semantica-agi/semantica v0.6.5 repo
v0.6.5 security release closing 6 externally-reported vulnerabilities across the Explorer API and graph/triplet store backends, including a Critical missing-authentication gap and a Critical Cypher-injection path, plus a CodeQL-flagged ReDoS. Also adds an embedded Oxigraph TripletStore backend, full PROV-O trust/spec completeness for ProvenanceManager, the Altair Anzo triplet store backend, and closes 25-plus correctness bugs across vector stores, provenance, and ontology validation.
What it does for you: The 2 Critical vulnerabilities in v0.6.4 would expose any Axion or Hermes deployment running the Explorer API to unauthorized access and query manipulation via Cypher injection. Upgrading to v0.6.5 is mandatory before building anything on semantica following yesterday's rank 1 listing. The new Oxigraph embedded backend reduces infrastructure requirements for the graphify integration, removing the need for an external graph store in development and lightweight production environments.
In practice: Security maintenance cadence this fast, 6 CVEs patched one day after first listing, is a strong positive signal: the team is actively reviewing the attack surface. The severity of the Critical findings validates the cautious approach to building on a new repo. The addition of Oxigraph and PROV-O completeness alongside the security fixes shows feature work continuing in parallel with the security response.
For: Both runtimes. Python pip package callable from any Python runtime including Hermes.
Verdict: build now. Critical security release mandatory for anyone building on semantica following yesterday's rank 1 listing. Closes a Critical missing-authentication gap and a Critical Cypher-injection path in the Explorer API and triplet store backends. Also adds the Oxigraph embedded backend and full PROV-O trust/spec, reducing infrastructure requirements for the graphify integration. Security score raised from 3 to 4 based on demonstrated active CVE response.
Build #1 semantica-agi/semantica: use the ai-implementation-build-intake skill to build this safely. Source: https://github.com/semantica-agi/semantica. Save canonical skill/agent under AXION\Skills and AXION\Agents.
Source · v0.6.5 released 2026-08-11. 6 externally-reported CVEs closed: 2 Critical (missing-authentication and Cypher-injection), 1 CodeQL ReDoS, 3 additional issues. 4,022 stars and 479 forks confirmed on 2026-08-11. pip install semantica. MIT license.