Safetensors or to be sure not to load pickled weights #173
Replies: 3 comments
-
@wllhf Thanks for the positive feedback. It inherits the behaviour of "SentenceTransformers", it will automatically filter certain files, and AFAIK not download the jaxformers weights / rustformers etc. Also the default behaviour is Here are 2 security suggestions from a MLE, if the project is a high security one:
|
Beta Was this translation helpful? Give feedback.
-
@wllhf Does this solve the question for you? |
Beta Was this translation helpful? Give feedback.
-
Yes. Thanks! |
Beta Was this translation helpful? Give feedback.
-
I'm really grateful for infinity! Thanks a lot! We are thinking about using it in a project with high security demands. Is it possible somehow to only load models via safetensors (or other safe formats) and exclude loading pickled weights? Is there a way knowing which format was used for loading when starting up a model via Infinity?
Beta Was this translation helpful? Give feedback.
All reactions