cold-summer-59604
05/12/2026, 7:26 AMresolves_to_uploaded_prior_to in my company's repo to ensure that lockfiles are typically at least 7 days old. We also use security scanning with snyk and that typically means we have to use the latest dependency to get around a vulnerability. uv has an exclude-newer setting which pip lacks, that'd allow us to overrule the 7 days rule on a per-package basis. Has there been any thought put into this? I think for now I'll just default to 7 days but recommend bypassing it for all dependencies when necessary. I'm happy to contribute code for this, however it makes sense to discuss it first.wide-midnight-78598
05/12/2026, 11:39 AMwide-midnight-78598
05/12/2026, 11:40 AMcold-summer-59604
05/12/2026, 11:43 AMwide-midnight-78598
05/12/2026, 11:45 AMalthough moving over to the pre-release pants was giving os.fork warningsUgh. Yeah, one of our deps needs to be updated, or we need to hide the warning.
I just mucked around with it today, seemed to work without issueš Thanks for testing this out! In this pre-release stage is when we want to find issues with the resolver.
rc0 should be going out today, and then I want to keep an eye on any blockers (however, since it's an opt-in feature, not sure there will be)cold-summer-59604
05/12/2026, 11:58 AMwide-midnight-78598
05/12/2026, 11:59 AMhundreds-carpet-28072
05/12/2026, 2:44 PMexclude-newer support. @wide-midnight-78598 Is there a ticket for these UV features? Iād like to have a look if possiblewide-midnight-78598
05/12/2026, 3:03 PM