← All changes
Cache

Bazel defaults to read-only developers

Bazel uploads locally produced action results unless told otherwise. A developer machine whose builds are not fully hermetic can therefore publish a result that every other machine replays - the same shape of problem as CVE-2025-36852, arriving through a default rather than an attack.

Generated Bazel setup now ships read-only for everyone and opts trusted CI back in per invocation, and onboarding issues a read-only token instead of one read/write token for everybody. The flag is guidance; the token scope is the boundary Cachely enforces.

Put a shared build cache behind your builds
Free tier, no credit card - connect Nx, Turborepo, Gradle, or Bazel in about five minutes.
Start freeSee pricing