From 639ea319035b32ad16107096f16aca3221018ef2 Mon Sep 17 00:00:00 2001 From: "Matthias J. Kannwischer" Date: Fri, 2 Oct 2026 14:47:17 +0800 Subject: [PATCH 1/2] CI: Bump libOQS, Pavona, and AWS-LC pins Signed-off-by: Matthias J. Kannwischer --- .github/workflows/all.yml | 2 +- .github/workflows/integration-liboqs.yml | 2 +- .github/workflows/integration-pavona.yml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/all.yml b/.github/workflows/all.yml index 42703f3777..31be05ab6b 100644 --- a/.github/workflows/all.yml +++ b/.github/workflows/all.yml @@ -72,7 +72,7 @@ jobs: needs: [ base ] uses: ./.github/workflows/integration-awslc.yml with: - commit: v5.8.0 + commit: v5.11.0 ct-test: name: Constant-time permissions: diff --git a/.github/workflows/integration-liboqs.yml b/.github/workflows/integration-liboqs.yml index 4093060f90..dec1e955ca 100644 --- a/.github/workflows/integration-liboqs.yml +++ b/.github/workflows/integration-liboqs.yml @@ -43,7 +43,7 @@ jobs: packages: 'cmake python3-jinja2 python3-tabulate python3-git python3-pytest valgrind' - uses: ./.github/actions/setup-oqs with: - commit: 'bbe0907a04e8d4ca7afb51976b616c66f1f2dcdc' # main (2026-09-08) + commit: 'e6b9e783747536f34700aab4bd10718c2fecab3f' # main (2026-09-29) gh_token: ${{ secrets.GITHUB_TOKEN }} repository: 'open-quantum-safe/liboqs' - name: Apply patch diff --git a/.github/workflows/integration-pavona.yml b/.github/workflows/integration-pavona.yml index 051a9280ac..96ddd8b5b1 100644 --- a/.github/workflows/integration-pavona.yml +++ b/.github/workflows/integration-pavona.yml @@ -69,7 +69,7 @@ jobs: - uses: ./.github/actions/setup-pavona with: pavona-repository: https://github.com/pavona/pavona - pavona-commit: 08fe42fd9dba4dc1cbd6e16f87d7c1d946885b48 # main (2026-09-05) + pavona-commit: 0677cf18963782bf53e9b49af5d27977f3abf5e4 # main (2026-10-02) - name: Patch mldsa-native dependency run: | From 4e216601bc224abdb0c0c48468fa29cdfc00f7bd Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:48:43 +0000 Subject: [PATCH 2/2] Bump aws-actions/configure-aws-credentials from 6.2.3 to 6.3.0 Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.3 to 6.3.0. - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/e6de054238d6b7531b4efff3b6587d9aade6a06c...e1253824e5c10ff9df46874f81ed3ec929e19cfd) --- updated-dependencies: - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/bench_ec2_reusable.yml | 4 ++-- .github/workflows/ci_ec2_container.yml | 4 ++-- .github/workflows/ci_ec2_reusable.yml | 4 ++-- .github/workflows/integration-pavona.yml | 4 ++-- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/bench_ec2_reusable.yml b/.github/workflows/bench_ec2_reusable.yml index 981ee5ddbc..b79a1126d4 100644 --- a/.github/workflows/bench_ec2_reusable.yml +++ b/.github/workflows/bench_ec2_reusable.yml @@ -115,7 +115,7 @@ jobs: echo "Using AMI ID: $AMI_ID" echo "AMI_ID=$AMI_ID" >> "$GITHUB_OUTPUT" - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ inputs.aws_region }} @@ -239,7 +239,7 @@ jobs: if: ${{ always() }} # required to stop the runner even if the error happened in the previous jobs steps: - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ inputs.aws_region }} diff --git a/.github/workflows/ci_ec2_container.yml b/.github/workflows/ci_ec2_container.yml index ce68259a39..fb9c73bc02 100644 --- a/.github/workflows/ci_ec2_container.yml +++ b/.github/workflows/ci_ec2_container.yml @@ -110,7 +110,7 @@ jobs: echo "Using AMI ID: $AMI_ID" echo "AMI_ID=$AMI_ID" >> "$GITHUB_OUTPUT" - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }} @@ -234,7 +234,7 @@ jobs: if: ${{ always() }} # required to stop the runner even if the error happened in the previous jobs steps: - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }} diff --git a/.github/workflows/ci_ec2_reusable.yml b/.github/workflows/ci_ec2_reusable.yml index d26e32ca5d..e535f14501 100644 --- a/.github/workflows/ci_ec2_reusable.yml +++ b/.github/workflows/ci_ec2_reusable.yml @@ -116,7 +116,7 @@ jobs: echo "Using AMI ID: $AMI_ID" echo "AMI_ID=$AMI_ID" >> "$GITHUB_OUTPUT" - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }} @@ -252,7 +252,7 @@ jobs: if: ${{ always() }} # required to stop the runner even if the error happened in the previous jobs steps: - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }} diff --git a/.github/workflows/integration-pavona.yml b/.github/workflows/integration-pavona.yml index 96ddd8b5b1..afe8cfb33d 100644 --- a/.github/workflows/integration-pavona.yml +++ b/.github/workflows/integration-pavona.yml @@ -35,7 +35,7 @@ jobs: persist-credentials: false - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }} @@ -120,7 +120,7 @@ jobs: if: ${{ always() && needs.start-ec2-runner.result != 'skipped' }} # required to stop the runner even if errors occur steps: - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ env.AWS_ROLE }} aws-region: ${{ env.AWS_REGION }}