| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
If you discover a security vulnerability in sushi, please report it privately:
- Do not open a public issue
- Open a private security advisory at
github.com/beamivalice/sushi/security/advisories/new with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
For anything that is not a vulnerability, use GitHub issues.
sushi is designed as a local inference server running on a single machine. It is not designed for production deployment or untrusted network exposure.
- Off by default. With no key set, every request is served.
--api-key <token>(or--api-key-env <VAR>, which keeps the key out of the process table) requires the key on every request from another machine:Authorization: Bearer,x-api-key, HTTP Basic (key = password) or?api_key=.GET /healthand CORS preflight stay open.- Loopback requests are trusted unless
--api-key-strictis also given.
- The default bind is
127.0.0.1:12345(this Mac only).--host 0.0.0.0opens the server to the network; set--api-keyif you do. A port already in use is refused at startup, never shared. - Only load models from trusted sources
- Do not run the server as root