GitHub Actions leaking secrets when Miri output is cached

8 points by peter


linkdd

The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches.

Then proceed to blame Github Actions.

NB: All CI platform that provide caching and would naturally cache the build folder that is target/ would have this security hole. The culprit is cargo miri, not Github Actions.