Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.106.0-dev.3Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.106.0-dev.3/cosign.pub \
ghcr.io/berriai/litellm:v1.106.0-dev.3Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- test(integration): boot owned proxies with a readiness-sized worker healthcheck budget by @devin-ai-integration[bot] in #45292
- fix(utils): make supports_audio_output read the supports_audio_output cost-map key by @devin-ai-integration[bot] in #45294
- fix(lens): refresh runs until gateway costs are complete by @tin-berri in #45105
- fix(lint-gates): fail on an empty base scan instead of blaming the change for every violation by @devin-ai-integration[bot] in #45314
- refactor(proxy): type fresh Moyai connect helpers and drop MCP rpm getattr by @devin-ai-integration[bot] in #45315
- revert(lint-gates): accept an empty base scan again, since zero violations is a legitimate count by @devin-ai-integration[bot] in #45319
- fix(bedrock_mantle): send OpenAI explicit prompt cache breakpoints for GPT-5.6 and newer by @msdianprince-7 in #38729
- test: make 77 legacy live tests offline in litellm_utils, router_unit and responses dirs by @devin-ai-integration[bot] in #45298
- test: move 81 legacy live tests in pass-through, spend, batches, audio, search, guardrails, image and ocr dirs offline by @devin-ai-integration[bot] in #45288
- feat(ui): add TypeSafe and Strands Decider to the Add Model provider list by @devin-ai-integration[bot] in #45335
- feat(mcp): support upstream OAuth client metadata identities by @joshua-berri in #45231
- fix(proxy-extras): name the database error when the Lens rename check cannot run by @devin-ai-integration[bot] in #45341
- test(integration): run the response cache tool-call tests on a proxy without the message cap by @devin-ai-integration[bot] in #45350
- fix(logging): skip sync success callbacks for internal sub-calls, deflake RAG and Langfuse tests by @devin-ai-integration[bot] in #45345
- fix(azure): move sora-2 retirement date to the later Models API date by @berriai-litellm-provider-info-sync[bot] in #45355
- fix(lens): block teamless feedback writes and fix retention test by @ishaan-berri in #45266
- fix(ci): trim rust-test debuginfo so the job fits on the runner disk by @devin-ai-integration[bot] in #45318
- fix(ui): list only catalog models in the Add Model picker by @devin-ai-integration[bot] in #44877
- feat(rust): add standalone typed LLM wire contracts by @yujonglee-berri in #45188
- test: delete 34 legacy tests already covered by e2e by @devin-ai-integration[bot] in #45340
- fix(responses): keep tool_result next to tool_use on Anthropic previous_response_id continuations by @mateo-berri in #45322
- test: realign stale decisions and lens tests with merged behaviour by @devin-ai-integration[bot] in #45346
- feat(prometheus): expose per-project per-model rate limit allowed and used gauges by @devin-ai-integration[bot] in #43561
- fix(mcp): preserve elicitation context and report relay failures by @joshua-berri in #45255
- docs(rust): add ADRs for the Rust core by @nate-berri in #45205
- test: move 76 live top-level tests to offline unit and integration coverage by @devin-ai-integration[bot] in #45352
- fix(proxy): mark background responses stale_expired when provider returns 404 by @devin-ai-integration[bot] in #41724
- fix(bedrock): take context, output limits and EOL dates from the Bedrock model cards by @berriai-litellm-provider-info-sync[bot] in #45409
- chore(cost-map): add openai gpt-6.1-sol ultrafast tier prices from the pricing page by @berriai-litellm-provider-info-sync[bot] in #45408
- fix(bedrock_mantle): take gpt-oss output limits and EOL dates from the Bedrock model cards by @berriai-litellm-provider-info-sync[bot] in #45417
- fix(rust): path-qualify attribute aliases so rust-analyzer resolves them by @nate-berri in #45416
- fix(proxy): use budget reset window for projected spend alerts by @Solomon-mithra in #31942
- test(proxy): audit the websocket rejection log on every live route by @mateo-berri in #45293
- fix(proxy): retry lock-timed-out daily spend batches in place so the shutdown flush keeps them by @mateo-berri in #45273
- fix(vertex_ai): forward the inline-tools-2026-09-15 beta to Vertex and Anthropic by @devin-ai-integration[bot] in #45297
- feat(fireworks_ai): forward the LiteLLM user id as user behind fireworks_forward_user_id by @yucheng-berri in #45265
- fix(model_prices): add Bedrock flex prices, Anthropic web search flags, Gemini shutdown dates, OpenRouter alias drift, Mistral Large 4 context by @devin-ai-integration[bot] in #44910
- feat(voyage): rebrand to VoyageAI by MongoDB and route MongoDB keys to ai.mongodb.com by @fzowl in #41812
- feat(gemini): accept file content blocks with video_metadata on multimodal embeddings by @devin-ai-integration[bot] in #45305
- feat(rust): add the Anthropic beta header policy by @yujonglee-berri in #45419
- test(decisions): post System One bodies to /v1/systemone in the translation bases by @yuneng-berri in #45327
- fix(ci): drop the publicly known master key prefix from the voyage routing test by @devin-ai-integration[bot] in #45431
- feat(guardrails): per-mode stream_scope with bedrock stream and pass-through fixes by @devin-ai-integration[bot] in #43801
- refactor(python-bridge): take NativeCall directly and fold routes into per-route folders by @yujonglee-berri in #45413
- fix(lens): prevent progress updates from starving analysis budget reservations by @moe-berri in #45432
- refactor(rust): derive strum VariantArray and string conversions by @yujonglee-berri in #45434
- chore(decisions): remove the System One converters and OpenAI spec types left dead by #45214 by @devin-ai-integration[bot] in #45442
- feat(spend_logs): configure which metadata fields are stored in LiteLLM_SpendLogs by @devin-ai-integration[bot] in #44659
- fix(ui): show the Add Model picker once the model catalog loads after a provider is picked by @yuneng-berri in #45426
- fix(rust): add the inline-tools-2026-09-15 beta to AnthropicBeta by @devin-ai-integration[bot] in #45439
- fix(bedrock): count tokens on bedrock-mantle when bedrock-runtime cannot count a Claude model by @devin-ai-integration[bot] in #45317
- fix(ui): link model access group chips to the access group filter by @devin-ai-integration[bot] in #45402
- fix(proxy): accept team-scoped models by their public name on POST /fallback by @devin-ai-integration[bot] in #45455
- fix(otel): emit OpenInference tool calls and metadata on Arize OTel v2 spans by @devin-ai-integration[bot] in #43698
- test(ui-e2e): update usage page selectors after the #45221 redesign by @devin-ai-integration[bot] in #45347
- test: replace 61 live logging and otel tests with offline unit and integration coverage by @devin-ai-integration[bot] in #45362
- fix(bedrock): remove the bare xai.grok-4.7 cost-map row that AWS cannot invoke by @devin-ai-integration[bot] in #45460
- test: make 38 legacy live base-class translation tests offline by @devin-ai-integration[bot] in #45351
- fix(bedrock): split the tag for gpt-oss only on native Chat Completions by @devin-ai-integration[bot] in #44432
- feat(ui): add Cmd+K command palette with key search by @ishaan-berri in #45456
- test(streaming): expect the unwrapped provider error in bridged /v1/messages error frames by @devin-ai-integration[bot] in #45465
- refactor(python-bridge): derive NativeCall extraction by @yujonglee-berri in #45449
- refactor(python-bridge): ship a signature base and read the resolved call by @yujonglee-berri in #45450
- fix(cost-map): update baseten DeepSeek-V4.1-Flash-Fast cache read price and max output by @berriai-litellm-provider-info-sync[bot] in #45468
- ci(unit): add unit passed collector job and fold proxy-db shards into test-unit.yml by @devin-ai-integration[bot] in #45466
- feat(guardrails): support logging_only mode for the Akto guardrail by @yucheng-berri in #45461
- fix(router): drop the encrypted reasoning a fallback hop's target cannot decrypt by @devin-ai-integration[bot] in #45393
- chore(cost-map): sync openrouter prices from the models API by @berriai-litellm-provider-info-sync[bot] in #45469
- fix(cli): pin pi compat flags so lite pi stops sending store to Anthropic models by @devin-ai-integration[bot] in #40739
- feat(bedrock): add twelvelabs pegasus 1.5 inference profiles by @berriai-litellm-provider-info-sync[bot] in #45477
- feat(sdk): build core from an independent packaging manifest by @joshua-berri in #44340
- fix(proxy): save file details for every batch output file so they list and retrieve by @devin-ai-integration[bot] in #41761
- fix(bedrock): remove the bare openai.gpt-6.1-sol cost-map row that AWS cannot invoke by @devin-ai-integration[bot] in #45479
- refactor(sdk): separate core AWS and tokenizer dependencies by @joshua-berri in #44447
- fix(router): match deployment pricing ids against the cost map only within the deployment's provider by @devin-ai-integration[bot] in #45472
- fix(bedrock): add gpt-6.1-sol ultrafast tier prices from the Bedrock model card by @berriai-litellm-provider-info-sync[bot] in #45482
- fix(ci): import seed_tracing_fixtures from the pytest scripts path in rust trace tests by @devin-ai-integration[bot] in #45485
- fix(bedrock): take gpt-6.1-sol context window from the Bedrock model card by @berriai-litellm-provider-info-sync[bot] in #45488
- feat(ui): add the evaluation mode to the Add Model form by @devin-ai-integration[bot] in #45481
- feat(mcp): translate input requests and bind continuations by @joshua-berri in #45464
- fix(bedrock): add the claude-sonnet-4-5 EOL date from the Bedrock model card by @berriai-litellm-provider-info-sync[bot] in #45496
- fix(token_counter): price a base64 PDF document per page instead of as one image by @devin-ai-integration[bot] in #45301
- ci: render lint, unit and smoke checks as / with one collector per tier by @devin-ai-integration[bot] in #45480
- test(routing): wait on deployment registration instead of boot model-info traffic by @yuneng-berri in #45267
- fix(anthropic): count a leading system run through count_tokens' system parameter by @devin-ai-integration[bot] in #45463
- ci: run only integration jobs on PR CircleCI pipelines and move router and guardrails suites to GHA by @devin-ai-integration[bot] in #45509
- test: update stale MCP call_tool and usage card assertions, add timeout headroom to request-log index boot test by @devin-ai-integration[bot] in #45523
- feat(credentials): add display_name and make credential_name immutable on PATCH by @devin-ai-integration[bot] in #43148
- fix(ui): let the model picker remove selections that are no longer available by @yuneng-berri in #43944
- refactor(proxy): inject one UTC clock read per operation into gateway tracking, PTU rollup and Mavvrik export by @devin-ai-integration[bot] in #45520
- refactor(proxy): inject the clock into the v1 parallel request limiter and pin it in its tests by @devin-ai-integration[bot] in #45522
- chore: bump litellm-enterprise 0.1.75 -> 0.1.76, litellm-proxy-extras 0.4.107 -> 0.4.108 by @devin-ai-integration[bot] in #45534
- feat(ui): configure OpenAI workload identity federation from the LLM Credentials and Add Model forms by @mateo-berri in #45528
New Contributors
- @msdianprince-7 made their first contribution in #38729
- @Solomon-mithra made their first contribution in #31942
Full Changelog: v1.106.0-dev.2...v1.106.0-dev.3