mirror of
https://github.com/mudler/LocalAI.git
synced 2026-09-29 09:35:02 -04:00
Code scanning flagged seven issues in the new backend: - G115 text.go: tool-call indexes and tokenize lengths come from the upstream server as int and were cast straight to int32. Add clampInt32 so an absurd upstream value saturates instead of wrapping. - G115 live.go: the int16 -> uint16 cast in PCM16 encoding is a deliberate two's-complement reinterpretation of an already clamped sample; mark it with #nosec and say so. - G304 proxy.go, media.go, client.go: api_key_file comes from the model config, and the media input and output paths are files core staged or chose for the call. None are caller-supplied. Clean the paths and add #nosec with that reason, as core/gallery and the sound classification endpoint already do. - G306 media.go: write generated media 0o600. Core runs as the same user and serves the file itself. gosec reports 0 issues for backend/go/localai-proxy and core/services/failover. The G104 once reported for failover/prober.go is no longer present. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Ettore Di Giacinto <mudler@localai.io>