Report: security@synapselayer.org · Response: 48h
Do NOT open public issues for security vulnerabilities.
synapse-layer >= 1.2.0
Applies to all repositories under github.com/SynapseLayer:
- synapse-layer
- synapse-layer-skill
- skills
- registry / servers (MCP mirrors)
- Zero hardcoded secrets (CI
secret-scan.ymlon every push/PR) - Header-first auth (
x-connect-token) - AES-256-GCM encryption at rest
- PII redaction pipeline