build(deps): Limit uv lock environments to python 3.13 (#126162)
Alternative to #126158. Instead of capping `requires-python`, keep it at `>=3.13` (#125179) and limit `[tool.uv] environments` to `python_version < '3.14'`. Only the lock's fork markers change. All Dependabot security updates for `uv.lock` currently fail (urllib3, Django, PyJWT, oauthlib): ``` uv lock --upgrade-package urllib3==2.8.0 error: No solution found when resolving dependencies for split (python_full_version >= '3.15' ...) cause: asyncpg==0.31.0 has no `sys_platform == 'darwin' or sys_platform == 'linux'`-compatible wheels ``` Since uv 0.12.14 ([astral-sh/uv#21672](https://github.com/astral-sh/uv/pull/21672)) wheel coverage is checked per resolver fork, and our internal PyPI has no cp314/cp315 wheels for several deps (asyncpg, uvloop, rpds-py, tiktoken, vroomrs, xmlsec). `bump-version.yml` is unaffected only because it pins uv 0.12.10. Compared to #126158, this keeps the project's declared Python support unchanged and only narrows what we lock for. Lifting it once the mirror builds 3.14 (and later 3.15) wheels is a one-line change. With this change, Dependabot's exact command succeeds for every open pip alert's target version.
A
Alexander Tarasov committed
b489eead8f0d4ab2597c78c183e26c819b5c6fbe
Parent: 4db0f7d
Committed by GitHub <noreply@github.com>
on 10/1/2026, 1:20:47 PM