Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.106.0-dev.2Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.106.0-dev.2/cosign.pub \
ghcr.io/berriai/litellm:v1.106.0-dev.2Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- refactor: expose public hidden_params accessors by @devin-ai-integration[bot] in #44668
- fix(azure): date claude-opus-5-5 and sonnet-5-5 and fill azure/eu/gpt-6-astra limits by @berriai-litellm-provider-info-sync[bot] in #45018
- refactor: remove fresh tech debt from the 2026-10-06 window by @devin-ai-integration[bot] in #45017
- ci: give the database-backed CircleCI jobs their own Postgres by @devin-ai-integration[bot] in #45007
- test(proxy): make the stagger-offset and linear-dedup guards independent of runner identity and load by @devin-ai-integration[bot] in #45031
- refactor(types): replace Any with proven types in 16 files by @devin-ai-integration[bot] in #45029
- fix(auth): clear the recent-miss user memo when /user/new creates the user by @devin-ai-integration[bot] in #45020
- fix(health): attribute background health check results to their own deployment by @devin-ai-integration[bot] in #44982
- fix(ollama): turn streamed prompt-based JSON tool calls into real tool calls by @devin-ai-integration[bot] in #45053
- fix(bedrock): update GovCloud OpenAI prices, add GPT-6 Astra ultrafast tier and Titan Image v2 EOL by @berriai-litellm-provider-info-sync[bot] in #45077
- fix(cost-map): add us data residency multiplier to anthropic claude-opus-5-5 by @berriai-litellm-provider-info-sync[bot] in #45078
- refactor(llms): expose public names for private provider helpers by @devin-ai-integration[bot] in #45037
- fix(bedrock): add 2027-03-30 deprecation date to DeepSeek R1 and Qwen3 Coder rows by @berriai-litellm-provider-info-sync[bot] in #45089
- fix(proxy): opt-in Redis hash-tag grouping for v3 rate limiter by @devin-ai-integration[bot] in #45085
- fix(bedrock): take context and output limits from the Bedrock model cards by @berriai-litellm-provider-info-sync[bot] in #45091
- fix(tests): match the lowercased bind error in the owned-proxy port-race retry by @devin-ai-integration[bot] in #45097
- test(e2e): tag llm_translation tests with Subject metadata and record harness steps by @ryan-crabbe-berri in #44950
- test(e2e): tag claude_code cells with Subject metadata and record CLI driver steps by @ryan-crabbe-berri in #44961
- test(e2e): tag management tests with Subject metadata and record management client steps by @ryan-crabbe-berri in #44962
- test(e2e): tag guardrails and logging tests with Subject metadata and record client steps by @ryan-crabbe-berri in #44963
- fix(caching): skip the cache past max_messages and keep tool_result text in semantic prompts by @devin-ai-integration[bot] in #43878
- test(e2e): tag router, batches and mcp tests with Subject metadata and record client steps by @ryan-crabbe-berri in #44964
- test(e2e): tag the remaining quota_management tests and record budget and spend client steps by @ryan-crabbe-berri in #44966
- fix(router): preserve native baseline identity and accounting by @tin-berri in #44960
- test(integration): scope the team-scoped models upstream check to its own model by @devin-ai-integration[bot] in #45106
- fix(prometheus): add model_group label to end-to-end latency metrics by @ahamedshaik16 in #44860
- test(mcp): fix stale bridge-hook, applied-guardrails and pagination-revoke integration tests by @devin-ai-integration[bot] in #45008
- test(observability): wait for warm-up spend rows in capped and count only the post-wipe half in X4 by @devin-ai-integration[bot] in #45006
- fix(cost-map): lower anthropic claude-sonnet-5-5 cache read price by @berriai-litellm-provider-info-sync[bot] in #45113
- fix(prompt-caching): default injected /v1/messages breakpoints to implicit lookup by @ryan-crabbe-berri in #45121
- test(integration): turn the model-info refresh off in every integration proxy config by @devin-ai-integration[bot] in #45104
- test(e2e): let the realtime send step accept input audio buffer frames by @ryan-crabbe-berri in #45127
- feat(model_prices): add claude-haiku-5-5 model pricing by @krrish-berri-2 in #45108
- fix(realtime): run transcript guardrails on raw-path transcription sessions with a transcription-safe block by @devin-ai-integration[bot] in #44844
- test(integration): hold the wire barrier until the test releases it or the wire closes by @devin-ai-integration[bot] in #45124
- fix(vertex-ai): correct claude-haiku-5-5 thinking and forced tool flags by @berriai-litellm-provider-info-sync[bot] in #45116
- feat(helm): allow custom labels, annotations, command and args on migrationJob by @ankitasahni511 in #42242
- test(e2e): tag a2a, access_control, other, secret_manager and migrations tests with Subject metadata by @ryan-crabbe-berri in #44965
- fix(azure): correct azure_ai/claude-haiku-5-5 forced tool use and thinking flags by @berriai-litellm-provider-info-sync[bot] in #45114
- perf(lens): claim worker jobs from an indexed due queue instead of scanning every lens by @devin-ai-integration[bot] in #45095
- perf(lens): prune ClickHouse partitions when sampling and sample in one pass by @devin-ai-integration[bot] in #45087
- fix(logging): bound data URI regex so base64 truncation stays linear by @devin-ai-integration[bot] in #45132
- perf(lens): bound single trace reads by the sampled start time by @devin-ai-integration[bot] in #45088
- feat(lens-ui): show findings ranked by priority with frequency and highlighted evidence by @ishaan-berri in #45143
- fix(ollama): answer in text after a tool result and cover ollama e2e on all three endpoints by @devin-ai-integration[bot] in #45079
- fix(openai-compat): send provider attribution headers on the default SDK path (+ Perplexity) by @ryan-crabbe-berri in #44291
- ci(codeql): run the default suite on full scans and security-extended on PRs by @devin-ai-integration[bot] in #45149
- feat(lens): flag traces with global System 1 signals by @devin-ai-integration[bot] in #45094
- feat(ui): configure Anthropic workload identity federation from the dashboard by @devin-ai-integration[bot] in #44889
- feat(guardrails): add logging_only_scope to observe input, output, or both by @devin-ai-integration[bot] in #43695
- test: move the unit half of 126 mixed legacy files into tests/unit by @devin-ai-integration[bot] in #45090
- fix(model_prices): consolidate claude-haiku-5-5 over-100k pricing and capability flags by @devin-ai-integration[bot] in #45151
- feat(ui): add auto-router usage and savings table by @tin-berri in #45152
- refactor(rust-bridge): unify native call inputs and Messages settings by @yujonglee-berri in #45126
- test(e2e): move the harness self-tests out of tests/e2e by @ryan-crabbe-berri in #45172
- test(e2e): record steps for raw transport calls and poll helpers by @ryan-crabbe-berri in #45150
- feat(lens): link traces to the conversation that started them by @ishaan-berri in #45169
- fix(router): resume sync streaming fallbacks without retrying primary by @amarrtech in #43959
- feat(guardrails): extend Akto guardrail to responses, MCP tools, attachments and masking by @rohan-akto in #44343
- fix(streaming): stop re-wrapping a bridged stream's MidStreamFallbackError by @devin-ai-integration[bot] in #44989
- fix(proxy): evict cached user on every proxy for tpm/rpm updates and edit limits in the users UI by @devin-ai-integration[bot] in #44130
- perf(lens): classify signals within seconds of a trace finishing by @ishaan-berri in #45186
- feat(proxy): add denied_passthrough_routes deny list for custom pass-through endpoints by @devin-ai-integration[bot] in #44924
- fix(responses): keep prompt_cache_breakpoint markers in the chat to responses bridge by @devin-ai-integration[bot] in #44119
- fix(mcp): preserve client application type during registration by @joshua-berri in #45159
- feat(mcp): rate limit all MCP operations and add server-level rpm by @devin-ai-integration[bot] in #44600
- fix(ci): align misc unit tests with NativeCall bridge and widened e2e diff gates by @devin-ai-integration[bot] in #45180
- fix(types): serialize deferred pydantic schema builds across threads by @devin-ai-integration[bot] in #45034
- fix(anthropic): normalize images for provider token counting by @tin-berri in #45185
- feat(lens): scope traces to one agent with a header picker by @ishaan-berri in #45202
- chore(codeowners): replace kerry-berri with kerrylu-berri by @devin-ai-integration[bot] in #45173
- test: delete 73 legacy tests covered by e2e, unable to fail, or dead in CI by @devin-ai-integration[bot] in #45195
- feat(lens): isolate ingestion and investigations in a Rust service by @moe-berri in #45148
- fix(mcp): honor scoped cache freshness by @joshua-berri in #45165
- chore(ui): bump next to 16.3.8 by @yuneng-berri in #45207
- refactor(rust-bridge): share field and response marshaling by @yujonglee-berri in #45187
- fix(lens): preserve numeric tags and report OTLP error codes by @moe-berri in #45206
- fix(scheduler): remove a request's queue entry once it stops waiting by @RachelHuangZW in #43061
- fix(vertex_ai): dial the multi-region Live API host for realtime sessions by @mateo-berri in #45166
- feat(proxy,ui): add Moyai to the view switcher with quick connect by @ishaan-berri in #45196
- fix(ci): restore vertex model sets mutated by get_optional_params tests by @devin-ai-integration[bot] in #45209
- feat(decisions): add the OpenAI Decisions spec types and the System One translation by @devin-ai-integration[bot] in #45129
- fix(anthropic): let /v1/messages mid-stream failures reach the proxy failure boundary by @D41910 in #44800
- test: remove dead imports and helpers left behind by legacy test deletion by @devin-ai-integration[bot] in #45208
- fix(vertex-ai): halve claude-sonnet-5-5 cache read price by @berriai-litellm-provider-info-sync[bot] in #45217
- fix(anthropic): fail closed when a token-file or inline-token federation credential is missing a rule or organization id by @mateo-berri in #45178
- fix(bedrock): map Scheduled batch jobs to in_progress on retrieve by @mrinal-berri in #45157
- feat(ui): redesign usage page with stacked model and agent charts by @ishaan-berri in #45221
- fix(bedrock): lower claude sonnet 5.5 cache read price to the aws offer index by @berriai-litellm-provider-info-sync[bot] in #45216
- fix(responses): keep cache breakpoints on blocks the bridge stringifies by @mateo-berri in #40032
- fix(bedrock_mantle): lower claude sonnet 5.5 cache read price to match bedrock runtime by @berriai-litellm-provider-info-sync[bot] in #45223
- fix(ui): address usage redesign review findings by @ishaan-berri in #45229
- perf(lens): faster trace opens and list pages at scale by @ishaan-berri in #45228
- refactor(proxy): expose public names for private proxy helpers by @mateo-berri in #45170
- fix(ollama): one stream id, 400 on non-text tool content, separated tool results, no empty message item by @mateo-berri in #45177
- feat(lens): simplify deployment and first trace setup by @moe-berri in #45230
- fix(proxy): traceparent/baggage fallback must not override caller metadata by @devin-ai-integration[bot] in #43688
- fix(proxy): accept router-wide default_litellm_params in required-param validation by @yucheng-berri in #44483
- fix(proxy): keep idle responses websockets open until a configurable session limit by @devin-ai-integration[bot] in #44433
- fix(lens-ui): open traces on the top-level step and stop showing model names as input by @ishaan-berri in #45254
- refactor(decisions): dispatch /v1/decisions through provider configs and the shared HTTP handler by @devin-ai-integration[bot] in #45130
- feat(lens): show agent, user and slack thread first in the run header by @ishaan-berri in #45261
- fix(proxy): declare the Moyai settings write's service target and allowlist its routes by @devin-ai-integration[bot] in #45220
- feat(lens): show end-user feedback on traces, stored in ClickHouse by @ishaan-berri in #45171
- fix(proxy): admit litellm_proxy/hosted_vllm in provider-endpoint discovery by @mayuriphad in #38617
- feat(decisions): serve System One format at /v1/systemone and OpenAI format at /v1/decisions by @mateo-berri in #45184
- feat(decisions): add OpenAI as a Decisions provider behind a shared decisions format by @mateo-berri in #45214
- feat(lint): add LIT015 requiring pydantic models to be frozen by @devin-ai-integration[bot] in #42348
- fix(router): keep include_fallback_errors off the provider call on the sync Router path by @mateo-berri in #45218
- fix(router): honor a per-request fallbacks list on a mid-stream fallback by @mateo-berri in #45227
- fix(responses): map input_audio blocks in the chat-to-Responses bridge by @mateo-berri in #45224
- fix(proxy): answer a rejected websocket handshake without crashing the HTTP exception handler by @mateo-berri in #45251
- ci(lint): gate every rule on its merge-base count and cap Anys at a fixed total by @devin-ai-integration[bot] in #40193
- test(e2e): cover responses API gaps on gemini, azure, compact and context management by @devin-ai-integration[bot] in #45248
- chore: bump litellm-proxy-extras to 0.4.107 and litellm-enterprise to 0.1.75 by @devin-ai-integration[bot] in #45291
New Contributors
- @ankitasahni511 made their first contribution in #42242
- @amarrtech made their first contribution in #43959
- @rohan-akto made their first contribution in #44343
- @RachelHuangZW made their first contribution in #43061
- @D41910 made their first contribution in #44800
- @mrinal-berri made their first contribution in #45157
- @mayuriphad made their first contribution in #38617
Full Changelog: v1.106.0-dev.1...v1.106.0-dev.2