From 246ca859d350abeeff141af2ab99f6a3ed1ca358 Mon Sep 17 00:00:00 2001 From: Ettore Di Giacinto Date: Wed, 30 Sep 2026 18:31:38 +0000 Subject: [PATCH] fix(vllm-cpp): annotate the hf_overrides config.json read for gosec G304 flags reading a path built from a variable. The directory is the model directory from the operator's own model config, not a request input, so it is annotated the way the other backends do it. Assisted-by: Claude Code:claude-sonnet-5-5 Signed-off-by: Ettore Di Giacinto --- backend/go/vllm-cpp/hfoverrides.go | 1 + 1 file changed, 1 insertion(+) diff --git a/backend/go/vllm-cpp/hfoverrides.go b/backend/go/vllm-cpp/hfoverrides.go index 2d7e3abdf..57745c1e6 100644 --- a/backend/go/vllm-cpp/hfoverrides.go +++ b/backend/go/vllm-cpp/hfoverrides.go @@ -50,6 +50,7 @@ func newConfigOverlay(modelDir, overrides string) (dir string, err error) { return "", fmt.Errorf("vllm-cpp: hf_overrides: %w", err) } + // #nosec G304 -- absDir is the model directory from the operator's own model config, never a request-supplied path raw, err := os.ReadFile(filepath.Join(absDir, "config.json")) if err != nil { return "", fmt.Errorf("vllm-cpp: hf_overrides needs %s: %w", filepath.Join(absDir, "config.json"), err)