Skip to content

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (sql) - #5712

Open
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-5707-to-2.19
Open

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (sql)#5712
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-5707-to-2.19

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Backport of #5707 to 2.19. The auto-backport failed (cherry-pick conflict), so this was recreated manually to the desired end state.

Relates to opensearch-project/opensearch-build#6440 (comment)

Signed-off-by: Peter Zhu zhujiaxi@amazon.com

@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit be09c37.

PathLineSeverityDescription
.github/workflows/maven-publish.yml29highGitHub Actions dependency change: '1password/load-secrets-action' updated from commit 581a835fb51b8e7ec56b71cf2ffddd7e68bb25e0 (v2) to 70062d7a876d3eb6334754fa26efd2fbd90c32f2 (v5.0.1). This action has direct access to 1Password secrets and exports them as environment variables, making it a high-value supply chain target. The major version jump (v2 → v5.0.1) and new commit hash must be verified against the official 1password/load-secrets-action repository to confirm authenticity before merging.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: 👀 In Review
Status: In review

Development

Successfully merging this pull request may close these issues.

1 participant