Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.105.0-rc.1Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.105.0-rc.1/cosign.pub \
ghcr.io/berriai/litellm:v1.105.0-rc.1Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- feat(mcp): add Microsoft 365 (Graph) server to the MCP catalog by @devin-ai-integration[bot] in #43099
- chore(cost-map): add azure_ai deprecation dates from the Azure retired models page by @berriai-litellm-provider-info-sync[bot] in #44142
- fix(daily_activity): keep NULL entity ids when excluding entity ids by @devin-ai-integration[bot] in #44139
- fix(proxy): reject non-canonical daily activity dates by @devin-ai-integration[bot] in #44143
- fix(proxy): always exit when database setup fails at boot by @devin-ai-integration[bot] in #44141
- feat(tracing): add scoped SQL queries and schema-aware help by @yujonglee-berri in #44085
- fix(guardrails): straiker v3 routes sk_agt_ keys to v3 and fails closed on a missing verdict by @PhimmStraiker in #44011
- test(integration): move legacy proxy, router and Redis tests into tests/integration by @yuneng-berri in #44128
- chore(cost-map): take azure_ai claude-sonnet-4-5 retirement date from the Azure schedule by @berriai-litellm-provider-info-sync[bot] in #44145
- fix(azure_storage): keep client call ids from sharing one Data Lake file by @devin-ai-integration[bot] in #44099
- fix(guardrails): restore Azure guardrail get_user_prompt dispatch and allow logging by @devin-ai-integration[bot] in #44067
- fix(proxy): keep tool payloads and logprobs unmasked in stored spend logs by @devin-ai-integration[bot] in #44075
- test(e2e): move live-provider legacy tests into tests/e2e by @yuneng-berri in #44120
- chore(harness): remove banner comments, restating comments and dead in_loop_thread by @devin-ai-integration[bot] in #44161
- test(straiker): assert a saved api_version v1 with an sk_agt_ key routes to v3 by @devin-ai-integration[bot] in #44153
- refactor(types): replace Any with proven types in 7 files by @devin-ai-integration[bot] in #43844
- chore(release): backport #44066 to rc/1.105.0 by @yuneng-berri in #44215
- fix(proxy-extras): backport #44203 to rc/1.105.0 by @devin-ai-integration[bot] in #44220
- fix(ui): leave unset callback select params out of the save payload (backport #44213 to rc/1.105.0) by @devin-ai-integration[bot] in #44223
- chore: bump litellm-proxy-extras 0.4.104 -> 0.4.105 by @devin-ai-integration[bot] in #44235
- fix(ui): shrink the sidebar logo so it stops outweighing page titles (backport #44247 to rc/1.105.0) by @yuneng-berri in #44251
- test: repair stale and polluting tests red on scheduled main CI (#44229) [rc/1.105.0] by @yuneng-berri in #44254
- test(integration): opt the config pass-through spend-log case into auth (rc/1.105.0 backport of #44265) by @yuneng-berri in #44269
- test: fix three order-dependent and timing-flaky tests (rc/1.105.0 backport of #44271) by @yuneng-berri in #44281
- fix(proxy-extras): retry P3009 when a peer already recovered the named migration row (rc/1.105.0 backport of #44283) by @yuneng-berri in #44308
- fix(bedrock): backport #44307 to rc/1.105.0 by @mateo-berri in #44317
- fix(otel): tolerate non-dict callback_settings.otel and ignore bare EXCLUDED_SERVICES env (backport #44086 to rc/1.105.0) by @devin-ai-integration[bot] in #44241
- chore(ui): rebuild the Admin UI bundle on rc/1.105.0 by @yuneng-berri in #44386
Full Changelog: v1.105.0-dev.2...v1.105.0-rc.1