AI NewsDev toolsAnnouncement

Astral releases uv 0.13.0 with eight breaking changes

Astral released uv 0.13.0 with eight breaking changes, including Python 3.15 as the default stable version, strict hash validation in included constraints files, and a new tar backend that rejects some older archives.

AI News

Editorial2 min read

LinkedInX
Astral uv logo on the release page for 0.13.0

Why it mattersA team pinning uv in CI needs to read the eight breaking changes before upgrading, because a build that passed on 0.12 can now fail on a hash check, an older archive, or a changed path parse.

A Python team that pinned uv at 0.12 and ran uv sync every morning now has eight reasons to read release notes before upgrading. Astral released uv 0.13.0, the version Astral itself labels with eight breaking changes.

The first change is the default stable Python. uv 0.13.0 downloads CPython 3.15 when no version is pinned, where 0.12 downloaded 3.14. A project with no version pinned, including anything that calls uv run on a bare script, will now resolve against a different interpreter than it did on the previous release. CPython 3.15.0 was added in the same release.

The seven other breaks, in plain words

Astral says uv now honours --require-hashes in constraints files pulled in with -c, where the directive was ignored before. An installation that worked on 0.12 can fail here if any included constraint sets the flag and any requirement is missing a hash. In the same category, uv now rejects editable (-e) requirements in a constraints file instead of silently dropping them, which Astral says matches pip's behaviour.

On Windows ARM64 machines, uv now prefers native aarch64 interpreters where it picked an emulated x86_64 before. The fallback is still there, so a project that depends on an x86-only wheel is not broken, but a build that happened to pick an emulated interpreter will switch architectures on the next run without any flag change.

Three more changes are smaller but can still break a build. uv 0.13.0 switches its tar backend from astral-tokio-tar to tar-codec, which Astral says applies stricter validation and will reject some archives the old backend accepted. Options such as --constraint now treat each value as a single path rather than splitting on spaces, so a path with a space in it works now and two paths on one flag do not. uv build --clear now refuses to delete an output directory that contains a build source, which blocks a class of accidents where the clear step removes the project files.

The eighth change is about Python startup. uv no longer writes _virtualenv.py and _virtualenv.pth into virtual environments on Python 3.10 or newer, which Astral says reduces Python startup overhead. The patch stays for 3.9 and earlier.

One preview, and the usual performance notes

The 0.13.0 release adds a preview --require-build-hashes flag, which extends the hash requirement to the packages a project builds against rather than only the packages it installs. Astral lists four performance improvements alongside the breaking changes: HTTP response revalidation, fewer allocations in cached response handling, smaller cache storage for policy and record data, and fewer allocations in cached source distribution revisions.

Astral does not state why these changes land in 0.13 rather than another 0.12 patch, and no migration guide is linked from the release page. The notes themselves list the breaking changes with the exact option names and file paths that trigger each one, which is where a team upgrading in CI should start.

Source

Astral.

SourceAstral

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX
Start a project