Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.105.0-dev.2Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.105.0-dev.2/cosign.pub \
ghcr.io/berriai/litellm:v1.105.0-dev.2Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- fix(router): carry per-request routing reads on context variables instead of public method kwargs by @devin-ai-integration[bot] in #43814
- fix(bedrock): add beta header for output config in message by @shrey-berri in #43778
- refactor: clean up fresh tech debt from 2026-09-29 by @devin-ai-integration[bot] in #43830
- test(router): settle the shared logging worker before recording shadow callbacks by @devin-ai-integration[bot] in #43847
- chore(model_prices): add Gemini Veo, Mistral and Azure Claude 4.5 deprecation dates by @devin-ai-integration[bot] in #43857
- fix(cost_calculator): bill ultrafast prompts above 272k at the ultrafast long-context rates by @devin-ai-integration[bot] in #43764
- refactor(rust): centralize Python bridge execution wrappers by @devin-ai-integration[bot] in #43871
- chore(cost-map): add openai gpt-image-2.5 batch prices from the pricing page by @berriai-litellm-provider-info-sync[bot] in #43869
- chore(cost-map): add fireworks priority prices for ember-1, nemotron and glm 5.3 us rows by @berriai-litellm-provider-info-sync[bot] in #43811
- fix(proxy): attribute completed batch cost rows to /batches in daily activity by @devin-ai-integration[bot] in #43870
- fix(router): strip encrypted reasoning the pinned deployment cannot decrypt by @devin-ai-integration[bot] in #43781
- fix(cost_calculator): stop copying optional_params into response hidden params by @yucheng-berri in #43637
- feat(pricing): add vertex_ai gemini-3.8 flash tts rows by @berriai-litellm-provider-info-sync[bot] in #43876
- fix(proxy): keep request-body credentials out of stored spend-log requests by @yucheng-berri in #43635
- fix(ui): right-align money and count columns across tables by @ryan-crabbe-berri in #37889
- feat(agents): enforce authoritative agent permissions by @joshua-berri in #43721
- fix(proxy): strip caller credentials from websocket passthrough by @devin-ai-integration[bot] in #43855
- fix(ui): render access group MCP and agent selections as wrapping chips by @devin-ai-integration[bot] in #41228
- fix(responses): scan and mask top-level instructions with guardrails by @devin-ai-integration[bot] in #43629
- feat(traces): add Rust storage foundation by @yujonglee-berri in #43819
- feat(ui): agent traces tab on logs with timeline and otel setup guide by @ishaan-berri in #43891
- feat(otel v2): excluded_services opt-out for datastore spans on tenant destinations by @devin-ai-integration[bot] in #43278
- fix(traces): correct ClickHouse rollup partitioning, dedupe keys, and retention changes by @devin-ai-integration[bot] in #43901
- fix(bedrock): keep applicable beta headers by @shrey-berri in #43829
- feat(agents): authenticate Entra identities and delegated requests by @joshua-berri in #43722
- fix(hosted_vllm): keep reasoning_content on replayed assistant messages by @devin-ai-integration[bot] in #43599
- fix(proxy): delete large teams without per-member transaction fan-out by @devin-ai-integration[bot] in #42998
- feat(tracing): port OTLP ingestion to current trace foundation by @yujonglee-berri in #43915
- feat(proxy): add native ROI calculator for gateway spend vs merged PRs by @devin-ai-integration[bot] in #43669
- test(e2e): repair completion, SAIL, and spend-log fixtures by @yuneng-berri in #43902
- test(s3_v2): pin async 5xx retry through the production AsyncHTTPHandler by @devin-ai-integration[bot] in #43080
- feat(ui): adopt the new LiteLLM logo and monogram by @yuneng-berri in #43913
- fix(proxy): relay Azure passthrough body model groups through the router by @devin-ai-integration[bot] in #43896
- fix(proxy): register a UI-configured arize callback next to otel under OTel v2 by @devin-ai-integration[bot] in #43906
- fix(transcription): honor base_url alias for Groq Whisper and report it as the api base by @devin-ai-integration[bot] in #43917
- feat(tracing): store spend in ClickHouse automatically by @yujonglee-berri in #43928
- fix(packaging): keep wheel paths under Windows MAX_PATH for Store Python by @ryan-crabbe-berri in #43903
- feat(agents): add identity registration and dashboard controls by @joshua-berri in #43723
- refactor(proxy): answer every team access check with TeamAccess.allows by @ryan-crabbe-berri in #43364
- test(bedrock): restore the AWS env after a failed live call in the auth tests by @devin-ai-integration[bot] in #43921
- feat(lens): analyze agent activity with a separate worker by @moe-berri in #43889
- fix(router): bill service tiers at catalog rates for custom-priced deployments by @devin-ai-integration[bot] in #43890
- test(ci): refresh qualified retired OpenAI fixtures by @yuneng-berri in #43938
- fix(anthropic): forward the dangerous-tool-use beta to Azure AI Foundry by @devin-ai-integration[bot] in #43934
- test(proxy): scope user_api_key_auth overrides in proxy_server tests by @yuneng-berri in #43952
- fix(wandb): set supports_vision true on GLM-5.3-Flash by @berriai-litellm-provider-info-sync[bot] in #43951
- chore(cost-map): sync openrouter prices from the models API by @berriai-litellm-provider-info-sync[bot] in #43950
- fix(grayswan): send request conversation and tool calls to post-call monitor by @devin-ai-integration[bot] in #43770
- fix(azure_storage): name Data Lake objects without base64 padding or slashes by @devin-ai-integration[bot] in #43914
- fix(guardrails): treat an unknown straiker api_version as unset instead of skipping the guardrail by @devin-ai-integration[bot] in #43956
- chore(deps): bump gitpython and tornado, extend diskcache osv ignore to Nov 1 by @yuneng-berri in #43961
- fix(azure_storage): keep the DataLakeServiceClient alive until its TTL elapses by @devin-ai-integration[bot] in #43082
- feat(proxy): record in spend logs whether a request used a client-forwarded Anthropic OAuth token by @devin-ai-integration[bot] in #43063
- test(ci): repair stale tests and move retired OpenAI text-completion fixtures by @yuneng-berri in #43958
- feat(e2e): record each e2e test's steps, starting with ProxyClient by @ryan-crabbe-berri in #42393
- feat(providers): add Cortecs as an OpenAI-compatible provider by @devin-ai-integration[bot] in #43872
- feat(ui): filter tags by name and description on the Tag Management page by @galovics in #42949
- fix(caching): write the response-cache SET to Redis at once instead of on the post-call batch by @devin-ai-integration[bot] in #43973
- test(e2e): typed per-test metadata for the e2e suite by @ryan-crabbe-berri in #42044
- feat(guardrails): honor litellm_params.timeout in every HTTP guardrail by @devin-ai-integration[bot] in #43134
- chore(cost-map): add fireworks inkling priority prices from the prices api by @berriai-litellm-provider-info-sync[bot] in #43949
- chore(cost-map): add deprecation date for anthropic claude-sonnet-4-5 by @berriai-litellm-provider-info-sync[bot] in #43898
- fix(cost-map): raise baseten DeepSeek-V4.1-Flash max output to 262144 by @berriai-litellm-provider-info-sync[bot] in #43916
- fix(proxy): restore pre-config-wins handling of pass-through endpoints by @yuneng-berri in #43962
- feat(lens): investigate sampled traces and retain batch results by @moe-berri in #43942
- fix(guardrails): scan Responses API input in Azure Prompt Shield by @devin-ai-integration[bot] in #43786
- fix(guardrails): scan Responses API input in Azure Text Moderation by @devin-ai-integration[bot] in #43965
- refactor: clean up fresh tech debt from 2026-09-30 by @devin-ai-integration[bot] in #43993
- test: inject the HIBP client and the MCP loop clock so two backend tests stop flaking by @devin-ai-integration[bot] in #44007
- fix(cost-map): reprice fireworks deepseek v4.1 flash to the 2026-10-01 pricing update by @berriai-litellm-provider-info-sync[bot] in #44024
- test(anthropic): native /v1/messages reasoning integration tests built on a captured Claude Code request by @devin-ai-integration[bot] in #43361
- fix(bedrock): add beta header for thinking display updates by @shrey-berri in #43832
- fix(proxy): preserve decision request bodies under token limits by @shrey-berri in #43920
- test(proxy): migrate DB and Redis backed proxy tests into tests/integration by @devin-ai-integration[bot] in #43996
- feat(lens): track worker spend through virtual keys by @moe-berri in #43989
- test(proxy): move auth, hooks, policy_engine and client tests into tests/unit/proxy by @devin-ai-integration[bot] in #43998
- fix(ui): give model leaderboard a distinct trophy icon by @moe-berri in #44036
- test(ci): repair stale tests and flaky CI infrastructure by @yuneng-berri in #43983
- test(proxy): move management_endpoints, management_helpers and guardrails tests into tests/unit/proxy by @devin-ai-integration[bot] in #44003
- feat(ui): agent traces open in a side drawer with a chat-style run view by @ishaan-berri in #43972
- feat(s3_v2): add s3_partition_granularity option for hourly S3 folders by @devin-ai-integration[bot] in #43748
- refactor(lens)!: rename internal engine code and API by @moe-berri in #44034
- test(proxy): move utils, agent_endpoints and endpoint tests into tests/unit/proxy by @devin-ai-integration[bot] in #44006
- test(proxy): move proxy_server, _experimental and db tests into tests/unit/proxy by @devin-ai-integration[bot] in #44012
- test(proxy): move middleware, spend_tracking, pass_through, common_utils and root proxy tests into tests/unit/proxy by @devin-ai-integration[bot] in #44015
- test(proxy): delete the legacy proxy test tree and shard tests/unit/proxy by glob by @devin-ai-integration[bot] in #44018
- chore(deps): bump pypdf from 6.16.2 to 6.19.0 by @dependabot[bot] in #44033
- chore(deps): drop unused pytest-postgresql dev dependency by @yuneng-berri in #44056
- docs(proxy): point mcp_server test references at tests/unit/proxy by @yuneng-berri in #44055
- feat(ui): show daily token totals on the model leaderboard by @ishaan-berri in #44044
- chore(lint): remove the LIT002 mutable-construction rule by @yuneng-berri in #43971
- feat(vertex-ai): add vertex_ai/xai/grok-4.7 pricing by @berriai-litellm-provider-info-sync[bot] in #44059
- feat(ui): drop the Beta badge from the Cost Optimization nav item by @devin-ai-integration[bot] in #43967
- test(e2e): bill Sail windows that synchronous calls can still use by @yuneng-berri in #44058
- ci(circleci): test Redis behavior against local Redis and print short tracebacks by @yuneng-berri in #44062
- fix(router): keep silent_model out of embedding provider requests by @devin-ai-integration[bot] in #44064
- fix(cost-map): add perplexity, openrouter, voyage and nebius models and fix registry metadata by @devin-ai-integration[bot] in #43907
- feat(tool-policies): show the user who owns the key that discovered a tool by @devin-ai-integration[bot] in #43892
- feat(proxy): gzip buffered responses for clients that accept it by @tin-berri in #44052
- fix(auto-router): show actual and baseline spend for historical savings by @tin-berri in #44057
- refactor(proxy): inject tracing receiver and access context by @yujonglee-berri in #44035
- feat: improve trace ingestion and trace details by @yujonglee-berri in #43975
- fix(proxy): enforce key/team vector_stores allowlist on /v1/rag/query by @devin-ai-integration[bot] in #43953
- feat(lens): move traces and setup into Lens by @moe-berri in #44068
- test(proxy-extras): run the db push timeout hint test without a database URL by @yuneng-berri in #44073
- fix(proxy-extras): build the SpendLogs indexes in the migration job instead of in migrations by @devin-ai-integration[bot] in #43948
- fix(mcp): resolve team-granted toolsets for non-admin keys and dashboard sessions by @devin-ai-integration[bot] in #43908
- fix(bedrock): accept Converse messages with no content key by @devin-ai-integration[bot] in #43936
- feat: add litellm.agent() to run claude code, codex, opencode and deep agents through the ai gateway by @ishaan-berri in #43885
- feat(ui): add test trace, tracing key and otel endpoints to tracing setup by @ishaan-berri in #44090
- feat(proxy): add LITELLM_DISABLE_LAZY_ROUTES to register optional routers at startup by @devin-ai-integration[bot] in #43911
- test(e2e): keep 1ms-timeout deployments off the provider cache by @yuneng-berri in #44082
- refactor(repositories): daily activity repository with centralized bounded usage queries by @devin-ai-integration[bot] in #43398
- fix(bedrock): add beta for mid-conversation tool changes by @shrey-berri in #43833
- feat(proxy): bounded daily activity routes (aggregated, search, model_top_keys, export, cache_leakage_keys) for all usage entities by @devin-ai-integration[bot] in #43408
- feat(ui): usage pages consume bounded daily activity routes instead of storing all keys client-side by @devin-ai-integration[bot] in #43409
- build(docker): drop the no-op PROXY_EXTRAS_SOURCE switch from the non-root image by @yuneng-berri in #44097
- fix(proxy): persist SSO display name as user_alias on login by @devin-ai-integration[bot] in #44065
- fix(cost-map): restore later azure Models API retirement dates and date gpt-6.1-sol by @berriai-litellm-provider-info-sync[bot] in #44072
- feat(lens): simplify setup and investigation workflow by @moe-berri in #44089
- chore(cost-map): sync openrouter prices from the models API by @berriai-litellm-provider-info-sync[bot] in #44105
- fix(providers): keep thinking display updates beta by @shrey-berri in #43969
- feat(rust): embed migration folders with a shared migrate! macro by @devin-ai-integration[bot] in #44104
- refactor(tracing): normalize agent spans in Rust by @yujonglee-berri in #44071
- perf(traces): recalculate ClickHouse TTL info only on retention changes by @devin-ai-integration[bot] in #44117
- fix(proxy-extras): bound the lock waits of the partitioned SpendLogs index build by @devin-ai-integration[bot] in #44109
- build(deps): bump oauthlib to 4.0.0 to clear osv-scan by @devin-ai-integration[bot] in #43899
- fix(ui): label lens trace services as agents by @ishaan-berri in #44116
- fix(ui): split the KeyActivityPanel condition chains to bring the lint budget back under its ceiling by @devin-ai-integration[bot] in #44114
- chore: bump litellm-enterprise 0.1.72 -> 0.1.73, litellm-proxy-extras 0.4.103 -> 0.4.104 by @yuneng-berri in #44126
New Contributors
Full Changelog: v1.105.0-dev.1...v1.105.0-dev.2