deps: ci: bump 1password/load-secrets-action from 2 to 3
- Dominant language
- Go
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Dependabot Update
Bumps [1password/load-secrets-action](https://github.com/1password/load-secrets-action) from 2 to 3.
Release notes
Sourced from 1password/load-secrets-action's releases.
v3.0.0
What's Changed
🔴 Breaking change
- Set
export-envinput tofalseby default by@volodymyrZotovin 1Password/load-secrets-action#114
If you want export secrets as env variables you should update your workflows and explicitly setexport-env: trueaka- name: Load secret
uses: 1password/load-secrets-action@v3
with:
# Export loaded secrets as environment variables
export-env: true
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }}
SECRET: op://app-cicd/hello-world/secret- name: Print masked secret
run: 'echo "Secret: $SECRET"'
# Prints: Secret: ***
🚀 Features
- Use op cli installer to enable Windows support by
@volodymyrZotovin 1Password/load-secrets-action#109- Set default for
versioninput by@volodymyrZotovin 1Password/load-secrets-action#112🔒 Security
- Use of Insufficiently Random Values in undici {#103}
- undici Denial of Service attack via bad certificate data {#103}
Full Changelog: https://github.com/1Password/load-secrets-action/compare/v2...v3.0.0
Commits
8d0d610Merge pull request #129 from 1Password/release/v3.1.076bec67Make latest build74311b1Bump version in package-lock.json5999940Bump version to 3.1.0b43a224Make latest buildc2b96b5Merge pull request #128 from 1Password/dependabot/npm_and_yarn/multi-75e6bc52106f52eddBump js-yamldc5cd4dMerge pull request #127 from 1Password/vzt/delete-op-cli-installer-dependencyb4962e1Use execFile to run safily pass arguments2f243caUse op-cli-installed as local package- Additional commits viewable in compare view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
## Pull Request
- PR: #45
- Author: @dependabot[bot]
- URL: https://github.com/aRustyDev/pcf-mcp/pull/45
---
This issue was automatically created to track the Dependabot update.
Contributor guide
Assessment
This issue has not been assessed yet.