Files
LocalAI/backend/go
Ettore Di Giacinto 53ce024efc fix(localai-proxy): clear the gosec findings
Code scanning flagged seven issues in the new backend:

- G115 text.go: tool-call indexes and tokenize lengths come from the
  upstream server as int and were cast straight to int32. Add clampInt32 so
  an absurd upstream value saturates instead of wrapping.
- G115 live.go: the int16 -> uint16 cast in PCM16 encoding is a deliberate
  two's-complement reinterpretation of an already clamped sample; mark it
  with #nosec and say so.
- G304 proxy.go, media.go, client.go: api_key_file comes from the model
  config, and the media input and output paths are files core staged or
  chose for the call. None are caller-supplied. Clean the paths and add
  #nosec with that reason, as core/gallery and the sound classification
  endpoint already do.
- G306 media.go: write generated media 0o600. Core runs as the same user
  and serves the file itself.

gosec reports 0 issues for backend/go/localai-proxy and
core/services/failover. The G104 once reported for failover/prober.go is
no longer present.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>
2026-09-27 07:42:21 +00:00
..