Files
setup-uv/docs/customization.md
T
cd13f92170 Verify downloads with astral-sh/versions checksums (#1033)
`setup-uv` currently ignores the `sha256` supplied by the default
`astral-sh/versions` manifest when a selected artifact is newer than its
bundled checksum table, allowing that download to proceed without
validation. Use the manifest checksum as a fallback after explicit and
bundled checksums, and reject manifest entries that do not provide one.
This preserves the stronger pinned hashes for known releases while
verifying newer releases without requiring an action update. Part of
#1032.

---------

Co-authored-by: Zanie Blue <contact@zanie.dev>
Co-authored-by: William Woodruff <william@yossarian.net>
Co-authored-by: Kevin Stillhammer <kevin.stillhammer@gmail.com>
2026-09-01 17:07:32 +02:00

2.6 KiB

Customization

This document covers advanced customization options including checksum validation, custom manifests, and problem matchers.

Validate checksum

Downloaded executables are automatically verified using checksums bundled with this action or, for newer, not yet bundled versions, the checksum from astral-sh/versions. You can specify a checksum to override those values. The sha256 hashes can also be found on the releases page of the uv repo.

- name: Install a specific version and validate the checksum
  uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
  with:
    version: "0.3.1"
    checksum: "e11b01402ab645392c7ad6044db63d37e4fd1e745e015306993b07695ea5f9f8"

Manifest file

By default, setup-uv reads version metadata from astral-sh/versions.

The manifest-file input lets you override that source with your own URL, for example to test custom uv builds or alternate download locations.

Format

The manifest file must use the same format as astral-sh/versions: one JSON object per line, where each object represents a version and its artifacts. The versions must be sorted in descending order. For example:

{"version":"0.10.7","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]}
{"version":"0.10.6","artifacts":[{"platform":"x86_64-unknown-linux-gnu","variant":"default","url":"https://example.com/uv-x86_64-unknown-linux-gnu.tar.gz","archive_format":"tar.gz","sha256":"..."}]}

setup-uv currently only supports default as the variant.

The archive_format field is currently ignored.

- name: Use a custom manifest file
  uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
  with:
    manifest-file: "https://example.com/my-custom-manifest.ndjson"

Note

When you use a custom manifest file and do not set the version input, setup-uv installs the latest version from that custom manifest.

Add problem matchers

This action automatically adds problem matchers for python errors.

You can disable this by setting the add-problem-matchers input to false.

- name: Install the latest version of uv without problem matchers
  uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
  with:
    add-problem-matchers: false