GitHub Actions leaking secrets when Miri output is cached
Miri stores all environment variables in the target directory, which persists when GitHub Actions caches that folder, allowing secrets to be read by pull‑request runs. The Rust Security Response Team issued a fix limiting saved variables to CARGO_* and OUT_DIR, and warned projects to audit their CI caches.
Miri writes every environment variable into the compilation directory. When workflows leverage persistent storage features between test runs, those sensitive parameters remain accessible. According to the Rust Security Response Team, combining this behavior with external continuous integration platforms allows unauthorized pull requests to read protected data. Developers utilizing Miri within automated pipelines that save build folders are potentially exposed. The response team stated that an ecosystem scan found one repository experiencing the problem and a handful of others that should remain cautious. It is possible the scan missed some projects, meaning anyone running the affected tool with accessible storage configurations might be impacted. Maintainers should inspect their continuous integration pipelines and clear existing saved data. The response team issued a patch restricting saved parameters to specific prefixes, and a future release scheduled for 2026-09-22 will remove the problematic behavior entirely. Teams are also advised to rotate any credentials that may have been exposed during previous test executions.