Skip to content

Bump 1password/load-secrets-action to v5.0.1 (notifications) - #1263

Merged
Hailong-am merged 1 commit into
opensearch-project:mainfrom
peterzhuamazon:1password-actions-v5
Aug 20, 2026
Merged

Bump 1password/load-secrets-action to v5.0.1 (notifications)#1263
Hailong-am merged 1 commit into
opensearch-project:mainfrom
peterzhuamazon:1password-actions-v5

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Description

Bump 1password/load-secrets-action to v5.0.1 (pinned to commit 70062d7a876d3eb6334754fa26efd2fbd90c32f2).

Issues Resolved

opensearch-project/opensearch-build#6440 (comment)

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 3f073c7.

Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
.github/workflows/maven-publish.yml30highGitHub Actions dependency change: 1password/load-secrets-action pinned commit hash updated from 581a835fb51b8e7ec56b71cf2ffddd7e68bb25e0 (v2) to 70062d7a876d3eb6334754fa26efd2fbd90c32f2 (v5.0.1). This action has privileged access to 1Password secrets and exports them as environment variables — a tampered version could silently exfiltrate all loaded secrets. The large version jump (v2 to v5.0.1) and new commit hash must be verified against the official 1password/load-secrets-action repository to confirm authenticity.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@peterzhuamazon peterzhuamazon added v3.9.0 skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. labels Aug 20, 2026
@Hailong-am
Hailong-am merged commit ee55299 into opensearch-project:main Aug 20, 2026
40 of 41 checks passed
@github-project-automation github-project-automation Bot moved this from 👀 In Review to ✅ Done in Engineering Effectiveness Board Aug 20, 2026
@opensearch-ci-bot

Copy link
Copy Markdown
Contributor

The backport to 2.19 failed. Please backport manually. See failed workflow run: https://github.com/opensearch-project/notifications/actions/runs/32324572135

@github-actions

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

peterzhuamazon added a commit that referenced this pull request Aug 20, 2026
…1264)

(cherry picked from commit ee55299)

Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com>
Co-authored-by: Peter Zhu <zhujiaxi@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 2.19 backport 3.8 enhancement New feature or request release skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. v3.9.0

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

3 participants