General

GitHub Actions leaking secrets when Miri output is cached

The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches. While not necessary a vulnerability in and of itself, when paired with GitHub Actions caching behavior, it is possible for this to expose secrets to PRs. Overview GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing…

Quelle: Originalartikel öffnen

AI Assistant
Context loaded: GitHub Actions leaking secrets when Miri output is cached