SIGN IN SIGN UP

build(deps): Limit uv lock environments to python 3.13 (#126162)

Alternative to #126158. Instead of capping `requires-python`, keep it at
`>=3.13` (#125179) and limit `[tool.uv] environments` to `python_version
< '3.14'`. Only the lock's fork markers change.

All Dependabot security updates for `uv.lock` currently fail (urllib3,
Django, PyJWT, oauthlib):

```
uv lock --upgrade-package urllib3==2.8.0
error: No solution found when resolving dependencies for split (python_full_version >= '3.15' ...)
  cause: asyncpg==0.31.0 has no `sys_platform == 'darwin' or sys_platform == 'linux'`-compatible wheels
```

Since uv 0.12.14
([astral-sh/uv#21672](https://github.com/astral-sh/uv/pull/21672)) wheel
coverage is checked per resolver fork, and our internal PyPI has no
cp314/cp315 wheels for several deps (asyncpg, uvloop, rpds-py, tiktoken,
vroomrs, xmlsec). `bump-version.yml` is unaffected only because it pins
uv 0.12.10.

Compared to #126158, this keeps the project's declared Python support
unchanged and only narrows what we lock for. Lifting it once the mirror
builds 3.14 (and later 3.15) wheels is a one-line change.

With this change, Dependabot's exact command succeeds for every open pip
alert's target version.
A
Alexander Tarasov committed
b489eead8f0d4ab2597c78c183e26c819b5c6fbe
Parent: 4db0f7d
Committed by GitHub <noreply@github.com> on 10/1/2026, 1:20:47 PM