Empowering everyone to build reliable and efficient software.
1 comment
linkdd8 days ago
The Rust Security Response Team was notified that Miri stores all environment variables to target/,
allowing secrets to persist in caches.
Then proceed to blame Github Actions.All CI platform that provide caching and would naturally cache the build folder that is target/ would have this security hole. The culprit is cargo miri, not Github Actions.
Read the full thread on Hacker News →
Related stories
- GitHub Actions leaking secrets when Miri output is cachedblog.rust-lang.orgHacker News · 2 points · 9 days ago
- GitHub Actions leaking secrets when Miri output is cachedblog.rust-lang.orgLobsters · 13 points · 8 days ago
- DEV Community · 17 points · 11 days ago
- DEV Community · 10 points · 1 day ago
- Hacker News · 2 points · 6 days ago
- Hacker News · 1 points · 4 days ago