Skip to content

Bump 1password/load-secrets-action from 4.0.1 to 5.0.1 - #34

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/1password/load-secrets-action-5.0.1
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/1password/load-secrets-action-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps 1password/load-secrets-action from 4.0.1 to 5.0.1.

Release notes

Sourced from 1password/load-secrets-action's releases.

v5.0.1

What's Changed

Fixes

  • Correct the authentication error message. It previously listed only the CLI methods (OP_SERVICE_ACCOUNT_TOKEN, or OP_CONNECT_HOST + OP_CONNECT_TOKEN), which misled anyone who meant to use Workload Identity but had one of those variables missing or misspelled. It now lists OP_WORKLOAD_ID + OP_ENVIRONMENT_ID + OP_INTEGRATION_KEY as a third valid option. (#187)

Dependencies

  • Bump @1password/sdk from 0.5.0-beta.1 to the stable 0.5.0, and rebuild dist/ (including core_bg.wasm). (#187)
  • Update the baked-in beta CLI fallback version: 2.38.1-beta.02 → 2.39.0-beta.02.

Security

  • Harden CI: add the StepSecurity harden-runner and pin GitHub Actions to commit SHAs across the E2E and fallback-version workflows, and restrict workflow permissions. (#182)

Full Changelog: 1Password/load-secrets-action@v5.0.0...v5.0.1

v5.0.0

What's Changed

Features

  • Add Workload Identity authentication using the GitHub Actions OIDC token (public preview). (#169)

Full Changelog: 1Password/load-secrets-action@v4.1.1...v5.0.0

v5.0.0-beta.1

What's Changed

Feature

  • Add Workload Identity authentication using the GitHub Actions OIDC token (private beta) (#169)

Full Changelog: 1Password/load-secrets-action@v4.0.0...v5.0.0-beta.1

v4.1.1

What's Changed

Features

  • Add fallback version resolution so if app-updates.agilebits.com is unavailable, the action now falls back to Docker Hub and then a baked-in pinned version. (#173 )

Security

  • Harden CI security: add StepSecurity harden runner and pin GitHub Actions to commit SHAs across workflows, restrict workflow permissions, and add Dependabot config. (#174 )

Full Changelog: 1Password/load-secrets-action@v4.0.1...v4.1.1

Commits
  • 70062d7 Merge pull request #190 from 1Password/release/v5.0.1
  • 6f5bd0e Prepare Release 5.0.1
  • 846abe0 Merge pull request #187 from 1Password/jill/bump-to-stable-sdk
  • 557708f Bump sdk type
  • 2d8a25c Merge pull request #182 from 1Password/chore/GHA-211518-stepsecurity-remediation
  • e544b78 Prepare Release v5.0.0 (#185)
  • eb2efd0 Merge pull request #183 from 1Password/release/v4.1.1
  • 22158bd Prepare release
  • 631992c Apply GitHub Actions security best practices
  • 19a016f Merge pull request #174 from 1Password/chore/GHA-151735-stepsecurity-remediation
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [1password/load-secrets-action](https://github.com/1password/load-secrets-action) from 4.0.1 to 5.0.1.
- [Release notes](https://github.com/1password/load-secrets-action/releases)
- [Commits](1Password/load-secrets-action@3a12b0a...70062d7)

---
updated-dependencies:
- dependency-name: 1password/load-secrets-action
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

PR: #34
Mode: squash
Topic: GH-oparent-34
Change-Ids:
Id66bf4aa4946fc12fb32e3a84e53ac5c722159f2
Digest: 1b26619d4e69
GitHub-Hash: a06c5e95ad8edf52

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/oparent/+/148011

onap-github pushed a commit that referenced this pull request Oct 7, 2026
## Release notes

Sourced from 1password/load-secrets-action's releases.

v5.0.1
What's Changed
Fixes

Correct the authentication error message. It previously listed only the CLI methods (OP_SERVICE_ACCOUNT_TOKEN, or OP_CONNECT_HOST + OP_CONNECT_TOKEN), which misled anyone who meant to use Workload Identity but had one of those variables missing or misspelled. It now lists OP_WORKLOAD_ID + OP_ENVIRONMENT_ID + OP_INTEGRATION_KEY as a third valid option. (#187)

Dependencies

Bump @1password/sdk from 0.5.0-beta.1 to the stable 0.5.0, and rebuild dist/ (including core_bg.wasm). (#187)
Update the baked-in beta CLI fallback version: 2.38.1-beta.02 → 2.39.0-beta.02.

Security

Harden CI: add the StepSecurity harden-runner and pin GitHub Actions to commit SHAs across the E2E and fallback-version workflows, and restrict workflow permissions. (#182)

Full Changelog: 1Password/load-secrets-action@v5.0.0...v5.0.1
v5.0.0
What's Changed
Features

Add Workload Identity authentication using the GitHub Actions OIDC token (public preview). (#169)

Full Changelog: 1Password/load-secrets-action@v4.1.1...v5.0.0
v5.0.0-beta.1
What's Changed
Feature

Add Workload Identity authentication using the GitHub Actions OIDC token (private beta) (#169)

Full Changelog: 1Password/load-secrets-action@v4.0.0...v5.0.0-beta.1
v4.1.1
What's Changed
Features

Add fallback version resolution so if app-updates.agilebits.com is unavailable, the action now falls back to Docker Hub and then a baked-in pinned version. (#173 )

Security

Harden CI security: add StepSecurity harden runner and pin GitHub Actions to commit SHAs across workflows, restrict workflow permissions, and add Dependabot config. (#174 )

Full Changelog: 1Password/load-secrets-action@v4.0.1...v4.1.1

## Commits

70062d7 Merge pull request #190 from 1Password/release/v5.0.1
6f5bd0e Prepare Release 5.0.1
846abe0 Merge pull request #187 from 1Password/jill/bump-to-stable-sdk
557708f Bump sdk type
2d8a25c Merge pull request #182 from 1Password/chore/GHA-211518-stepsecurity-remediation
e544b78 Prepare Release v5.0.0 (#185)
eb2efd0 Merge pull request #183 from 1Password/release/v4.1.1
22158bd Prepare release
631992c Apply GitHub Actions security best practices
19a016f Merge pull request #174 from 1Password/chore/GHA-151735-stepsecurity-remediation
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: Id66bf4aa4946fc12fb32e3a84e53ac5c722159f2
GitHub-PR: #34
GitHub-Hash: a06c5e95ad8edf52
Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Oct 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/1password/load-secrets-action-5.0.1 branch October 7, 2026 07:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants