* feat: add SHA256 verification for direct downloads
Store SHA256 hashes when running update scripts and verify them
when downloading files at build time. This improves security by
detecting unexpected changes to downloaded artifacts.
Platforms covered: macOS (CPython, PyPy, GraalPy), iOS, Android,
virtualenv, and python-build-standalone. Windows (nuget) and
Linux (Docker) are excluded.
SHA256 sources per platform:
- macOS/iOS/Android CPython (python.org): sha256_sum from API
- GraalPy: .sha256 sidecar assets from GitHub releases
- python-build-standalone: SHA256SUMS file in release
- PyPy, BeeWare iOS, Maven (Chaquopy): stream-download and compute
Changes:
- cibuildwheel/util/file.py: add sha256 param to download()
- cibuildwheel/platforms/{macos,ios,android}.py: add sha256 to
PythonConfiguration and pass to download()
- cibuildwheel/venv.py: read sha256 from toml and pass to download()
- cibuildwheel/util/python_build_standalone.py: add sha256 to
PythonBuildStandaloneAsset and pass to download()
- cibuildwheel/resources/build-platforms.toml: add sha256 fields
- cibuildwheel/resources/virtualenv.toml: add sha256 field
- cibuildwheel/resources/python-build-standalone-releases.json: add sha256
- bin/update_pythons.py: compute/store sha256 per source strategy
- bin/update_virtualenv.py: compute sha256 by streaming download
- bin/update_python_build_standalone.py: parse SHA256SUMS file
Closes#908
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
* fix: populate sha256 in resource files and fix Windows PythonConfiguration
- Add sha256 field to Windows PythonConfiguration (PyPy/GraalPy have
direct download URLs on Windows too)
- Pass sha256 to install_pypy() and install_graalpy() in windows.py
- Fix update_pythons.py: handle empty sha256 from CPython API (older
versions) by streaming download to compute it; fix condition to
check 'not sha256' rather than 'not in dict'
- Fix update_virtualenv.py: compute sha256 even when version unchanged
but sha256 is empty (first-time population)
- Fix update_python_build_standalone.py: resolve file path relative to
the script itself (not the installed package) so writes go to source
checkout, not the uv cache
- Populate actual sha256 values by running all three update scripts
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: copilot-cli:claude-sonnet-4.6
* fix: also include pyodide
Assisted-by: CopilotCLI:gpt-5.3-codex
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: PR review comments for cache verification and docs wording
Co-authored-by: henryiii <4616906+henryiii@users.noreply.github.com>
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: require sha256 for download configs
Require sha256 for URL-backed Python and virtualenv download configs. Update the GraalPy updater to refresh macOS x86_64 entries by selecting the latest release that still has a matching asset, and fill the two missing GraalPy checksums in build-platforms.toml.
Assisted-by: CopilotCLI:gpt-5.4
* ci: remove unit test for bin item
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* refactor: combine sha256 unit tests into test_sha256.py
Merge pyodide_test.py and python_build_standalone_test.py into a
single unit_test/test_sha256.py since both test sha256-related
behaviour.
Assisted-by: opencode:glm-5
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: henryiii <4616906+henryiii@users.noreply.github.com>
Since delvewheel is now the default repair-wheel-command on Windows,
update all places where auditwheel/delocate were referenced but
delvewheel was missing:
- diagram.html: add delvewheel repair block for Windows (was grouped
with ios/pyodide as optional dot)
- generate_schema.py: add Windows delvewheel default to the platform
loop so schema.json includes the default
- schema.json: regenerated with Windows delvewheel default
- options.md: add Windows to defaults list, remove outdated tip about
delvewheel being early-stage/optional, update examples
- contributing.md: add delvewheel to the tool list
Assisted-by: OpenCode:glm-5.1
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* feat: add CIBUILDWHEEL_BUILD_IDENTIFIER environment variable
Set `CIBUILDWHEEL_BUILD_IDENTIFIER` to the current build identifier
(e.g. `cp311-manylinux_x86_64`) in the environment for all per-build
steps: `before_build`, the build itself, `repair_command`,
`before_test`, and `test_command`.
This allows scripts and commands to inspect which build is currently
running, which is useful for e.g. writing per-build output files:
CIBW_TEST_COMMAND='pytest --junit-xml=results-$CIBUILDWHEEL_BUILD_IDENTIFIER.xml'
The variable is set after the user's environment overrides are applied
and is only available for per-build steps (not `before_all`, where no
single identifier applies). All six platforms are covered: linux, macOS,
Windows, pyodide, Android, and iOS.
Closes#944, closes#2750
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Assisted-by: OpenCode:claude-sonnet-4.6
* fix: address review comment moving this for Android
Assisted-by: OpenCode:glm-5.1
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* feat: add CPython 3.15 support for iOS
Assisted-by: OpenCode:Kimi-K2.6
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: copy in iOS support files
Assisted-by: Copilot:claude-sonnet-4.6
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: skip directories when copying iOS support files
When copying multiarch-specific support files (e.g. _cross_arm64_iphoneos.py),
the code was trying to copy all items in the directory including __pycache__
directories. The shutil.copy() function only works with files, not directories,
which caused an IsADirectoryError.
This fix adds a check to only copy files, skipping any directories like
__pycache__ that may have been created by Python imports.
Assisted-by: Copilot:claude-haiku-4.5
* fix: - in dir fine for now
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: apply review suggestions
Assisted-by: Copilot:claude-sonnet-4.6
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: only do this on 3.15+
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* Ensure target Python directory exists before build
Add assertion to check if target Python directory exists.
* fix(ios): use stdlib dir directly instead of copying to platform-config
Remove the _inject_support_files workaround for python.org 3.15+
distributions. Instead of copying sysconfig files from the stdlib into
a synthetic platform-config/ directory, pass the stdlib directory
directly to make_cross_venv.py.
make_cross_venv.py is updated to derive the multiarch tag from the
_sysconfigdata_ filename rather than assuming it comes from the
directory name.
Co-authored-by: Russell Keith-Magee <russell@keith-magee.com>
Assisted-by: OpenCode:Kimi-K2.6
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* Minor format cleanups on pre-commit skipped files.
* Clarify path names in make_cross_venv script.
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Co-authored-by: Russell Keith-Magee <russell@keith-magee.com>
* chore: Add agent and copilot setup files
Add AGENTS.md with project-specific developer notes for AI agents.
Add GitHub Actions workflow to validate Copilot setup steps.
Add changelog-entry skill for automated changelog generation.
Assisted-by: OpenCode:kimi
* Update .gitignore to include CLAUDE.md
Add CLAUDE.md to .gitignore for symlink instructions
Assert statements are skipped under python -O, making them unsuitable
for runtime validation. Replace assert with an explicit check that
raises PythonBuildStandaloneError if the target directory already exists.
Assisted-by: OpenCode:glm-5
* chore: minor fixups across errors, oci_container, and options
- Strengthen error message wording: 'is expected to' → 'must' and
'is expected to place one' → 'must place exactly one' in
FailedWheelRepairError classes.
- Remove shell=True from subprocess.run in oci_container debug_info,
passing command as a list instead of a string.
- Update pinned image error message from 'cibuildwheel 3.x' to
'cibuildwheel 4.x' and add comment about next warning candidate.
Assisted-by: OpenCode:glm-5
* Update cibuildwheel/options.py
* feat: add CPython 3.15 support for iOS and Android
Add cp315 identifiers to build-platforms.toml for both iOS (arm64_iphoneos,
x86_64_iphonesimulator, arm64_iphonesimulator) and Android (arm64_v8a, x86_64).
Update bin/update_pythons.py to route iOS 3.15+ to python.org instead of
BeeWare GitHub releases. Update README.md platform table to show Android and
iOS as supported for 3.15. Add cp315-cp315 to expected_wheels test defaults
for android and ios platforms.
Assisted-by: OpenCode:Kimi-K2.6
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: adjust expectations
All changes made and linting passes. Here's a summary of what was done:
1. test/utils.py:390-394 — Added "cp315-cp315": 24 to the Android API level mapping, fixing the KeyError: 'cp315-cp315' in test_android.py::test_expected_wheels.
2. cibuildwheel/resources/build-platforms.toml:247 — Removed the cp315-ios_x86_64_iphonesimulator entry since CPython 3.15 dropped Intel iOS simulator support.
3. test/utils.py:397-405 — Updated the iOS expected wheels logic to return an empty platform_tags list for x86_64 when the Python version is 3.15+, so no x86_64_iphonesimulator wheels are expected for cp315+ on Intel Macs.
The XCframework slice name (ios-arm64_x86_64-simulator) stays the same in ios.py — I verified the 3.15 tarball still uses that name. The target_python.exists() iOS ARM64 failure on the feature branch is a separate issue (the 3.15 python.org distribution has a different structure than the beeware distributions used for 3.13/3.14) — left alone per your request.
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Assisted-by: OpenCode:glm-5.1
* revert: x86 is still supposed to exist
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* docs: fix readme for Pyodide
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* docs: mention eol
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: drop assert
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* feat: add CPython 3.15 support for Android only
Cherry-picked all changes from henryiii/feat/cp315-ios-android, then
reverted iOS-specific parts (iOS 3.15 build configs, ios.py assert
removal, update_pythons.py iOS URL logic, iOS test expectations, and
README iOS column for 3.15). Android cp315 entries, test expectations,
and README Android column remain.
Assisted-by: OpenCode:glm-5
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
test: add Python 3.15 to CI test matrix and classifiers
Update the Max Python CI job from 3.14 to 3.15 and add the
Programming Language :: Python :: 3.15 classifier to pyproject.toml.
Assisted-by: OpenCode:GLM-5
* fix: drop Cirrus CI (going away June 1, 2026)
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* Restore missing note
* Update CI services documentation for Cirrus CI
Removed official support for Cirrus CI due to end-of-life.
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* tests: fully type the test suite
* chore: require more typing
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
* fix: avoid PYTHON_VERSION breaking uv if set
* fix: also keep UV_PYTHON out
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: specify the python version in the uv command more often
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* fix: revert env order change
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* Update windows.py
Co-authored-by: Joe Rickerby <joerick@mac.com>
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
Co-authored-by: Joe Rickerby <joerick@mac.com>
* chore: clean up config a bit
* chore: add an extra check
* Apply suggestions from code review
Co-authored-by: Henry Schreiner <HenrySchreinerIII@gmail.com>
* fix: give uv the full python path
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Fix python binary path in Linux build script
I thought the dir was enough. Seems not.
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* ci: avoid broken GraalPy release
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* ci: skip GraalPy when no release url available
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
---------
Signed-off-by: Henry Schreiner <henryfs@princeton.edu>
* ci: rework tests to break out ios/android tests
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Apply suggestions from code review
* ci: fix check for wheels
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Update .github/workflows/test.yml
* tests: pass via flag instead of envvar
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* tests: apply to serial/parallel
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* tests: join together marks
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* tests: join together marks
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* ci: break up azure job
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* ci: use matrix for azure pipelines
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Try installing Java on macos as well
* Revert "Try installing Java on macos as well"
This reverts commit aedf0f5106d2467938705b85180a0b249d49b99d.
* Try to get the most basic android test running first
* Rename platform to test_select, move headers in run_tests
Maybe it's a personal thing, but the header location was really making
me have to think more than I needed to look at that file!
* Only run docker unit tests on machines that are testing linux
* Update the flag name in azure-pipelines too
* Update azure-pipelines.yml
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Matthieu Darbois <mayeut@users.noreply.github.com>
Co-authored-by: Joe Rickerby <joerick@mac.com>
You can't change the running process in Windows. In pip 25.2, the format of the generated file changes, so this now breaks if you try to update to the latest pip (which can happen if deps are unpinned).
This is no longer experimental in 3.13 beta 3, so we don't need an enable for it anymore. Someone can skip expliclity with `'cp31?t-*'` if they really don't want free-threaded wheels.
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* chore: add summary to Action
* refactor: new summary table
* fix: fixup tests and formatting
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: pyodide missing some logging
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: nicer printout, nicer in-place summary
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: use summary for everything
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: support only one output wheel from repair
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Add new Github summary format
* Remove a couple of humanize uses
* fix: filter ANSI codes in summary
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: add sha256
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: nicer wheel/wheels depending on how many are present
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Joe Rickerby <joerick@mac.com>
* feat: remove 32-bit linux from auto arch, fix auto32 on linux aarch64
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Apply suggestions from code review
Co-authored-by: Joe Rickerby <joerick@mac.com>
* Update cibuildwheel/architecture.py
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Joe Rickerby <joerick@mac.com>
* docs: color output for docs
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: use asdf (python-build)
* docs: try to fix colors
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Update .pre-commit-config.yaml
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
* feat: support multiple commands on iOS
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* Move split_command into a util module
* (unrelated) fix test docstring
* Implement short-circuit behaviour on test-command
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: Joe Rickerby <joerick@mac.com>
This was a workaround for a bug in validate-pyproject, but that bug was fixed some time ago, so we can use the standard line here now.
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* chore: move codespell config to pyproject.toml
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
* fix: virtualenv 20.31 no-wheel
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* fix: show failed output on failure
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
* Update linux.py
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
* Update linux.py
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
---------
Signed-off-by: Henry Schreiner <henryschreineriii@gmail.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>