- Add sha256 field to Windows PythonConfiguration (PyPy/GraalPy have
direct download URLs on Windows too)
- Pass sha256 to install_pypy() and install_graalpy() in windows.py
- Fix update_pythons.py: handle empty sha256 from CPython API (older
versions) by streaming download to compute it; fix condition to
check 'not sha256' rather than 'not in dict'
- Fix update_virtualenv.py: compute sha256 even when version unchanged
but sha256 is empty (first-time population)
- Fix update_python_build_standalone.py: resolve file path relative to
the script itself (not the installed package) so writes go to source
checkout, not the uv cache
- Populate actual sha256 values by running all three update scripts
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
Store SHA256 hashes when running update scripts and verify them
when downloading files at build time. This improves security by
detecting unexpected changes to downloaded artifacts.
Platforms covered: macOS (CPython, PyPy, GraalPy), iOS, Android,
virtualenv, and python-build-standalone. Windows (nuget) and
Linux (Docker) are excluded.
SHA256 sources per platform:
- macOS/iOS/Android CPython (python.org): sha256_sum from API
- GraalPy: .sha256 sidecar assets from GitHub releases
- python-build-standalone: SHA256SUMS file in release
- PyPy, BeeWare iOS, Maven (Chaquopy): stream-download and compute
Changes:
- cibuildwheel/util/file.py: add sha256 param to download()
- cibuildwheel/platforms/{macos,ios,android}.py: add sha256 to
PythonConfiguration and pass to download()
- cibuildwheel/venv.py: read sha256 from toml and pass to download()
- cibuildwheel/util/python_build_standalone.py: add sha256 to
PythonBuildStandaloneAsset and pass to download()
- cibuildwheel/resources/build-platforms.toml: add sha256 fields
- cibuildwheel/resources/virtualenv.toml: add sha256 field
- cibuildwheel/resources/python-build-standalone-releases.json: add sha256
- bin/update_pythons.py: compute/store sha256 per source strategy
- bin/update_virtualenv.py: compute sha256 by streaming download
- bin/update_python_build_standalone.py: parse SHA256SUMS file
Closes#908
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
* Add PEP 723 metadata for various `bin` scripts
* Use a subprocess to install chromium
* Regenerate image
* Update shebangs
Co-Authored-By: Henry Schreiner <HenrySchreinerIII@gmail.com>
* Add cibuildwheel local dependency for some scripts
Co-Authored-By: Henry Schreiner <HenrySchreinerIII@gmail.com>
* Remove `bin` dependency group fully
* Add CSS for styling the diagram
Co-Authored-By: Joe Rickerby <1244307+joerick@users.noreply.github.com>
* Restore image to original
* Install `uv` for PyLint to find it
* Drop setup-python too in favour of setup-uv
* Revert "Drop setup-python too in favour of setup-uv"
This reverts commit 663db5c253f18bd09229ea5dbf92f7f6aa8ebf1c.
* Make `uv` venv backend for nox optional again
---------
Co-authored-by: Henry Schreiner <HenrySchreinerIII@gmail.com>
Co-authored-by: Joe Rickerby <1244307+joerick@users.noreply.github.com>
* Fix a typo: pyoodide ➡️ pyodide
* Add `pyodide_build_version` attribute
* Add version to xbuildenv log step
* Add version to Emscripten log step
* Use `pyodide-build`'s version for updating constraints
* Bump Pyodide constraints by updating `pyodide-build`
* Add a schema for `pyodide-version`
* Update Pyodide constraints
* Bump `pyodide-build` to new 0.29.0
* Test out another Pyodide identifier
* Update outdated Pyodide constraints
* Add Pyodide version to temp directory name
* Remove Pyodide 0.26.1 from build configurations
* Retrieve + validate + install specific xbuildenvs
* Test wheel builds with Pyodide 0.26.2
* Add correct Pyodide version to identifier temp dir
* Don't pre-call Pyodide xbuildenv search
* Fetch just the stable Pyodide versions
* Refactor search + validation + install into one step
* Move all of it under a lock
* Reorder xbuildenv installation
* Add env and cwd to xbuildenv search call
* Temporarily lower to 0.26.2 target
* Separate out search, validate, install; again
* Run xbuildenv search in `CIBW_CACHE_PATH`
* Remove prior `PYODIDE_ROOT` env vars, copy envs
* Validate doesn't need to depend on searching
* Add file lock when searching xbuildenvs
* Test the original version: 0.26.1
* Update Pyodide constraints
* Update constraints for `pyodide-build` 0.29.0 again
* Bump Pyodide from version 0.26.1 ➡️ version 0.26.4
* Add note on compatibility for macOS + other archs
* Note Pyodide version for Pyodide identifier
* Docs about `CIBW_PYODIDE_VERSION`
* Don't fetch just the stable versions
* Discard a variable that's not used later
* Rename `search_xbuildenv` ➡️ `get_xbuildenv_versions`
* `validate_xbuildenv` ➡️ `validate_xbuildenv_version`
* Replace ordered comment, add newline
* Replace sentence on macOS support
Co-Authored-By: Hood Chatham <roberthoodchatham@gmail.com>
* Capitalise: "pyodide" ➡️ "Pyodide"
Co-Authored-By: Hood Chatham <roberthoodchatham@gmail.com>
* "work" ➡️ "may succeed"
Co-Authored-By: Hood Chatham <roberthoodchatham@gmail.com>
* Add another job to test a custom Pyodide version
* Handle "v"-prefixed + non-prefixed versions
* Convert to a proper toml-able option, and remove some hardcoded versions
This removes the enscripten and pyodide-build version specs from
pyproject.toml - pyodide-build is spec'd in the constraints file, and
the emscripten version can be read from the pyodide-build output.
* Add a schema entry
* Add docs for CIBW_PYODIDE_VERSION
* Rephrase
* Add tests for pyodide-version
* Apply suggestions from code review
* Add python_build_standalone util
* Hook up to python-build-standalone, removing dependency on host python
* Remove python hard-code in action.yml
* Add log step
* Add workaround for https://github.com/pyodide/pyodide-build/issues/143
* Add emscripten pytest test
* Remove unneeded checks
* Fix a pytest invoke for emscripten
* Generate pyodide-build constraints from the pinned pyodide version
* Remove pyodide python-build-standalone workaround
* Fixup paths from newer version of pyodide-build
* Fix/skip some failing tests
* Use `python -m pytest` on pyodide, even on Linux
* Docs fixes
* Don't call the github API at runtime, cache the release assets instead
* Ignore pylint false positive
* Add version auto-updating for pyodide
* Add support for pyodide 3.13.
* Fix tests for multiple pyodide wheels
* Remove workaround for unreleased pyodide-build
* Rename to "test_pyodide"
* Fix pathname confusion
* Remove extra github actions job
* Fix expectation for test_abi_none
* Fix the custom_repair_wheel test to actually have clashing names
* Fix pinned version test
* Document test-command limitation
* Remove pyodide 0.28.0a1 for now
* Update constraints files
* Docs/test fixes post removing pyodide cp313
* Fix ABI test expectation
* Docs improvements
* Improve some comments
* Remove logic duplication
* remove pyodide special casing
* Refactor constraints code to use a utility script, circumventing import issues
* chore: nicer nox env
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: typo in variable name found by copilot
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Apply suggestions from code review
* Some more Pyodide version updates in the docs section
* We haven't released Pyodide v0.27.6 yet
* Back to the Github URL for cross-build-environments
* `pyodide-build`, not `emsdk` for Windows skips
Co-Authored-By: Hood Chatham <roberthoodchatham@gmail.com>
* Move to a separate `_json_request` function
Co-Authored-By: Hood Chatham <roberthoodchatham@gmail.com>
* Rename "retries" ➡️ "retry_count"
* Add some type hints
* Copy env vars before `UV_CUSTOM_COMPILE_COMMAND`
* Use `HTTPError.headers.get` instead
* Remove extra end quote
* Change download tests URL to `https://badssl.com/`
Co-Authored-By: Joe Rickerby <1244307+joerick@users.noreply.github.com>
* Download size changes, too
* Use jsdelivr for Github asset mirroring
* Bump to Pyodide v0.27.6
* Fix unit tests
* Move to pyodide v0.27.6 again
* Bump to pyodide-build 0.30.4
* Use new URL for cross-build environments metadata
Co-authored-by: Joe Rickerby <joerick@mac.com>
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Hood Chatham <roberthoodchatham@gmail.com>
Co-authored-by: Joe Rickerby <joerick@mac.com>
Co-authored-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Joe Rickerby <1244307+joerick@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>