deps: ci: bump 1password/load-secrets-action from 2 to 3

Open
#48 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
20/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Stale
Tech stack
github-actions
Domain
ci-cd

Research direction

Start by reviewing the GitHub Actions workflow usage of 1password/load-secrets-action and the existing PR #45. Check the v3 breaking change around export-env, then verify that CI passes and secret-loading behavior remains correct after the dependency update.

Written by the indexing model from the issue text.

Description

dependencies github-actions

Dependabot Update

Bumps 1password/load-secrets-action from 2 to 3.

Release notes

Sourced from 1password/load-secrets-action's releases.

v3.0.0

What's Changed

🔴 Breaking change
      - name: Load secret
        uses: 1password/load-secrets-action@v3
        with:
          # Export loaded secrets as environment variables
          export-env: true
        env:
          OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_SERVICE_ACCOUNT_TOKEN }}
          SECRET: op://app-cicd/hello-world/secret
  - name: Print masked secret
    run: 'echo "Secret: $SECRET"'
    # Prints: Secret: ***

🚀 Features
🔒 Security

Full Changelog: https://github.com/1Password/load-secrets-action/compare/v2...v3.0.0

Commits
  • 8d0d610 Merge pull request #129 from 1Password/release/v3.1.0
  • 76bec67 Make latest build
  • 74311b1 Bump version in package-lock.json
  • 5999940 Bump version to 3.1.0
  • b43a224 Make latest build
  • c2b96b5 Merge pull request #128 from 1Password/dependabot/npm_and_yarn/multi-75e6bc5210
  • 6f52edd Bump js-yaml
  • dc5cd4d Merge pull request #127 from 1Password/vzt/delete-op-cli-installer-dependency
  • b4962e1 Use execFile to run safily pass arguments
  • 2f243ca Use op-cli-installed as local package
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Pull Request


This issue was automatically created to track the Dependabot update.

Dominant language
Go
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from aRustyDev/pcf-mcp

All issues in aRustyDev/pcf-mcp

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.