Skip to content

Synapse Layer v2.4.3 — Security Remediation

Choose a tag to compare

@SynapseLayer SynapseLayer released this 01 Jul 23:09

Summary

  • Corrective security release publishing the first immutable PyPI artifact with the fixed cryptography dependency floor.

Security

  • Pins cryptography>=48.0.1 to resolve GHSA-537c-gmf6-5ccf, which affects cryptography wheels bundling vulnerable OpenSSL versions below 48.0.1.

Dependency

  • cryptography>=46.0.7cryptography>=48.0.1

Scope

  • Dependency-floor only.
  • No functional changes.
  • No API changes.
  • No MCP tool changes.
  • No runtime behavior changes.
  • No npm package publication.

Validation

  • CI green on commit 94daf1c.
  • Version Gate green.
  • Secret Scan green.
  • OSV confirms cryptography 48.0.1 has zero vulnerabilities for the relevant advisory check.

Marketplace Follow-up

  • After PyPI publishes synapse-layer==2.4.3, update/reimport the Official MCP Registry entry and rescan the MCP Marketplace listing.