uv 0.12.18: Security Fix for Windows Path Traversal, Pip Enhancements
uv version 0.12.18 has been released, including a security fix for a path traversal vulnerability (GHSA-2cv4-cqwr-gwf7) affecting Windows during wheel installation. This update introduces `--output-format json` for `uv pip install` and `uv pip sync`, along with a new `--check` flag to report planned changes without modifying the environment. The release also delivers general enhancements, performance improvements, and bug fixes across the tool. Users on Windows are advised to update to mitigate the path traversal risk.
- →Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check
- →Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment
- →Identify failures from get_requires_for_build_* hooks correctly in build errors
- →Speed up uv_build editable wheel creation by omitting compression from temporary wheels
- →Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#21860, #21856)
Features (1) ›
Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out
Enhancements (4) ›
- Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check
- Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment
- Identify failures from get_requires_for_build_* hooks correctly in build errors
- Speed up uv_build editable wheel creation by omitting compression from temporary wheels
Fixes (7) ›
Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#21835, #21836)
- Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#21860, #21856)
- Use configured dependency-metadata when checking whether installed requirements are satisfied
- Reject archive entries that normalize to absolute Windows paths
- Recognize distribution filenames and archive extensions when URL fragments contain ?
- Generate correctly lowercased platform tags for BSD and Haiku releases
- Avoid rebuilding a Windows relative path into an absolute form
https://github.com/astral-sh/uv/releases/tag/0.12.18
Related releases
- Python Documentation Now Available in German Python Insider ·
- pydantic-ai v2.51.0 Adds OpenAI GPT-Live Support and Refines AI Model Compatibility Pydantic AI Releases ·
- Google ADK for Python v2.10.0 Boosts Skill Lifecycles, DB Integrations, and Eval Metrics Google ADK (Python) Releases ·
- PEP 848 Proposes Generational Incremental Garbage Collection for CPython Python PEPs ·
- Pydantic-AI v2.50.0 Introduces DecisionModel and Gemini Realtime Support Pydantic AI Releases ·
- uv 0.12.19 Released with PyPy/GraalPy Updates and New Preview Features uv Releases ·