Repository navigation
Update pybind11 requirement from >=2.10.0 to >=3.1.0 - #96
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [pybind11](https://github.com/pybind/pybind11) to permit the latest version. - [Release notes](https://github.com/pybind/pybind11/releases) - [Changelog](https://github.com/pybind/pybind11/blob/master/docs/changelog.md) - [Commits](pybind/pybind11@v2.10.0...v3.1.0) --- updated-dependencies: - dependency-name: pybind11 dependency-version: 3.1.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 5967861. Configure here.
| @@ -1,5 +1,5 @@ | |||
| [build-system] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=3.5.0", "pybind11>=2.10.0"] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=3.5.0", "pybind11>=3.1.0"] | |||
There was a problem hiding this comment.
Incomplete pybind11 pin update
Medium Severity
The build-system requirement raises pybind11 to >=3.1.0, but setup_requires in setup.py still allows >=2.10.0. Depending on whether the build goes through PEP 517 or a legacy setup.py path, different major versions can be selected, so the intended floor bump is only half applied.
Reviewed by Cursor Bugbot for commit 5967861. Configure here.
| @@ -1,5 +1,5 @@ | |||
| [build-system] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=3.5.0", "pybind11>=2.10.0"] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=3.5.0", "pybind11>=3.1.0"] | |||
There was a problem hiding this comment.
Python version metadata mismatch
Medium Severity
Requiring pybind11>=3.1.0 makes Python 3.9 the effective minimum for source builds, but python_requires remains >=3.7. On 3.7/3.8, installers accept the package then fail resolving build deps, because no pybind11 3.1+ supports those interpreters.
Reviewed by Cursor Bugbot for commit 5967861. Configure here.


Updates the requirements on pybind11 to permit the latest version.
Release notes
Sourced from pybind11's releases.
... (truncated)
Changelog
Sourced from pybind11's changelog.
... (truncated)
Commits
97bf890chore: prepare 3.1.0 release (#6125)05f6e6ffix(subinterpreter): don't touch the thread state before create() attaches on...6dd1756chore(deps): update pre-commit hooks (#6126)5956509Delegate py::print to Python's native print (#6121)63d627cfeat!: drop support for Python 3.8, MSVC 2017 (#6110)695a7a4chore(deps): bump the actions group with 3 updates (#6119)ea9e6e6feat: small command line helpers for quick tests (#4272)652c694fix: add py::mod_gil_used() spelling, support pedantic tests (#5797)2f85cc8chore(ci): bump NVHPC to 26.5 (#6117)5540f96fix: only add string_view life support for transient sources (#6096)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Medium Risk
Major pybind11 upgrade can break extension builds or runtime binding behavior; 3.1 also drops Python 3.8 support, which may conflict with the project’s existing
python_requiresif 3.7–3.8 are still targeted elsewhere.Overview
Raises the pybind11 minimum in
pyproject.tomlbuild-systemrequiresfrom>=2.10.0to>=3.1.0, so PEP 517 builds can install the current pybind11 major line.This is a dependency-only change; no C++ bindings or build scripts in the diff are modified. Note: pybind11 3.1 no longer supports Python 3.8, while
setup.pystill listspython_requires=">=3.7"andsetup_requireswithpybind11>=2.10.0—those were not updated in this PR.Reviewed by Cursor Bugbot for commit 5967861. Bugbot is set up for automated code reviews on this repo. Configure here.