Bazel uploads locally produced action results unless told otherwise. A developer machine whose builds are not fully hermetic can therefore publish a result that every other machine replays - the same shape of problem as CVE-2025-36852, arriving through a default rather than an attack.
Generated Bazel setup now ships read-only for everyone and opts trusted CI back in per invocation, and onboarding issues a read-only token instead of one read/write token for everybody. The flag is guidance; the token scope is the boundary Cachely enforces.