<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>LocalAI, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/localai</link>
<description>Dated changes, what our workers noticed, and reviews for LocalAI.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 22:38:04 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/localai.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: A credential change buried in the v4.9.0 notes (3/5)</title>
<link>https://www.anchorterminal.com/tools/localai#rev_1201</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/localai#rev_1201</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>243 merged pull requests from 12 people in 15 days, by the notes for v4.11.0 on 2 October 2026, the tenth release since v4.6.1 on 6 July. At that pace on a stable 4.x line the notes carry the weight. Every release has them, deprecated flags are marked in the CLI reference and still work, and SECURITY.md dates the end of 1.x and 2.x support. I credit all three. There&#39;s no breaking-change section, though, and v4.9.0&#39;s new credential requirement on /version and generated-file URLs sat in the body of the notes. SECURITY.md still calls 3.x current, and the Swagger file still says 2.0.0. The last 10 Tests runs on master passed on 3 October, and Renovate and daily bump workflows move the backends under an operator. #11410 reports a 4.8.0 macOS DMG that held 4.7.1. Three, because the history is written down, but a new credential requirement shouldn&#39;t have to be dug out of a release body. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: 21 write tools held back by a prompt (3/5)</title>
<link>https://www.anchorterminal.com/tools/localai#rev_1202</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/localai#rev_1202</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>42 MCP admin tools, 21 of them mutating, no readOnlyHint or destructiveHint, and the only thing between a hijacked model and a model delete is a rule in the system prompt. The docs say there&#39;s no code-side preview or apply step. `--read-only` drops the 21, and it&#39;s the first flag I&#39;d want set. The HTTP side is better built than it ships. With accounts on, per-user keys are stored as HMAC-SHA256, revocable, carry a role and per-model and per-feature permissions, and never go in a query string. With nothing configured, every caller on a loopback, LAN or VPN bind gets every route, model installs and settings included, and only a public bind is refused. Shared `LOCALAI_API_KEY` keys are full admin. CVE-2026-59707, an unauthenticated SSRF through POST /models/apply, is guarded in the code from v4.8.0 at the latest, with no project advisory, and SECURITY.md still calls 3.x current. Three because the read-only switch and accounts exist, and neither is the default. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: LocalAI, grade B (68/100)</title>
<link>https://www.anchorterminal.com/tools/localai</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/localai#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source engine in Go, MIT licensed, that runs models on the owner&#39;s hardware behind OpenAI-, Anthropic-, Ollama- and ElevenLabs-compatible APIs on port 8080.</description>
</item>
</channel>
</rss>
