github MakazhanAlpamys/Soup v0.10.10
v0.10.10 — Security Hardening

latest releases: v0.75.2, v0.75.1, v0.75.0...
6 months ago

What's New

Security hardening across all HTTP-facing components.

Web UI (soup ui)

  • Bearer token auth on all mutating endpoints (POST/DELETE) — token printed at startup
  • CORS restricted to served origin (no more wildcard *)
  • Path traversal protection on /api/data/inspect — sandboxed to working directory
  • Config validation before writing to disk and spawning training
  • Removed user-controlled config_path from train API (fixed temp path)

Inference Server (soup serve)

  • max_tokens capped at 16,384 per request (prevents resource exhaustion)
  • Generic error messages in HTTP responses (no stack traces or internal details)

Data Generation (soup data generate)

  • SSRF protection — --api-base blocks non-HTTPS for remote URLs (HTTP allowed for localhost)
  • --api-key deprecated — use OPENAI_API_KEY env var instead
  • API error responses no longer echo response body (prevents potential key leak)

Export (soup export)

  • llama.cpp cloned from pinned tag b5270 (not HEAD) for supply-chain safety

Other

  • soup push --token deprecated — use HF_TOKEN env var instead
  • Warning printed before executing custom .py reward files (arbitrary code awareness)
  • All 666 tests pass (40 UI tests updated with auth headers)

Install / Upgrade

pip install --upgrade soup-cli

Full Changelog

v0.10.9...v0.10.10

Don't miss a new Soup release

NewReleases is sending notifications on new releases.