Habr•August 29, 2026•🇷🇺Translated from Russian

redb 3.7.2 Released with Custom gRPC Protocol, Dependency Vulnerability Fixes and .NET 10 Migration

The redb ecosystem published three consecutive releases—3.7.0, 3.7.1 and 3.7.2—within three days after version 3.7.0 was withdrawn from nuget.org. The withdrawn build targeted .NET 9 and carried high-severity vulnerabilities in its published artifacts.

NuGet audit only surfaced the problems during a full rebuild; incremental builds had masked the issues. Affected packages included SSH.NET 2025.1.0 (GHSA-q939-rpr3-3284) in redb.Route.Sftp, transitive SSH.NET 2024.2.0 via Testcontainers 4.3.0, SQLitePCLRaw.lib.e_sqlite3 2.1.10 through Microsoft.Data.Sqlite 9.0.3, System.Security.Cryptography.Xml 9.0.4 from Microsoft.AspNetCore.DataProtection 9.0.4, and Microsoft.Bcl.Memory 9.0.0 via OpenIddict.Abstractions.

All libraries were updated and the entire stack migrated to .NET 10. redb.Tsak and redb.Identity now declare the same multi-targeting matrix (net8.0;net9.0;net10.0) already used by redb.Core and redb.Route. Host applications and container images are pinned to net10.0.

redb.Route: native gRPC wire protocol

The largest change replaces the previous Grpc.AspNetCore dependency with a custom GrpcWire implementation. Each gRPC method address is now registered as an independent route on the shared Kestrel instance already serving HTTP, AS2 and SOAP traffic. The wire format implements length-prefixed framing, grpc-status and grpc-message trailers, and grpc-timeout deadlines.

Applications can now expose typed .proto services without server stubs, stream in both directions via IAsyncEnumerable, enforce mTLS with certificate pinning, and serve the standard grpc.health.v1.Health/Check endpoint. Interoperability was validated against the Node.js @grpc/grpc-js client in both directions.

Additional redb.Route features

A new redb.Route.Soap connector supports SOAP 1.1/1.2 envelopes, WS-Security, MTOM/XOP and WSDL publication. Control Bus operations (start, stop, suspend, resume, status) are now available via messaging, including an asynchronous notify consumer for route lifecycle events. The Claim Check pattern was completed so that Set/Get operations can safely park message bodies around enrichment steps.

Critical file-transport defects were fixed: readLock=Rename and FileLock no longer return empty payloads, idempotency keys are released on error, and path validation now uses directory-boundary checks to prevent escape via ../ or absolute paths.

Security and compatibility notes

Two behavioral changes were introduced for gRPC producers: ThrowOnError defaults to true and status mapping is enabled by default. Existing behavior can be restored with throwOnError=false or suppressStatusMapping=true. .NET 8 and .NET 9 reach end of support on 10 November 2026; redb.CLI now requires .NET 10.

Related articles

Habr•Supply Chain & Open Source

Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes

The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.

AntiMalware•Supply Chain & Open Source

PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions

Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.

Habr•Supply Chain & Open Source

AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries

Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.

Habr•Supply Chain & Open Source

Sapper Revives Minefield to Deliver Accurate SBOM-Based Vulnerability Impact Reports for Cyber Resilience Act Compliance

Developer Perruer has forked the archived BitBom project Minefield into a new open-source tool called Sapper, fixing critical bugs in dependency graph construction and vulnerability matching. The original Minefield used roaring bitmaps and Tarjan's algorithm to build transitive dependency caches from SBOMs in O(n + m) time, but it incorrectly interpreted SPDX edge directions from protobom 0.6, creating false cycles and massively inflating dependent package counts. Additional fixes addressed SQLite memory database pooling issues, OSV range sorting errors with Go pseudo-versions and ECOSYSTEM ecosystems, and slow OSV ingestion by adding a package name index. Sapper now produces prioritized reports using CISA KEV and EPSS scores, showing exact shortest paths from vulnerable packages to root products while respecting OpenVEX statements. The tool maintains full air-gapped operation and supports CycloneDX 1.3–1.7 and SPDX 2.x formats. These improvements directly help organizations meet the 24-hour notification requirements under the EU Cyber Resilience Act for actively exploited vulnerabilities.