- Sources: uv 0.12.0 release, HN 49088887
- Summary: uv 0.12.0 changes what
uv init creates: a new project declares a uv_build build system and places its source under src/. The release notes state that existing projects are unaffected and that uv init --no-package restores the previous layout. The release also rejects several legacy archive and digest formats, and several of those breaking changes have no opt-out. uv now rejects legacy .tar.bz2 and .tar.xz source distributions, including when they are referenced by an existing lockfile, rejects MD5-only digests under --require-hashes, and rejects wheels whose entry points or data files could overwrite the virtual environment interpreter. Legacy .zip source distributions remain supported for backwards compatibility. - Why it matters: A lockfile that resolved yesterday can fail to install on 0.12.0 with no flag to restore the old behaviour, so the upgrade is a pinned-dependency audit rather than a version bump.
send feedback on this story