Skip to content

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (performance-analyzer) - #974

Merged
peterzhuamazon merged 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-972-to-2.19
Aug 24, 2026
Merged

[Backport 2.19] Bump 1password/load-secrets-action to v5.0.1 (performance-analyzer)#974
peterzhuamazon merged 1 commit into
opensearch-project:2.19from
peterzhuamazon:backport/backport-972-to-2.19

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Backport of #972 to 2.19. The auto-backport failed (cherry-pick conflict), so this was recreated manually to the desired end state.

Relates to opensearch-project/opensearch-build#6440 (comment)

Signed-off-by: Peter Zhu zhujiaxi@amazon.com

@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 1b75577.

Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
.github/workflows/maven-publish.yml26highGitHub Actions dependency change: 1password/load-secrets-action updated from pinned commit 2ebe1bc (v2) to 70062d7 (v5.0.1). This is a major version jump (v2 → v5) for an action with direct access to secrets. The new commit hash must be independently verified against the official 1password/load-secrets-action repository to confirm it corresponds to the claimed v5.0.1 tag and has not been tampered with. A compromised version of this action could silently exfiltrate all secrets it loads.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@peterzhuamazon
peterzhuamazon force-pushed the backport/backport-972-to-2.19 branch from e272691 to 1b75577 Compare August 24, 2026 19:01
@peterzhuamazon peterzhuamazon added the skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. label Aug 24, 2026
@github-actions

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

@peterzhuamazon
peterzhuamazon merged commit b0b32c8 into opensearch-project:2.19 Aug 24, 2026
11 of 12 checks passed
@github-project-automation github-project-automation Bot moved this from 👀 In Review to ✅ Done in Engineering Effectiveness Board Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request release skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis.

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

2 participants