
  • Send Databricks v2 Claude model services through the Anthropic route #​12486
  • Show tool output for tools without a priority annotation #​12436
  • Treat an unavailable prompt classifier as no signal #​12452
  • Guard MCP streamable-HTTP client redirects against SSRF #​11501
  • Resolve vision support from the canonical catalog in GDK so tool result images reach the model #​12440
  • Prevent Extension Manager from disabling itself #​12270
  • Rename deepseek-v4-flash to deepseek-flash #​12269
  • Auto-compact at tool boundaries in the unrolled agent loop #​12444
  • Remediate GHSA-6mg9-3cvh-9939 security vulnerability #​12537
🔧 Improvements
  • Suppress warning when ending on a successful tool call #​12468
  • Update rmcp to 3.4.1 #​12483
  • Remove MCP sampling code #​12193
  • Remove production code only reachable from tests #​12504
  • Pin remaining GitHub Actions to commit SHAs #​11989
📚 Documentation
  • Warn about keyring hang in unattended ACP environments #​12173

Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "on sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants