fix(vllm-cpp): annotate the hf_overrides config.json read for gosec

G304 flags reading a path built from a variable. The directory is the model
directory from the operator's own model config, not a request input, so it is
annotated the way the other backends do it.

Assisted-by: Claude Code:claude-sonnet-5-5
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>
This commit is contained in:
Ettore Di Giacinto committed 2026-09-30 18:31:38 +00:00
1 parent b540c3e1fd
commit 246ca859d3
1 file changed
+1
+1
View File
@@ -50,6 +50,7 @@ func newConfigOverlay(modelDir, overrides string) (dir string, err error) {
return "", fmt.Errorf("vllm-cpp: hf_overrides: %w", err)
}
// #nosec G304 -- absDir is the model directory from the operator's own model config, never a request-supplied path
raw, err := os.ReadFile(filepath.Join(absDir, "config.json"))
if err != nil {
return "", fmt.Errorf("vllm-cpp: hf_overrides needs %s: %w", filepath.Join(absDir, "config.json"), err)