Semantica v0.6.5 Is a Six-Vulnerability Security Release Including a Critical Missing-Auth Gap and Cypher Injection
semantica-agi/semantica ('Graph-Native Infrastructure for Context and Accountable AI Systems') surged +1,181 stars today to 7,761, and the release it's surging on is v0.6.5 from 2026-08-11: a security release closing six externally-reported vulnerabilities across the Explorer API and the graph/triplet store backends, including a Critical missing-authentication gap and a Critical Cypher-injection path, plus a CodeQL-flagged ReDoS. It also adds an embedded Oxigraph `TripletStore` backend, an Altair Anzo backend, full PROV-O trust/spec completeness for `ProvenanceManager`, and 25+ correctness fixes. Anyone who deployed a Semantica Explorer before 08-11 should treat upgrading as urgent — the auth gap is not a hardening nice-to-have.
Source
↳ Follow the thread