Merge rust-bitcoin/rust-bitcoin#6839: build(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.2
2427fa6add1a172cc87ba57eef70dfae8ca9bb62 build(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.2 (dependabot[bot])
Pull request description:
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.2.0 to 8.3.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's releases</a>.</em></p> <blockquote> <h2>v8.3.2 🌈 update known checksums for 0.11.28</h2> <h2>Changes</h2> <p>Just a maintenance release</p> <h2>🧰 Maintenance</h2> <ul> <li>chore: update known checksums for 0.11.28 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/947">#947</a>)</li> </ul> <h2>📚 Documentation</h2> <ul> <li>docs: update version references to v8.3.1 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/946">#946</a>)</li> </ul> <h2>⬆️ Dependency updates</h2> <ul> <li>chore: roll up Dependabot updates <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/948">#948</a>)</li> </ul> <h2>v8.3.1 🌈 update known checksums for 0.11.27</h2> <h2>Changes</h2> <p>Just a maintenance release</p> <h2>🧰 Maintenance</h2> <ul> <li>Change update-docs PR labels from 'update-docs' to 'documentation' <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/945">#945</a>)</li> <li>chore: update known checksums for 0.11.27 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/944">#944</a>)</li> </ul> <h2>📚 Documentation</h2> <ul> <li>docs: update version references to v8.3.0 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/939">#939</a>)</li> </ul> <h2>v8.3.0 🌈 Support uv.lock as a version-file source</h2> <h2>Changes</h2> <p>Thanks to <a href="https://github.com/somaz94"><code>@somaz94</code></a> you can now use the pinned version of uv itself in <code>uv.lock</code>. It gets picked up automatically. If you have pinned another version of uv in your <code>uv.lock</code> you can use the inputs <code>version</code> or <code>version-source</code> to override this.</p> <h2>🐛 Bug fixes</h2> <ul> <li>Strip environment markers from detected uv dependency pins <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/938">#938</a>)</li> <li>Fix cache keys for Python version ranges <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/937">#937</a>)</li> <li>fix: use BUILD_ID as backup for determining os version <a href="https://github.com/hgaiser"><code>@hgaiser</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/912">#912</a>)</li> </ul> <h2>🚀 Enhancements</h2> <ul> <li>feat: support uv.lock as a version-file source <a href="https://github.com/somaz94"><code>@somaz94</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/918">#918</a>)</li> </ul> <h2>🧰 Maintenance</h2> <ul> <li>ci: call docs update workflow from release <a href="https://github.com/eifinger"><code>@eifinger</code></a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/933">#933</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/setup-uv/commit/11f9893b081a58869d3b5fccaea48c9e9e46f990"><code>11f9893</code></a> chore: roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/948">#948</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/f79855603231e1609d02bec6956bd0e05cbc46b5"><code>f798556</code></a> docs: update version references to v8.3.1 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/946">#946</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/e80544d808267c93733c3fd1e2c8c65e0c8707d6"><code>e80544d</code></a> chore: update known checksums for 0.11.28 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/947">#947</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/f98e06938123ccabd21905ea5d0069192241f9f1"><code>f98e069</code></a> Change update-docs PR labels from 'update-docs' to 'documentation' (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/945">#945</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/cd462639a967553a16241af35461402a96978d48"><code>cd46263</code></a> chore: update known checksums for 0.11.27 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/944">#944</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/11245c7e122cd1c2297e8115d1e43fe1570f6270"><code>11245c7</code></a> docs: update version references to v8.3.0 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/939">#939</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/d31148d669074a8d0a63714ba94f3201e7020bc3"><code>d31148d</code></a> Strip environment markers from detected uv dependency pins (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/938">#938</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/17c398959b4611a88929fabb5c563a8e43a0ff60"><code>17c3989</code></a> Fix cache keys for Python version ranges (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/937">#937</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/3cc3c11fdf511cab39136b7c946d973d4ad0df20"><code>3cc3c11</code></a> chore(deps): roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/936">#936</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/9225f843d7a9f80a757cf25ef48901fda69ba4bc"><code>9225f84</code></a> chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/924">#924</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/setup-uv/compare/fac544c07dec837d0ccb6301d7b5580bf5edae39...11f9893b081a58869d3b5fccaea48c9e9e46f990">compare view</a></li> </ul> </details> <br />
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
<details> <summary>Dependabot commands and options</summary> <br />
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
ACKs for top commit: apoelstra: ACK 2427fa6add1a172cc87ba57eef70dfae8ca9bb62; successfully ran local tests
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version
What changed, and why it matters
This is a routine update to a GitHub Actions helper used to install a Python tool called uv during automated security scanning workflows. It only changes the pinned version of that helper from 8.2.0 to 8.3.2 in two workflow files. There is no indication this fixes or introduces a security problem in the rust-bitcoin library itself.
Recommended action
No security action required. Treat as normal CI maintenance. If desired, review upstream astral-sh/setup-uv release notes for any future security advisories, but none are indicated here.
Security signals we found
01
No security-relevant signal: routine dependency bump in CI tooling
02
Workflows affected are security scanners (zizmor), not production code
03
No CVE, advisory, or vendor security statement present in commit or references
Technical analysis
Evidence from the diff
The commit bumps the astral-sh/setup-uv GitHub Action from commit fac544c0 (v8.2.0) to 11f9893b (v8.3.2) in .github/workflows/cron-zizmor.yml and .github/workflows/zizmor.yml. These workflows run zizmor, a static analyzer for GitHub Actions security issues. The upstream release notes describe the new version as a maintenance release updating known checksums, documentation, and dependency rollups, plus bug fixes for cache keys and environment markers. No security advisory or vulnerability disclosure is mentioned in the commit or supplied references.
This commit updates a GitHub Actions automation tool (actions/labeler) used to automatically tag pull requests with labels. It is a routine dependency version bump from 6.2.0 to 7.0.0, with no indication of a security fix or vulnerability.…
This commit is a routine update to the GitHub Actions checkout tool used by the project's automated workflows. It only changes version numbers in configuration files and does not alter the actual Bitcoin library code that users run. There …
This commit updates a GitHub Actions helper used to install a Python tool called uv, which runs the zizmor security scanner. The change only bumps the pinned version of the helper from 8.3.2 to 9.0.0. The new version's release notes mentio…
No security-relevant signals in commit or upstream release notesDependency bump in CI only, not in library codeNo CVE or advisory referenced