Skip to content

build(deps): bump pypa/cibuildwheel from 4.2.0 to 4.2.1 - #190

Merged
justinjoy merged 1 commit into
mainfrom
fix/cibuildwheel-4.2.1-with-guard
Sep 12, 2026
Merged

justinjoy merged 1 commit into
mainfrom
fix/cibuildwheel-4.2.1-with-guard

Conversation

@justinjoy

Copy link
Copy Markdown
Contributor

Supersedes #189.

Why #189 could not merge

Dependabot opened #189 to bump pypa/cibuildwheel from v4.2.0 to v4.2.1 in
the two wheel-building workflows. lint passed and all twelve test-matrix
jobs failed, every one of them on a single assertion:

FAILED tests/test_wheels_config.py::test_wheel_workflows_use_cibuildwheel_v4_2_0
  AssertionError: assert 'pypa/cibuildwheel@v4.2.0' in '...'

test_wheel_workflows_use_cibuildwheel_v4_2_0 pins the exact cibuildwheel
version both workflows must use. Dependabot cannot edit tests, so the pin and
the guard drift apart on every cibuildwheel bump. #185 failed the same way
before the 4.1.1 -> 4.2.0 bump was redone by hand in 9fc85d9.

What this PR does

The workflow edits here are byte-identical to Dependabot's commit 45ae699,
plus the guard update Dependabot could not make:

File Change
.github/workflows/wheels.yml pypa/cibuildwheel@v4.2.0 -> @v4.2.1
.github/workflows/release.yml pypa/cibuildwheel@v4.2.0 -> @v4.2.1
tests/test_wheels_config.py guard renamed to ..._v4_2_1, positive assert flipped, v4.2.0 added to the superseded list

Three files, +5/-4 - the same shape as precedent 9fc85d9.

No CHANGELOG entry: tests/test_changelog_format.py::test_unreleased_section_is_empty_for_100_release
requires the Unreleased section stay byte-for-byte empty, and this repo records
CI action bumps at release time inside the dated section.

Upstream risk (v4.2.1)

Upstream change Exposure here
Respects machine-configured NuGet sources for CPython on Windows (#2966) The only item with live exposure - see the verification note below
Fixes a NameError on Pyodide when reusing a compatible wheel (#2968) None: skip excludes PyPy/musllinux, no Pyodide target
Android testbed and Gradle updates for Java 25 (#2962) None: Android is not built
Dependency refresh incl. CPython 3.15.0rc2 None: tool.cibuildwheel.build enumerates cp311-cp314 explicitly

Verification

Neither wheels.yml nor release.yml runs on pull_request - both trigger only
on v* tags and workflow_dispatch. A green check here therefore proves the
workflow pin matches the guard, but proves nothing about cibuildwheel v4.2.1
actually building a wheel. wheels.yml is dispatched once on this branch to
cover that; its build_wheels job is byte-identical to release.yml's, so one
run validates both.

Local: full suite 653 passed, 9 skipped, coverage 94.02%. black --check,
isort --check-only, flake8, mypy src/pyrewire all clean.

Bumps pypa/cibuildwheel from v4.2.0 to v4.2.1 in the release and wheels
workflows, redoing #189 with the one change Dependabot cannot make.

test_wheel_workflows_use_cibuildwheel_v4_2_0 pins the exact cibuildwheel
version both wheel-building workflows must use, so the bump has to update
that guard in lockstep. Dependabot cannot touch the test, which is why
#189 failed all twelve test-matrix jobs on that single assertion while
lint passed. #185 failed the same way before the 4.1.1 to 4.2.0 bump was
redone by hand in 9fc85d9.

The guard is renamed to match the version it now asserts, and v4.2.0
joins the list of superseded versions the workflows must not fall back
to.

v4.2.1 is a patch release: it respects machine-configured NuGet sources
when installing CPython on Windows, fixes a NameError on Pyodide when an
already-compatible wheel is reused, updates the Android testbed for Java
25, and refreshes dependencies including CPython 3.15.0rc2. None of it
reaches this wheel matrix -- `tool.cibuildwheel.build` enumerates cp311
through cp314 explicitly, `skip` excludes PyPy and musllinux, and neither
Pyodide nor Android is built here. The Windows NuGet change is the only
item with live exposure, so wheels.yml is dispatched on the branch to
exercise it; neither wheel workflow runs on pull_request.
@justinjoy
justinjoy merged commit b976320 into main Sep 12, 2026
20 checks passed
@justinjoy
justinjoy deleted the fix/cibuildwheel-4.2.1-with-guard branch September 12, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant