Skip to content

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (security-analytics) - #1795

Open
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-1793-to-2.19
Open

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (security-analytics)#1795
peterzhuamazon wants to merge 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-1793-to-2.19

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Backport of #1793 to 2.19. The auto-backport failed (cherry-pick conflict), so this was recreated manually to the desired end state.

Relates to opensearch-project/opensearch-build#6440 (comment)

Signed-off-by: Peter Zhu zhujiaxi@amazon.com

@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 155e907.

Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
.github/workflows/maven-publish.yml30highGitHub Action dependency changed from '1password/load-secrets-action@v2' to a pinned commit hash '70062d7a876d3eb6334754fa26efd2fbd90c32f2' claimed to be v5.0.1 — a major version jump (v2 → v5). Per mandatory supply chain policy, all dependency changes must be flagged. Maintainers should verify the commit hash corresponds to the legitimate 1password/load-secrets-action v5.0.1 release and that the major version bump does not introduce behavioral changes affecting secret handling.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request release

Projects

Status: 👀 In Review
Status: In review

Development

Successfully merging this pull request may close these issues.

1 participant