sftcd
d01cd520e5
require manual build for external ECH tests
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Matt Caswell <matt@openssl.org >
MergeDate: Fri Feb 20 14:16:40 2026
(Merged from https://github.com/openssl/openssl/pull/30059 )
2026-02-20 14:16:07 +00:00
Stanislav Zidek
0a99c3e9df
interop tests: update
...
* simplified specfile
* newer tests
* update to Fedora-43
Signed-off-by: Stanislav Zidek <szidek@redhat.com >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
MergeDate: Mon Feb 9 10:00:14 2026
(Merged from https://github.com/openssl/openssl/pull/29559 )
2026-02-09 11:00:12 +01:00
Alexandr Nedvedicky
539c7a001d
Add enable-tls-deprecated-ec option to keep provider compatibility
...
test happy.
Fixes openssl/project#1849
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Viktor Dukhovni <viktor@openssl.org >
MergeDate: Mon Feb 2 16:50:45 2026
(Merged from https://github.com/openssl/openssl/pull/29866 )
2026-02-02 11:50:41 -05:00
Orgad Shaneh
4430162203
CI: Disable scheduled Fuzzing action in forks
...
There is no reason to run it in forks.
Similar to 6e5ce1ebb5 .
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
MergeDate: Mon Jan 26 15:47:57 2026
(Merged from https://github.com/openssl/openssl/pull/29660 )
2026-01-26 16:47:50 +01:00
Helen Zhang
fe67753da4
Add SRTPKDF implementation
...
In compliance with RFC 3711, Section 4.3.3
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Shane Lontis <shane.lontis@oracle.com >
MergeDate: Fri Jan 23 10:19:32 2026
(Merged from https://github.com/openssl/openssl/pull/29435 )
2026-01-23 11:19:31 +01:00
Neil Horman
a4148379a8
check-news-changes.yml: Fix the label check
...
The yaml for the check-news-changes CI job had an error in the step
conditional that prevented skipping the check if the
no_news_changes_needed flag was set. Fix that.
While we're add it, also add some debug code so that we can better see
what the checks are looking at during the CI job.
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
MergeDate: Thu Jan 22 17:19:07 2026
(Merged from https://github.com/openssl/openssl/pull/29705 )
2026-01-22 18:18:40 +01:00
slontis
fe874fcf0d
KDF: Add configuration options to disable many of the KDF algorithms.
...
This includes KDF's for ss,x963,hmac-drbg,KB,KRB5,PVK,SNMP,SSH and X942.
SSKDF/X963KDF Changes: Modify code to handle algorithms being disabled via configuration options.
Reviewed-by: Tim Hudson <tjh@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29576 )
2026-01-19 15:51:45 +11:00
Dmitry Belyavskiy
54d175c7d5
Disabling explicit EC curves encoding
...
In case the parameters don't exactly match the well-known ones
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Simo Sorce <simo@redhat.com >
(Merged from https://github.com/openssl/openssl/pull/29639 )
2026-01-17 10:31:43 +01:00
Neil Horman
84ee443446
Fix search pattern in check-news-changes CI job
...
The check for impacting a public api had an incorrect pattern in the
search, leading to erroneous failures. Fix it up.
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
MergeDate: Thu Jan 15 17:14:30 2026
(Merged from https://github.com/openssl/openssl/pull/29636 )
2026-01-15 12:14:25 -05:00
Norbert Pocs
2bc0ee0400
github/workflows: Update checkout@v5 to v6
...
New version is out.
Signed-off-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Dmitry Misharov <dmitry@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29566 )
2026-01-14 10:27:17 +01:00
Neil Horman
faf48d097b
Update .github/workflows/check-news-changes.yml
...
Co-authored-by: Pocs Norbert <norbertpocs0@gmail.com >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
MergeDate: Tue Jan 13 19:17:42 2026
(Merged from https://github.com/openssl/openssl/pull/29536 )
2026-01-13 14:17:34 -05:00
Neil Horman
7f51fd8ef7
Create a simple check for suggesting NEWS/CHANGES additions
...
During a release cycle we always wind up going through our git history
to try make sure we caught all the stuff that needed a CHANGES/NEWS
entry. Lets try make that at least a little more automated here. PR's
that reference CVEs, come from feature branches or impact public apis
generally need a NEWS/CHANGES entry, so lets flag those during CI. It
should serve as a reminder to add entries to NEWS/CHANGES to prs meeting
the above criteria, and can be ignored via the application of the
no_news_changes_needed label to the PR.
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
MergeDate: Tue Jan 13 19:17:37 2026
(Merged from https://github.com/openssl/openssl/pull/29536 )
2026-01-13 14:17:26 -05:00
Milan Broz
f442c00266
Add clang-21 to CI compilers
...
Signed-off-by: Milan Broz <gmazyland@gmail.com >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29587 )
2026-01-12 12:20:16 +01:00
Dmitry Misharov
ca58a66e31
do not hardcode CI workspace path
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29577 )
2026-01-12 12:07:45 +01:00
Nikola Pajkovsky
277634a842
lhash_test: set back num_workers to 16
...
commit 131c2a1adb ("Defang the lhash test") has reduced default number
of the thread workers in CI to HARNESS_JOBS / 4. Setting LHASH_WORKERS
will set it back.
Resolves: https://github.com/openssl/project/issues/1769
Signed-off-by: Nikola Pajkovsky <nikolap@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
MergeDate: Mon Jan 12 10:09:54 2026
(Merged from https://github.com/openssl/openssl/pull/29565 )
2026-01-12 11:09:47 +01:00
Tomas Mraz
9aeb35372f
run-checker-daily.yml: heartbeats cannot be enabled anymore
...
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Neil Horman <nhorman@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29517 )
2025-12-31 12:49:43 -05:00
xxcui
14018b02df
SM3: Performance optimized with RISC-V Vector Crypto
...
RISC-V Cryptographic Vector Extension provides ZVK instructions which
can be used to accelerate SM3 computing.
By calculating SHA512 performance on C930 FPGA, it is proven that sm3
speed is improved from 120695K to 323844K.
Reviewed-by: Paul Yang <paulyang.inf@gmail.com >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29264 )
2025-12-31 13:43:19 +01:00
Neil Horman
0755a8ef90
Add ci test to run against minimal gcc version we support
...
We currently support gcc 9 as a minimum compiler version. We should run
at least one ci job against that minimal version to make sure we don't
break anything.
Most notably this will help us catch errors if we attempt to use
intrinsics that aren't supported by that compiler.
Reviewed-by: Paul Yang <paulyang.inf@gmail.com >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29482 )
2025-12-26 17:32:46 -05:00
Andrew Dinh
0b271780ea
Remove sslv3 flags from x86 CI jobs
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Viktor Dukhovni <viktor@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29338 )
2025-12-23 10:54:08 -05:00
Kurt Roeckx
60c15b2aff
Remove support for SSLv3
...
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Viktor Dukhovni <viktor@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29338 )
2025-12-23 10:54:06 -05:00
Norbert Pocs
077e94f6e5
Interop: c_rehash was removed; don't look for it
...
Signed-off-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29474 )
2025-12-23 07:55:37 -05:00
xxcui
93119bae7f
SHA512 performance optimized by RISCV RVV
...
This patch is dedicated to improve SHA512 speed with RISCV
Cryptographic Vector Extension.
Below performance output is calculated by Xuantie C930 FPGA with VLEN256.
- sha512 speed might be improved from 197032K to 1010986KB
Reviewed-by: Paul Yang <paulyang.inf@gmail.com >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29263 )
2025-12-23 14:50:26 +11:00
Stanislav Zidek
02d2431973
interop: fix for engine removal
...
CLA: trivial
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29333 )
2025-12-14 11:24:30 -05:00
Neil Horman
5ba513fadd
Remove crypto-mdebug-backtrace option from config
...
We still build with crypto-mdebug-backtrace enabled in a few ci jobs,
but it does nothing.
With the upcoming merge of feature/removesslv3, the code changes there
prevent the use of this option (i.e. enabling it results in
configuration failure).
It seems the most sensible thing to do here, given we have a major
release is to eliminate the option entirely, as it hasn't done anything
since 1.0.2.
Fixes openssl/project#1763
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Simo Sorce <simo@redhat.com >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29380 )
2025-12-12 19:34:54 -05:00
Dmitry Misharov
d6f3733f94
add clang-format as a pre-commit hook
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29282 )
2025-12-09 10:23:48 -05:00
Milan Broz
197ae2f63d
ci: Remove no longer supported config options
...
Signed-off-by: Milan Broz <gmazyland@gmail.com >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Matt Caswell <matt@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29305 )
2025-12-04 07:32:18 -05:00
Milan Broz
cfd96295fc
Remove ENGINESDIR variable and engines installation from Makefiles.
...
For compatibility reasons, OPENSSL_ENGINES_DIR and OPENSSL_INFO_ENGINES_DIR
are still supported but return values like with engines disabled.
The OPENSSL_ENGINES environment variable will be removed with engine
removal later.
Resolves: https://github.com/openssl/project/issues/1425
Signed-off-by: Milan Broz <gmazyland@gmail.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Matt Caswell <matt@openssl.org >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29305 )
2025-12-04 07:31:06 -05:00
Tomas Mraz
af05eeb59c
windows.yml: Clean up duplicate --strict-warnings option
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29300 )
2025-12-03 15:25:20 +01:00
Bernd Edlinger
0857839af1
CIFuzz: Remove some unnecessary files to free up space
...
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29061 )
2025-12-03 14:10:40 +01:00
Igor Ustinov
20991f3000
Branch 3.2 was removed from and branch 3.6 was added to the
...
"Provider compatibility for PRs" test.
Do not test the provider from the PR against modified branches.
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29236 )
2025-12-01 13:27:40 +11:00
Igor Ustinov
7e430d9dc1
Branch 3.2 was removed from the "Provider compatibility across versions"
...
test and "skip the same version" logic was changed.
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/29236 )
2025-12-01 13:27:40 +11:00
Dmitry Misharov
d40b314a75
add release notes from NEWS.md when making a release
...
Reviewed-by: Matt Caswell <matt@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29224 )
2025-11-28 17:41:01 +01:00
Neil Horman
0b803c2adc
merge x509 and handshake memfail test
...
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28736 )
2025-11-19 15:53:01 +01:00
Neil Horman
7916bccc77
Add x509 memfail test to run_checker_daily
...
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28736 )
2025-11-19 15:52:44 +01:00
Dmitry Misharov
793a744f2b
add CI job for linux-x86 platform
...
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29123 )
2025-11-19 14:16:37 +01:00
dependabot[bot]
af50059508
Dependabot update
...
CLA: trivial
(deps): Bump cross-platform-actions/action
Bumps [cross-platform-actions/action](https://github.com/cross-platform-actions/action ) from 0.27.0 to 0.30.0.
- [Release notes](https://github.com/cross-platform-actions/action/releases )
- [Changelog](https://github.com/cross-platform-actions/action/blob/master/changelog.md )
- [Commits](https://github.com/cross-platform-actions/action/compare/fe0167d8082ac584754ef3ffb567fded22642c7d...46e8d7fb25520a8d6c64fd2b7a1192611da98eda )
---
updated-dependencies:
- dependency-name: cross-platform-actions/action
dependency-version: 0.30.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Richard Levitte <levitte@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29129 )
2025-11-13 12:56:33 +01:00
dependabot[bot]
4aa9ebde22
Dependabot update
...
CLA: trivial
(deps): Bump docker/setup-docker-action
Bumps [docker/setup-docker-action](https://github.com/docker/setup-docker-action ) from 4.4.0 to 4.5.0.
- [Release notes](https://github.com/docker/setup-docker-action/releases )
- [Commits](https://github.com/docker/setup-docker-action/compare/3fb92d6d9c634363128c8cce4bc3b2826526370a...efe9e3891a4f7307e689f2100b33a155b900a608 )
---
updated-dependencies:
- dependency-name: docker/setup-docker-action
dependency-version: 4.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Richard Levitte <levitte@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29126 )
2025-11-13 12:55:26 +01:00
dependabot[bot]
3bd52f8243
Dependabot update
...
CLA: trivial
(deps): Bump dtolnay/rust-toolchain
Bumps [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain ) from 6d653acede28d24f02e3cd41383119e8b1b35921 to 0f44b27771c32bda9f458f75a1e241b09791b331.
- [Release notes](https://github.com/dtolnay/rust-toolchain/releases )
- [Commits](https://github.com/dtolnay/rust-toolchain/compare/6d653acede28d24f02e3cd41383119e8b1b35921...0f44b27771c32bda9f458f75a1e241b09791b331 )
---
updated-dependencies:
- dependency-name: dtolnay/rust-toolchain
dependency-version: 0f44b27771c32bda9f458f75a1e241b09791b331
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29125 )
2025-11-13 12:47:41 +01:00
dependabot[bot]
92261e77a6
Dependabot update
...
CLA: trivial
(deps): Bump actions/setup-python
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 5.3.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v5.3.0...v6.0.0 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Richard Levitte <levitte@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29105 )
2025-11-13 12:45:23 +01:00
Dmitry Misharov
cd79a23174
revert changes in "FIPS Check and ABIDIFF" workflow
...
Applying labels is not possible from pull request
context. This commit reverts changes from
8948ccdf03 commit.
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29112 )
2025-11-12 11:02:29 +01:00
Dmitry Misharov
c6a9f090af
Run CIFuzz workflow on schedule
...
There is no point to run oss-fuzz on each pull request.
Reviewed-by: Bernd Edlinger <bernd.edlinger@hotmail.de >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29080 )
2025-11-12 10:29:37 +01:00
Bernd Edlinger
70b3250ed8
print CPUINFO in QEMU cross-compile jobs
...
Reviewed-by: Paul Dale <paul.dale@oracle.com >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
(Merged from https://github.com/openssl/openssl/pull/28760 )
2025-11-10 07:18:29 +01:00
dependabot[bot]
1b2e3bd233
Dependabot update
...
CLA: trivial
(deps): Bump actions/download-artifact
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 4.1.8 to 6.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v4.1.8...v6.0.0 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29100 )
2025-11-07 14:55:41 +01:00
dependabot[bot]
5cbc1ea8d2
Dependabot update
...
CLA: trivial
(deps): Bump actions/github-script
Bumps [actions/github-script](https://github.com/actions/github-script ) from 7 to 8.
- [Release notes](https://github.com/actions/github-script/releases )
- [Commits](https://github.com/actions/github-script/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: actions/github-script
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29099 )
2025-11-07 14:53:57 +01:00
dependabot[bot]
3066e59dfe
Dependabot update
...
CLA: trivial
(deps): Bump actions/checkout
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29098 )
2025-11-07 14:23:08 +01:00
dependabot[bot]
87afb84c39
Dependabot update
...
CLA: trivial
(deps): Bump cygwin/cygwin-install-action
Bumps [cygwin/cygwin-install-action](https://github.com/cygwin/cygwin-install-action ) from 5 to 6.
- [Release notes](https://github.com/cygwin/cygwin-install-action/releases )
- [Commits](https://github.com/cygwin/cygwin-install-action/compare/f61179d72284ceddc397ed07ddb444d82bf9e559...f2009323764960f80959895c7bc3bb30210afe4d )
---
updated-dependencies:
- dependency-name: cygwin/cygwin-install-action
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29097 )
2025-11-07 14:18:00 +01:00
dependabot[bot]
2ffd40ec50
Dependabot update
...
CLA: trivial
(deps): Bump actions/upload-artifact
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 4 to 5.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29096 )
2025-11-07 14:10:40 +01:00
Dmitry Misharov
c30fb0fbc4
add missing input in dtolnay/rust-toolchain action
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28982 )
2025-11-07 10:46:58 +01:00
Dmitry Misharov
8948ccdf03
remove workflow_run trigger in fips and abiddif workflows
...
workflow_run runs in the context of the target
repository rather than the fork repository, while
also being typically triggerable by the latter.
This can lead to attacker controlled code execution
or unexpected action runs with context controlled
by a malicious fork.
https://docs.zizmor.sh/audits/#dangerous-triggers
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28982 )
2025-11-07 10:46:58 +01:00
Dmitry Misharov
aeb5975f9b
remove workflow_run trigger in quic workflows
...
workflow_run runs in the context of the target
repository rather than the fork repository, while
also being typically triggerable by the latter.
This can lead to attacker controlled code execution
or unexpected action runs with context controlled
by a malicious fork.
https://docs.zizmor.sh/audits/#dangerous-triggers
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28982 )
2025-11-07 10:46:57 +01:00