GitHub Actions leaking secrets when Miri output is cached
Summary
The Rust Security Response Team warns that Miri caches environment variables to target/, which can leak secrets to GitHub Actions caches. When combined with PR-triggered CI and cache sharing, secrets may be exposed to pull requests; a short-term fix limits preserved variables, and longer-term improvements are planned. The article advises checks on workflows, possible mitigations like disabling cache or scoping secrets, and rotating any potentially leaked secrets.