LiteLLM v1.101.0-dev.1

v1.101.0-dev.1Pre-release
Added 10
  • Honor streaming buffer and sampling config for unbuffered post_call scans in Bedrock
  • Set ENABLE_TOOL_SEARCH=true for lite Claude in CLI
  • Close duplicate issues after a 3-day grace period in CI
  • Persist router metadata in spend logs for internal router models in spend_tracking
  • Support workload identity federation (OIDC token exchange) in OpenAI
  • Add /v1/responses/input_tokens token counting endpoint in proxy
Changed 2
  • Clear Any type seams across 47 files and ratchet basedpyright ceilings
  • Clear 1.2k basedpyright Any errors across 16 hotspot files
Fixed 14
  • Emit timing headers and overhead for /v1/messages and /v1/responses in proxy
  • Derive the no-cache-read-rate savings baseline from the model map in tests
  • Deliver budget alerts on webhook-only alerting and accept ALERTING_WEBHOOK_URL in proxy
  • Update stale source URLs and deprecation dates in model cost map
  • Configure Prompt Security file timeout policy in guardrails
  • Stop duplicating Converse config blocks inside inferenceConfig in Bedrock
Security 1
  • Sign all LiteLLM Docker images with cosign

From LiteLLM

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.101.0-dev.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.101.0-dev.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.101.0-dev.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed
New Contributors

Full Changelog: https://github.com/BerriAI/litellm/compare/v1.100.0-rc.1...v1.101.0-dev.1

View original

Upgraded? How did it go?

Discussion