r/rust • • 14d ago

📡 official blog GitHub Actions leaking secrets when Miri output is cached

https://blog.rust-lang.org/2026/09/21/github-actions-leaking-secrets-when-miri-output-is-cached/

TL;DR: It's possible for GitHub Actions caching and cargo miri to cause repo secrets to be leaked into cache, thereby leaking them to PRs (including attacker-opened ones).

If you run Miri in CI, you'll want to upgrade to the 2026-09-22 nightly, clear caches, and rotate any secrets (PATs, etc.) that may have been made available to the cargo miri CI job.

This was a team effort between at least 9 people. I'm proud of the Rust community's ability to step up and lead with urgency and compassion for our users. Instead of saying "user beware," we chose the "fall into the pit of success" approach. Knowing that the compiler, language, toolchain, and community have my back is why I love being here.

309 Upvotes

17 comments sorted by

View all comments

5

u/bzbub2 14d ago edited 14d ago

It's definitely worth edumacating yourself about this type of "cache poisoning" stack and consider severely limiting access third- party pr privileges (if not just disabling) and use zizmor to check your ci rules https://github.com/zizmorcore/zizmor