Skip to content

build(deps): bump pypa/cibuildwheel from 4.1.1 to 4.2.0 - #185

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pypa/cibuildwheel-4.2.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pypa/cibuildwheel-4.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Contributor

Bumps pypa/cibuildwheel from 4.1.1 to 4.2.0.

Release notes

Sourced from pypa/cibuildwheel's releases.

v4.2.0

  • 🌟 CPython 3.15 wheels are now built by default - without the "cpython-prerelease" enable set. It's time to build and upload these wheels to PyPI! This release includes CPython 3.15.0rc1, which is guaranteed to be ABI compatible with the final release. (#2944)
  • ✨ Adds Pyodide 3.15 support with the cp315-pyodide_wasm32 build identifier, using Pyodide 315.0.0a2. These are also stable wrt. the final release. (#2958)
  • 🐛 Retries a failed download six times with exponential backoff, so short network outages no longer stop a build. A 4xx response is still reported at once. (#2953)
  • 🐛 Accepts default as a build-frontend value on Pyodide, and accepts pyodide-build in the top-level table and in overrides (#2951)
  • 🛠 Holds pip back on GraalPy, where newer pip breaks the build (#2955)
  • 🛠 Updates Pyodide to 314.0.4 (#2949, #2952)
  • 🛠 Updates dependencies and container pins (#2952, #2960)
  • 💼 Updates CI action pins (#2948, #2954)
  • 🧪 Uses pp311 for the abi3 test, and deletes test_overridden_pip_constraint, which is not necessary since #2583 (#2956, #2957)
Changelog

Sourced from pypa/cibuildwheel's changelog.

v4.2.0

4 August 2026

  • 🌟 CPython 3.15 wheels are now built by default - without the "cpython-prerelease" enable set. It's time to build and upload these wheels to PyPI! This release includes CPython 3.15.0rc1, which is guaranteed to be ABI compatible with the final release. (#2944)
  • ✨ Adds Pyodide 3.15 support with the cp315-pyodide_wasm32 build identifier, using Pyodide 315.0.0a2. These are also stable wrt. the final release. (#2958)
  • 🐛 Retries a failed download six times with exponential backoff, so short network outages no longer stop a build. A 4xx response is still reported at once. (#2953)
  • 🐛 Accepts default as a build-frontend value on Pyodide, and accepts pyodide-build in the top-level table and in overrides (#2951)
  • 🛠 Holds pip back on GraalPy, where newer pip breaks the build (#2955)
  • 🛠 Updates Pyodide to 314.0.4 (#2949, #2952)
  • 🛠 Updates dependencies and container pins (#2952, #2960)
  • 💼 Updates CI action pins (#2948, #2954)
  • 🧪 Uses pp311 for the abi3 test, and deletes test_overridden_pip_constraint, which is not necessary since #2583 (#2956, #2957)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pypa/cibuildwheel](https://github.com/pypa/cibuildwheel) from 4.1.1 to 4.2.0.
- [Release notes](https://github.com/pypa/cibuildwheel/releases)
- [Changelog](https://github.com/pypa/cibuildwheel/blob/main/docs/changelog.md)
- [Commits](pypa/cibuildwheel@v4.1.1...v4.2.0)

---
updated-dependencies:
- dependency-name: pypa/cibuildwheel
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 13, 2026
@justinjoy justinjoy closed this Sep 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/pypa/cibuildwheel-4.2.0 branch September 5, 2026 04:55
justinjoy added a commit that referenced this pull request Sep 5, 2026
Bumps pypa/cibuildwheel from v4.1.1 to v4.2.0 in the release and wheels
workflows.

test_wheel_workflows_use_cibuildwheel_v4_1_1 pins the exact cibuildwheel
version both wheel-building workflows must use, so the bump has to update
that guard in lockstep. Dependabot cannot touch the test, which is why
#185 failed the whole test matrix on that single assertion.

The guard is renamed to match the version it now asserts, and v4.1.1 joins
the list of superseded versions the workflows must not fall back to.

v4.2.0 builds CPython 3.15 wheels by default, but `tool.cibuildwheel.build`
already enumerates cp311 through cp314 explicitly, so the wheel matrix is
unchanged. The release also retries failed downloads with exponential
backoff, which only makes the wirelog source fetch in `before-all` more
robust.

Claude-Session: https://claude.ai/code/session_01MqHwvCimcvrg1osEY5MH7o
justinjoy added a commit that referenced this pull request Sep 12, 2026
Bumps pypa/cibuildwheel from v4.2.0 to v4.2.1 in the release and wheels
workflows, redoing #189 with the one change Dependabot cannot make.

test_wheel_workflows_use_cibuildwheel_v4_2_0 pins the exact cibuildwheel
version both wheel-building workflows must use, so the bump has to update
that guard in lockstep. Dependabot cannot touch the test, which is why
#189 failed all twelve test-matrix jobs on that single assertion while
lint passed. #185 failed the same way before the 4.1.1 to 4.2.0 bump was
redone by hand in 9fc85d9.

The guard is renamed to match the version it now asserts, and v4.2.0
joins the list of superseded versions the workflows must not fall back
to.

v4.2.1 is a patch release: it respects machine-configured NuGet sources
when installing CPython on Windows, fixes a NameError on Pyodide when an
already-compatible wheel is reused, updates the Android testbed for Java
25, and refreshes dependencies including CPython 3.15.0rc2. None of it
reaches this wheel matrix -- `tool.cibuildwheel.build` enumerates cp311
through cp314 explicitly, `skip` excludes PyPy and musllinux, and neither
Pyodide nor Android is built here. The Windows NuGet change is the only
item with live exposure, so wheels.yml is dispatched on the branch to
exercise it; neither wheel workflow runs on pull_request.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant