Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.104.0-rc.1Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.104.0-rc.1/cosign.pub \
ghcr.io/berriai/litellm:v1.104.0-rc.1Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- test(e2e): cover Azure code_interpreter container files by native id with a service-account key by @devin-ai-integration[bot] in #43122
- fix(router): await budget redis pipeline before sync reads (internal copy of #32618) by @devin-ai-integration[bot] in #43125
- chore(cost-map): add openai cached image input prices from the pricing page by @berriai-litellm-provider-info-sync[bot] in #43143
- feat(langfuse)!: migrate the sdk callback to langfuse v4 by @yucheng-berri in #36741
- fix(key_management): count team unified access group MCP servers when validating key MCP grants by @devin-ai-integration[bot] in #41231
- fix(ui): group cost optimization cache leakage by model group by @devin-ai-integration[bot] in #43008
- fix(presidio): mask streamed /v1/messages output when the first upstream read is a keepalive, a data-less ping, or a split utf8 character by @devin-ai-integration[bot] in #43023
- test: backport stale and state-leaking test fixes to rc/1.104.0 (#43266) by @yuneng-berri in #43267
- chore: backport CI fixes, #43206 and Rust changes to rc/1.104.0 by @yuneng-berri in #43338
- fix(s3_v2): backport #43022 to rc/1.104.0 by @yuneng-berri in #43354
- chore: rebuild Admin UI bundle for rc/1.104.0 by @yuneng-berri in #43372
- chore: backport CircleCI speedups (#43347) and cost-map fixes (#42951) to rc/1.104.0 by @yuneng-berri in #43366
- revert(usage): remove the top-N key cap, its follow-ups and the daily global spend rollup code from rc/1.104.0 by @yuneng-berri in #43385
- fix(streaming): backport text-completion usage chunk fix (#43047) to rc/1.104.0 by @yuneng-berri in #43402
- test(e2e): report batch cleanup leftovers as a plain UserWarning on rc/1.104.0 by @yuneng-berri in #43406
- test(e2e): skip the LangSmith batch serialization e2e on rc/1.104.0 until CI has a LangSmith key by @yuneng-berri in #43418
- test(unit): stop test modules from putting their own directory on sys.path on rc/1.104.0 by @yuneng-berri in #43420
- fix(proxy): unregister logging callbacks removed from the stored config on rc/1.104.0 by @yuneng-berri in #43432
Full Changelog: v1.104.0-dev.2...v1.104.0-rc.1