From 283038fd0f88fe47a7c1f5aa25d0f15e0dbe8590 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 22 Jan 2026 18:27:57 +0000 Subject: [PATCH 1/2] Bump wheel from 0.38.1 to 0.46.2 Bumps [wheel](https://github.com/pypa/wheel) from 0.38.1 to 0.46.2. - [Release notes](https://github.com/pypa/wheel/releases) - [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst) - [Commits](https://github.com/pypa/wheel/compare/0.38.1...0.46.2) --- updated-dependencies: - dependency-name: wheel dependency-version: 0.46.2 dependency-type: direct:development ... Signed-off-by: dependabot[bot] --- requirements_dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements_dev.txt b/requirements_dev.txt index 8fbacac..1cb1d67 100644 --- a/requirements_dev.txt +++ b/requirements_dev.txt @@ -1,6 +1,6 @@ httpx==0.24.0 bump2version==0.5.11 -wheel==0.38.1 +wheel==0.46.2 watchdog==0.9.0 flake8==3.7.8 coverage==4.5.4 From dc03e724cc01c9f3258aa497fa02aedc55cad3e8 Mon Sep 17 00:00:00 2001 From: mbasadi Date: Mon, 9 Feb 2026 13:03:49 -0500 Subject: [PATCH 2/2] Fix wheel version compatibility with Python 3.7/3.8 CI matrix wheel 0.46.2 dropped support for Python <3.9. Use version-specific pinning so older Python versions get wheel 0.42.0 while Python 3.9+ gets the security fix (CVE-2026-24049). Co-authored-by: Cursor --- requirements_dev.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements_dev.txt b/requirements_dev.txt index 1cb1d67..41085f3 100644 --- a/requirements_dev.txt +++ b/requirements_dev.txt @@ -1,12 +1,13 @@ httpx==0.24.0 bump2version==0.5.11 -wheel==0.46.2 watchdog==0.9.0 flake8==3.7.8 coverage==4.5.4 Sphinx==1.8.5 # Version-specific dependencies +wheel==0.42.0; python_version < '3.9' +wheel==0.46.2; python_version >= '3.9' tox==3.24.0; python_version < '3.8' tox==4.8.0; python_version >= '3.8' importlib_metadata<5.0.0; python_version < '3.8'