LiteLLM v1.99.0-dev.1

v1.99.0-dev.1Pre-release
Added 4
  • Async Rust OCR Bridge and MCP OAuth UI Restore
  • Add Lite mixed-provider auto-router preset in UI
  • Link key info header to its user, creator, team, and organization in UI
  • Forward LiteLLM identity and metadata into Bedrock requestMetadata
Fixed 14
  • Register WebSocket passthrough for OpenAI prefixes in proxy
  • Report uploaded size in the FileObject returned by Bedrock managed batch uploads
  • Support AWS Bedrock batch cancellation via StopModelInvocationJob
  • Do not crash logging when a completed batch has no output file
  • Add default model pin to complexity router UI
  • Scan text on /guardrails/apply_guardrail for Azure Content Safety
Security 2
  • Docker images are signed with cosign for verification
  • Bump sqlparse to 0.6.0 to resolve osv-scan CVEs

From LiteLLM

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.99.0-dev.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.99.0-dev.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.99.0-dev.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed
New Contributors

Full Changelog: https://github.com/BerriAI/litellm/compare/v1.98.0-rc.1...v1.99.0-dev.1

View original

Upgraded? How did it go?

Discussion