name: Update dependencies on: pull_request: paths: - '.github/workflows/update-dependencies.yml' - 'bin/update_pythons.py' - 'bin/update_docker.py' - 'bin/update_virtualenv.py' - 'bin/projects.py' - 'docs/data/projects.yml' - 'noxfile.py' workflow_dispatch: schedule: - cron: '0 6 * * 1' # "At 06:00 on Monday." permissions: {} jobs: update-dependencies: name: Update dependencies if: github.repository_owner == 'pypa' || github.event_name != 'schedule' runs-on: ubuntu-latest permissions: contents: write environment: ${{ github.ref == 'refs/heads/main' && github.repository == 'pypa/cibuildwheel' && 'update-dependencies-workflow' || '' }} steps: # we use this step to grab a Github App auth token, so that PRs generated by this workflow # run the GHA tests. - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 id: generate-token if: github.ref == 'refs/heads/main' && github.repository == 'pypa/cibuildwheel' with: client-id: ${{ secrets.CIBUILDWHEEL_BOT_APP_ID }} private-key: ${{ secrets.CIBUILDWHEEL_BOT_APP_PRIVATE_KEY }} permission-contents: write permission-pull-requests: write - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: python-version: "3.14" - name: "Run update: dependencies" run: uvx nox --force-color -s update_constraints - name: "Run update: python configs" run: uvx nox --force-color -s update_pins - name: "Run update: docs user projects" run: uvx nox --force-color -s update_proj -- --auth=${{ secrets.GITHUB_TOKEN }} - name: Create Pull Request if: github.ref == 'refs/heads/main' && github.repository == 'pypa/cibuildwheel' uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: commit-message: Update dependencies title: '[Bot] Update dependencies' body: | Update the versions of our dependencies. PR generated by "Update dependencies" [workflow](https://github.com/${{github.repository}}/actions/runs/${{github.run_id}}). branch: update-dependencies-pr sign-commits: true token: ${{ steps.generate-token.outputs.token }} delete-branch: true labels: | CI: GraalPy CI: PyPy dependencies