
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@syncrona/credential-store
Advanced tools
Shared encrypted credential store for SyncroNow AI (core CLI and MCP server).
Shared encrypted credential store for SyncroNow AI. It is the single source of
truth for at-rest credential storage used by both the syncrona CLI and
the @syncrona/mcp-server, so the encryption format, key derivation, file
naming, and on-disk layout never diverge between processes.
~/.syncrona/
config.json # { "activeInstance": "<instance>" }
credentials/<instance>.enc # AES-256-GCM "iv:authTag:ciphertext" (hex)
Async (used by the core CLI, read + write):
saveCredentials(instance, user, password)loadCredentials(instance) — throws if missinglistInstances()removeCredentials(instance) / removeAllCredentials()setActiveInstance(instance) / getActiveInstance()resolveCredentialsFromStore(instance?)getSyncronaDir()Sync (used by the MCP server during secrets resolution; never throw, return
null on any failure):
getActiveInstanceSync()loadCredentialsSync(instance)Low-level primitives are also exported: getStoreKey, getStoreKeySource,
getMachineKey, encrypt, decrypt, instanceToFilename,
filenameToInstance.
The encryption key is resolved by getStoreKey() with the precedence:
SYNCRONA_STORE_KEY — an explicit 32-byte key (64 hex chars or base64),
for CI / secrets managers. Strongest option.@napi-rs/keyring dependency is installed; opt out with
SYNCRONA_USE_KEYCHAIN=0 (e.g. a headless CI box with no keychain). A random
256-bit master key is kept in the OS keychain (macOS Keychain / Windows
Credential Manager / libsecret).@napi-rs/keyring is unavailable (or explicitly disabled).Reads fall back to the machine-derived key so pre-existing files keep
decrypting. getStoreKeySource() reports which path won ("env" /
"keychain" / "machine"). See the core README "Credential storage security"
section for hardening recommendations.
FAQs
Shared encrypted credential store for SyncroNow AI (core CLI and MCP server).
We found that @syncrona/credential-store demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.