Post

GitHub Actions leaking secrets when Miri output is cached

Rust’s security team found that cargo miri had been saving environment variables into target/; when CI caches that directory for pull requests, credentials exposed to the Miri job could become readable in later PR runs. The team narrowed what Miri preserves and advises affected projects to update to the September 22 nightly, clear caches, and rotate potentially exposed secrets. The report identified one repository with the issue, but warns that its ecosystem scan may have missed cases; the broader lesson is to keep secrets out of jobs that write shared caches.

In the 16-comment Reddit thread, maintainers recommend separating “runs untrusted code” jobs from “has secrets” jobs. Others note that restricting Miri’s saved variables can affect build reproducibility and that caches are only one part of CI secret hygiene.