Cache
Restored archives are checked against content fingerprints before extraction. The BoringCache Action fails closed on server-signature verification by default. Unused cache remains reclaimable under the workspace's cache policy.
Security
Give each job access to the workspace and product it needs. Separate consumption from publication and preserve the integrity checks for each kind of build data.
Restored archives are checked against content fingerprints before extraction. The BoringCache Action fails closed on server-signature verification by default. Unused cache remains reclaimable under the workspace's cache policy.
Each ready Artifact is an immutable stored representation with an expected SHA-256 checksum and explicit retention. BoringCache records when the object store also confirms that representation checksum. Artifacts are never reclaimed as cache.
Registry uploads are streamed through exact SHA-256 verification before promotion to immutable OCI digest keys. Repository authorization is checked before a manifest or blob is returned, even when its digest is known.
Cache can require a Sigstore attestation from a GitHub publisher selected by your pinned policy before restoring Archive, Archive Graph, or OCI content. Remote compiler and GitHub Actions-compatible entries cannot satisfy that policy yet. Artifact receipts record BoringCache publication, while producer attestations require separate verification. Registry exposes digest-addressed images and OCI referrers; image pulls do not enforce a signer policy.
See the trust checks for each product →Cache and Artifacts can use managed storage or your own S3-compatible bucket or Azure Blob container on Custom. With BYOC, you control storage credentials, encryption, access policy, and lifecycle while BoringCache retains the metadata needed to authorize and locate objects.
Registry storage is currently managed by BoringCache. It does not use the workspace's BYOC destination.
Read the storage setup →CLI releases publish checksums and a signed checksum bundle. The Action can be pinned to an immutable commit. Managed BuildKit images are signed by digest and published with provenance and SBOM attestations.
Email security@boringcache.com or use private vulnerability reporting in the affected public repository. Include the affected product, version or page, expected impact, and enough reproduction detail for us to investigate.
Do not include live credentials, customer data, or secrets. Test only with accounts, workspaces, and data you control. Do not degrade service, access another customer's data, use social engineering, or run high-volume automated scans. These reporting instructions do not authorize disruptive testing.
Please validate findings before sending them. Scanner output without a reproducible security impact may not receive a response.
We use cookies to understand how people use BoringCache. Learn more