Repository navigation
feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.2) - #1463
Conversation
konflate · #1463 — feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.2)Tip Routine: only container-image and chart-version changes; 1 resource across 1 app
konflate 0.6.4 · rendered |
AI Automated ReviewAnalysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai) Recommendation: ApproveRoutine Renovate minor version bump for Changed Files
Non-blocking Caveats
Sources
|
c180cea to
534070a
Compare
AI Automated ReviewAnalysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai) Recommendation: ✅ ApproveRoutine Renovate minor version bump for Changed Files
The image remains pinned by both tag and Upstream NotesThe compare range (v1.102.1…v1.103.0) spans 2,943 commits. Notable changes include proxy fixes (bulk key update, spend-log placeholder handling, cost-tracking alert metadata), a router 429 feature for Evidence Provider FindingsKonflate rendered diff (v0.6.4, rendered at
Tool Harness Findings
Unknowns / Needs Verification
|
534070a to
e168808
Compare
AI Automated ReviewAnalysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai) Recommendation: ✅ ApproveRoutine Renovate container image update for Change Summary
The image remains pinned by both tag and SHA digest, consistent with repository conventions for container images. Upstream Release Notes (v1.103.0)The minor bump includes fixes across responses, proxy, MCP OAuth admission, logging, Fireworks model resolution, spend-logs, auth session tokens, and Bedrock S3 file operations. No breaking changes are indicated in the release notes. Evidence Provider Findingskonflate-rendered-diff (status: ok, severity: info):
Tool Harness FindingsNo native tool calls were issued; review was conducted directly from the corpus. No additional evidence was gathered beyond what the evidence providers supplied. Unknowns or Needs Verification
|
e168808 to
6be1d81
Compare
AI Automated ReviewAnalysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai) Recommendation: ✅ ApproveRoutine Renovate minor-version bump for the LiteLLM proxy image. Single-line change, verified upstream release, no cautions from rendered diff. Change Summary
The image is pinned by both tag and SHA-256 digest. The upstream release v1.103.2 (published 2026-10-01) is confirmed via the GitHub API. The version span (v1.102.1 → v1.103.2) covers:
No breaking changes are called out in the release notes. The Konflate rendered diff confirms the only cluster impact is the image field on the single Evidence Provider FindingsKonflate rendered-diff (status: ok, severity: info):
Tool Harness Findings
|
kritika review1 finding · 1 important This is a Renovate image bump for the LiteLLM proxy from v1.102.1 to v1.103.2, with the sha256 digest updated in lockstep; konflate confirms only the container image changes across the one affected resource. I pulled the upstream release notes for the three releases in range (v1.103.0, v1.103.1, v1.103.2) via the BerriAI/litellm GitHub API to check for breaking changes affecting this deployment. Safe to merge: the only breaking change in range, the new default that re-checks key/user budgets on router fallback targets, does not apply to anything configured in this repo's manifest (no fallbacks, no paid targets, no max_budget), so it is a no-op here unless such things are set up later in the LiteLLM UI. Findings
Sources consulted
Reviewed |
6be1d81 to
d3c50ae
Compare
| generalSettings: | ||
| health_check_endpoint: /v1/health | ||
| image: ghcr.io/berriai/litellm:v1.102.1@sha256:87f34979b9f8cb274fac90ca8a4fdda07d8480de22755562a26adeb95ce20d02 | ||
| image: ghcr.io/berriai/litellm:v1.103.2@sha256:f63fb81b831b170ec16851e23c36ac5bf52ef106b271406429524a2ed730bbfd |
There was a problem hiding this comment.
[important · correctness] v1.103.0 adds a default-on budget re-check on router fallbacks
This bump crosses v1.103.0, which ships fix!: re-check budget on router fallback targets (BerriAI/litellm#41379) — the only !-marked change in the v1.102.1…v1.103.2 range. It is on by default and needs no config to take effect: once enabled, a key/user that has already exhausted its max_budget is refused the paid fallback target (returns the primary model's own error) instead of silently billing against it. The PR's truncated release notes never surface this, so it's easy to miss. It does not change anything for the values written here (no fallbacks, no paid model_list entries, no max_budget in the manifest), but LiteLLM keys and model fallbacks can also be managed at runtime in the proxy UI/DB; if that is done here, over-budget callers that previously fell through to a paid model will now get an error after this deploy. The behavior change is a security improvement, so it is worth a one-time check rather than a revert.
Suggested fix
No code change needed. After the upgrade, if any LiteLLM keys or models are managed in the proxy UI/DB, verify no configured fallback pair relies on an over-budget caller reaching a paid target; if any deployment genuinely needs the old fall-through behavior, add generalSettings.enforce_fallback_budget: false to this manifest.
This PR contains the following updates:
v1.102.1→v1.103.2Release Notes
BerriAI/litellm (ghcr.io/berriai/litellm)
v1.103.2Compare Source
Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit
0112e53.Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
Expected output:
What's Changed
Full Changelog: BerriAI/litellm@v1.103.1...v1.103.2
v1.103.1Compare Source
Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit
0112e53.Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
Expected output:
Full Changelog: BerriAI/litellm@v1.103.0...v1.103.1
v1.103.0Compare Source
Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit
0112e53.Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
Expected output:
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.