Ruff 0.17.0 Raises Its Default Python Target to 3.11, Removes ruff-lsp Support and Code-Signs macOS and Windows Executables
Astral's Ruff 0.17.0 release notes, dated October 9, list code-signed executables, a default Python version of 3.11, changed default rules and the removal of ruff-lsp support.
Editor's Note ·
- Clarification:
- The Overview says the release notes' text 'appears in the project's CHANGELOG.md at the 0.17.0 tag'. The changelog at that tag lists the same breaking changes, stabilizations and fixes as the GitHub release page, but it does not contain the release page's opening paragraph on code-signed macOS and Windows executables; that information appears only in the release notes on GitHub.
Overview
Astral’s Python linter and formatter Ruff has a new minor release. According to the 0.17.0 release notes on GitHub, the version was “Released on 2026-10-09” and combines a change in how its executables are signed with a list of breaking changes, among them a higher default Python version and the removal of support for the legacy ruff-lsp language server. The same text appears in the project’s CHANGELOG.md at the 0.17.0 tag. Astral is the company that OpenAI agreed to acquire, as previously reported; the release notes do not mention the deal.
What the Release Notes Say
Signed binaries
The release notes state that the executables in the macOS and Windows release archives and the ruff wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple, while Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. The notes say this enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and “should reduce security warnings and antivirus false positives.”
Default Python versions
Per the release notes, Ruff now defaults to Python 3.11 instead of 3.10 when no Python version is configured through target-version or requires-python. When checking for syntax errors without a configured Python version, it now defaults to Python 3.15 instead of 3.14.
Default rule set
The notes say several flake8-datetimez rules (DTZ001, DTZ005, DTZ006, DTZ007, DTZ011, DTZ012 and DTZ901) are no longer enabled by default. Meanwhile undefined-local-with-nested-import-star-usage (F406), which corresponds to a syntax error, is now enabled by default, according to the release notes.
Other breaking changes
The changelog lists several further breaking changes:
- Support for
ruff-lsp, described as the legacy Python language server deprecated in Ruff v0.9.5, has been removed. The VS Code extension now always uses the native language server, andruff.nativeServeris deprecated and ignored. - The default
fulloutput format now shows unsafe fixes and suggestions requiring manual review regardless of theunsafe-fixessetting. Applying unsafe fixes still requires explicit opt-in. - JUnit output now uses a
skippedattribute instead ofdisabledon<testsuite>elements and includes askippedattribute on the root<testsuites>element. - The default
lint.dummy-variable-rgxnow recognizes underscore-prefixed Unicode names, such as_次, as dummy variables. - Ruff now uses Unicode 17 data for identifier normalization and named character escapes.
datetime as dtis added as a conventional alias underICN001.- The conda-forge build no longer depends on Python, so
python -m ruffandimport ruffno longer work there; the changelog says PyPI installations and those from the standalone installer are unaffected.
Stabilizations
The release notes say three rules were stabilized: lazy-import-mismatch (TID254), lazy-import-immediately-resolved (TID255) and os-path-commonprefix (RUF071). One behavior was also stabilized: the formatter, unsorted-imports (I001), line-too-long (E501) and doc-line-too-long (W505) now consistently ignore trailing pragma comments when computing line length. The notes add that this may cause existing imports to be reformatted and was therefore classified as a breaking change.
What We Don’t Know
- The release notes do not say how many projects will see new or removed diagnostics from the changed default rule set; that depends on each project’s configuration.
- The notes describe the signing change as intended to reduce security warnings and antivirus false positives. No independent measurement of that effect was found in the sources reviewed.
- Both cited sources are Astral’s own repository files, so the account here rests on the vendor’s description of its release. No independent coverage of 0.17.0 was found at the time of writing.
Practical Note
The release notes name target-version and requires-python as the two ways to configure the Python version Ruff assumes. Projects that set either explicitly are not described as affected by the new default of Python 3.11.