
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
cibuildwheel
Advanced tools
Python wheels are great. Building them across Mac, Linux, Windows, on multiple versions of Python, is not.
cibuildwheel is here to help. cibuildwheel runs on your CI server - currently it supports GitHub Actions, Azure Pipelines, Travis CI, CircleCI, and GitLab CI - and it builds and tests your wheels across all of your platforms.
While cibuildwheel itself requires a recent Python version to run (we support the last three releases), it can target the following versions to build wheels:
| macOS Intel | macOS Apple Silicon | Windows 64bit | Windows 32bit | Windows Arm64 | manylinux musllinux x86_64 | manylinux musllinux i686 | manylinux musllinux aarch64 | manylinux musllinux ppc64le | manylinux musllinux s390x | manylinux musllinux armv7l | Android | iOS | Pyodide | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CPythonΒ 3.8 | β | β | β | β | N/A | β | β | β | β | β | β β΅ | N/A | N/A | N/A |
| CPythonΒ 3.9 | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | N/A | N/A | N/A |
| CPythonΒ 3.10 | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | N/A | N/A | N/A |
| CPythonΒ 3.11 | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | N/A | N/A | N/A |
| CPythonΒ 3.12 | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | N/A | N/A | β β΄ |
| CPythonΒ 3.13Β³ | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | β | β | β β΄ |
| CPythonΒ 3.14 | β | β | β | β | β Β² | β | β | β | β | β | β β΅ | β | β | N/A |
| PyPyΒ 3.8 v7.3 | β | β | β | N/A | N/A | β ΒΉ | β ΒΉ | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
| PyPyΒ 3.9 v7.3 | β | β | β | N/A | N/A | β ΒΉ | β ΒΉ | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
| PyPyΒ 3.10 v7.3 | β | β | β | N/A | N/A | β ΒΉ | β ΒΉ | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
| PyPyΒ 3.11 v7.3 | β | β | β | N/A | N/A | β ΒΉ | β ΒΉ | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
| GraalPyΒ 3.11 v24.2 | β | β | β | N/A | N/A | β ΒΉ | N/A | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
| GraalPyΒ 3.12 v25.0 | β | β | β | N/A | N/A | β ΒΉ | N/A | β ΒΉ | N/A | N/A | N/A | N/A | N/A | N/A |
ΒΉ PyPy & GraalPy are only supported for manylinux wheels.
Β² Windows arm64 support is experimental.
Β³ Free-threaded mode requires opt-in on 3.13 using enable.
β΄ Experimental, not yet supported on PyPI, but can be used directly in web deployment. Use --platform pyodide to build.
β΅ manylinux armv7l support is experimental. As there are no RHEL based image for this architecture, it's using an Ubuntu based image instead.
See the cibuildwheel 1 documentation if you need to build unsupported versions of Python, such as Python 2.
cibuildwheel runs inside a CI service. Supported platforms depend on which service you're using:
| Linux | macOS | Windows | Linux ARM | macOS ARM | Windows ARM | Android | iOS | |
|---|---|---|---|---|---|---|---|---|
| GitHub Actions | β | β | β | β | β | β Β² | β β΄ | β Β³ |
| Azure Pipelines | β | β | β | β | β Β² | β β΄ | β Β³ | |
| Travis CI | β | β | β | β β΄ | ||||
| CircleCI | β | β | β | β | β β΄ | β Β³ | ||
| Gitlab CI | β | β | β | β ΒΉ | β | β β΄ | β Β³ | |
| Cirrus CI | β | β | β | β | β | β β΄ |
ΒΉ Requires emulation, distributed separately. Other services may also support Linux ARM through emulation or third-party build hosts, but these are not tested in our CI.
Β² Uses cross-compilation. It is not possible to test arm64 on this CI platform.
Β³ Requires a macOS runner; runs tests on the simulator for the runner's architecture.
β΄ Building for Android requires the runner to be Linux x86_64, macOS ARM64 or macOS x86_64. Testing has additional requirements.
To build manylinux, musllinux, macOS, and Windows wheels on GitHub Actions, you could use this .github/workflows/wheels.yml:
name: Build
on: [push, pull_request]
jobs:
build_wheels:
name: Build wheels on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-latest, ubuntu-24.04-arm, windows-latest, windows-11-arm, macos-15-intel, macos-latest]
steps:
- uses: actions/checkout@v5
# Used to host cibuildwheel
- uses: actions/setup-python@v5
- name: Install cibuildwheel
run: python -m pip install cibuildwheel==3.3.1
- name: Build wheels
run: python -m cibuildwheel --output-dir wheelhouse
# to supply options, put them in 'env', like:
# env:
# CIBW_SOME_OPTION: value
# ...
- uses: actions/upload-artifact@v4
with:
name: cibw-wheels-${{ matrix.os }}-${{ strategy.job-index }}
path: ./wheelhouse/*.whl
For more information, including PyPI deployment, and the use of other CI services or the dedicated GitHub Action, check out the documentation and the examples.
The following diagram summarises the steps that cibuildwheel takes on each platform.

Explore an interactive version of this diagram in the docs.
| Option | Description | |
|---|---|---|
| Build selection | platform | Override the auto-detected target platform |
buildskip | Choose the Python versions to build | |
archs | Change the architectures built on your machine by default. | |
project-requires-python | Manually set the Python compatibility of your project | |
enable | Enable building with extra categories of selectors present. | |
allow-empty | Suppress the error code if no wheels match the specified build identifiers | |
| Build customization | build-frontend | Set the tool to use to build, either "build" (default), "build[uv]", or "pip" |
config-settings | Specify config-settings for the build backend. | |
environment | Set environment variables | |
environment-pass | Set environment variables on the host to pass-through to the container. | |
before-all | Execute a shell command on the build system before any wheels are built. | |
before-build | Execute a shell command preparing each wheel's build | |
xbuild-tools | Binaries on the path that should be included in an isolated cross-build environment. | |
repair-wheel-command | Execute a shell command to repair each built wheel | |
manylinux-*-imagemusllinux-*-image | Specify manylinux / musllinux container images | |
container-engine | Specify the container engine to use when building Linux wheels | |
dependency-versions | Control the versions of the tools cibuildwheel uses | |
pyodide-version | Specify the Pyodide version to use for pyodide platform builds | |
| Testing | test-command | The command to test each built wheel |
before-test | Execute a shell command before testing each wheel | |
test-sources | Paths that are copied into the working directory of the tests | |
test-requires | Install Python dependencies before running the tests | |
test-extras | Install your wheel for testing using extras_require | |
test-groups | Specify test dependencies from your project's dependency-groups | |
test-skip | Skip running tests on some builds | |
test-environment | Set environment variables for the test environment | |
test-runtime | Controls how the tests will be executed. | |
| Debugging | debug-keep-container | Keep the container after running for debugging. |
debug-traceback | Print full traceback when errors occur. | |
build-verbosity | Increase/decrease the output of the build |
These options can be specified in a pyproject.toml file, or as environment variables, see configuration docs.
Here are some repos that use cibuildwheel.
| Name | CI | OS | Notes |
|---|---|---|---|
| scikit-learn | The machine learning library. A complex but clean config using many of cibuildwheel's features to build a large project with Cython and C++ extensions. | ||
| duckdb | DuckDB is an analytical in-process SQL database management system | ||
| pytorch-fairseq | Facebook AI Research Sequence-to-Sequence Toolkit written in Python. | ||
| NumPy | The fundamental package for scientific computing with Python. | ||
| Tornado | Tornado is a Python web framework and asynchronous networking library. Uses stable ABI for a small C extension. | ||
| NCNN | ncnn is a high-performance neural network inference framework optimized for the mobile platform | ||
| Matplotlib | The venerable Matplotlib, a Python library with C++ portions | ||
| MyPy | The compiled version of MyPy using MyPyC. | ||
| Prophet | Tool for producing high quality forecasts for time series data that has multiple seasonality with linear or non-linear growth. | ||
| Kivy | Open source UI framework written in Python, running on Windows, Linux, macOS, Android and iOS |
βΉοΈ That's just a handful, there are many more! Check out the Working Examples page in the docs.
Since cibuildwheel repairs the wheel with delocate or auditwheel, it might automatically bundle dynamically linked libraries from the build machine.
It helps ensure that the library can run without any dependencies outside of the pip toolchain.
This is similar to static linking, so it might have some license implications. Check the license for any code you're pulling in to make sure that's allowed.
5 January 2026
12 November 2025
test-runtime option, to customise how tests on simulated/emulated environments are run (#2636)manylinux_2_35 images on 32-bit ARM armv7l, offering better C++20 compatibility (#2656)build[uv] is now supported on Android (#2587)uv) with a simple option on the GitHub Action (#2630){project} and {package} placeholders are now supported in repair-wheel-command (#2589)dependency-versions no longer constrain packages specified by your build-system.requires. Previously, on platforms other than Linux, the constraints in this option would remain in the environment during the build. This has been tidied up make behaviour more consistent between platforms, and to prevent version conflicts. (#2583)test-command on Android, enabling more options to be passed (#2590)12 October 2025
22 September 2025
pypy-eol in the enable option, as it is now end-of-life. (#2521)19 August 2025
--clean-cache command to clean up our cache (#2489)pyodide-build when dependency-versions is set (#2548)CMAKE_FIND_ROOT_PATH_MODE_PACKAGE to BOTH on Android (#2547)patchelf dependency for platforms that can build Android wheels (#2552)CIBW_ARCHS like most other environment variables (#2541)color and suggest_on_error argparse options are now default in 3.14rc1+ (#2554)That's the last few versions.
βΉοΈ Want more changelog? Head over to the changelog page in the docs.
For more info on how to contribute to cibuildwheel, see the docs.
Everyone interacting with the cibuildwheel project via codebase, issue tracker, chat rooms, or otherwise is expected to follow the PSF Code of Conduct.
Core:
Platform maintainers:
cibuildwheel stands on the shoulders of giants.
run_with_env.cmdMassive props also to-
Another very similar tool to consider is matthew-brett/multibuild. multibuild is a shell script toolbox for building a wheel on various platforms. It is used as a basis to build some of the big data science tools, like SciPy.
If you are building Rust wheels, you can get by without some of the tricks required to make GLIBC work via manylinux; this is especially relevant for cross-compiling, which is easy with Rust. See maturin-action for a tool that is optimized for building Rust wheels and cross-compiling.
FAQs
Build Python wheels on CI with minimal configuration.
We found that cibuildwheel demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.