Empowering everyone to build reliable and efficient software.

2 points•metrofun•8 days ago•1 comment•

1 comment

linkdd8 days ago

    The Rust Security Response Team was notified that Miri stores all environment variables to target/,
    allowing secrets to persist in caches.
Then proceed to blame Github Actions.

All CI platform that provide caching and would naturally cache the build folder that is target/ would have this security hole. The culprit is cargo miri, not Github Actions.

Read the full thread on Hacker News →

Related stories