Skip to content

feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.2) - #1463

Merged
Faustvii merged 1 commit into
mainfrom
renovate/ghcr.io-berriai-litellm-1.x
Oct 2, 2026
Merged

Faustvii merged 1 commit into
mainfrom
renovate/ghcr.io-berriai-litellm-1.x

Conversation

@faust-renovate

@faust-renovate faust-renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
ghcr.io/berriai/litellm (source) minor v1.102.1 → v1.103.2

Release Notes

BerriAI/litellm (ghcr.io/berriai/litellm)

v1.103.2

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.103.1...v1.103.2

v1.103.1

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

Full Changelog: BerriAI/litellm@v1.103.0...v1.103.1

v1.103.0

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.0

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.0

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@faust-renovate

faust-renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

konflate · #1463 — feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.2)

Tip

Routine: only container-image and chart-version changes; 1 resource across 1 app

image from to upstream
ghcr.io/berriai/litellm v1.102.1@sha256:87f349… v1.103.2@sha256:f63fb8… ✅

konflate 0.6.4 · rendered d3c50ae

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

AI Automated Review

Analysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai)

Recommendation: Approve

Routine Renovate minor version bump for ghcr.io/berriai/litellm (v1.102.1 → 1.103.0). Single-line image reference change in kubernetes/apps/ai/litellm/app/litellmproxy.yaml. Konflate rendered diff confirms only the LiteLLMProxy resource in namespace ai is affected — no other resources, no render failures, no cautions.

Changed Files

File Change
kubernetes/apps/ai/litellm/app/litellmproxy.yaml Image tag v1.102.1@sha256:87f349… → 1.103.0@sha256:bd089a…

Non-blocking Caveats

  • Tag prefix dropped: The previous image used a v-prefixed tag (v1.102.1), matching the upstream git tag convention. The new tag is 1.103.0 (no v). This may reflect a change in the project's Docker image tagging scheme, but it's inconsistent with the prior pin. Renovate presumably resolved this tag from the GHCR registry, so it likely exists — just worth a quick docker pull sanity check if the pod fails to start.
  • Upstream behavioral note: The v1.103.0-rc.1 release notes include refactor(proxy): make the config file win over the database (PR 41779). If your LiteLLM proxy relies on database-stored config that previously overrode the config file, this inversion could change runtime behavior. No action needed if you don't use DB-stored config overrides.

Sources

  • Konflate rendered diff (PR PR 1463, commit c180cea): 1 resource changed, routine image bump, upstream ✅
  • BerriAI/litellm GitHub releases: v1.103.0-rc.1 published 2026-09-20; no stable v1.103.0 tag visible in the fetched release list (only RC and dev tags), but the GHCR image tag 1.103.0 was resolved by Renovate
  • PR diff: single line, image reference only

github-actions[bot]

This comment was marked as outdated.

@faust-renovate
faust-renovate Bot force-pushed the renovate/ghcr.io-berriai-litellm-1.x branch from c180cea to 534070a Compare September 27, 2026 21:01
@faust-renovate faust-renovate Bot changed the title feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ 1.103.0) feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.0) Sep 27, 2026
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

AI Automated Review

Analysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai)

Recommendation: ✅ Approve

Routine Renovate minor version bump for ghcr.io/berriai/litellm (v1.102.1 → v1.103.0). Single-line change to the image reference in the LiteLLMProxy HelmRelease values. No breaking-change indicators in the 2,943 upstream commits; konflate confirms 1 resource affected with no cautions.

Changed Files

File Change
kubernetes/apps/ai/litellm/app/litellmproxy.yaml Image tag v1.102.1 → v1.103.0, digest updated accordingly

The image remains pinned by both tag and @sha256: digest, consistent with repository convention for container images.

Upstream Notes

The compare range (v1.102.1…v1.103.0) spans 2,943 commits. Notable changes include proxy fixes (bulk key update, spend-log placeholder handling, cost-tracking alert metadata), a router 429 feature for max_parallel_requests, and various UI/cleanup refactors. No breaking API or configuration changes are evident in the commit messages.

Evidence Provider Findings

Konflate rendered diff (v0.6.4, rendered at 534070a):

  • Blast radius: 1 resource (LiteLLMProxy ai/litellm), 1 image change.
  • Cautions: None (no data-loss, immutable-field, RBAC, or suspend/prune signals).
  • Render status: Clean — no failures.
  • Upstream check: ✅

Tool Harness Findings

  • mcp__konflate__get_pr_summary confirms the routine classification and upstream ✅.
  • gh_api fetch of repos/BerriAI/litellm/releases/tags/v1.103.0 returned 404 — the tag exists (compare API resolved it) but has no formal GitHub Release object. This is non-blocking; the image is present on ghcr.io and the digest is pinned.

Unknowns / Needs Verification

  • No formal release notes are available for v1.103.0 (tag exists, release object does not). The compare metadata and commit log provide sufficient signal that this is a standard minor release with no breaking changes. CI is still pending at review time.

@faust-renovate
faust-renovate Bot force-pushed the renovate/ghcr.io-berriai-litellm-1.x branch from 534070a to e168808 Compare September 30, 2026 00:01
@faust-renovate faust-renovate Bot changed the title feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.0) feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.1) Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

AI Automated Review

Analysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai)

Recommendation: ✅ Approve

Routine Renovate container image update for ghcr.io/berriai/litellm from v1.102.1 → v1.103.1. Single-line change in kubernetes/apps/ai/litellm/app/litellmproxy.yaml updating the image tag and SHA digest. No structural, configuration, or multi-resource impact.

Change Summary

File Change
kubernetes/apps/ai/litellm/app/litellmproxy.yaml image: ghcr.io/berriai/litellm:v1.102.1@sha256:87f349… → v1.103.1@sha256:df1540…

The image remains pinned by both tag and SHA digest, consistent with repository conventions for container images.

Upstream Release Notes (v1.103.0)

The minor bump includes fixes across responses, proxy, MCP OAuth admission, logging, Fireworks model resolution, spend-logs, auth session tokens, and Bedrock S3 file operations. No breaking changes are indicated in the release notes.

Evidence Provider Findings

konflate-rendered-diff (status: ok, severity: info):

  • Rendered Flux diff confirms a single resource change: LiteLLMProxy ai/litellm — only the image field differs.
  • Classified as Routine: only container-image changes; 1 resource across 1 app.
  • Upstream image check: ✅ (image exists in registry).
  • No render failures, no caution lints (no data-loss, immutable-field, RBAC, or suspend/prune concerns).

Tool Harness Findings

No native tool calls were issued; review was conducted directly from the corpus. No additional evidence was gathered beyond what the evidence providers supplied.

Unknowns or Needs Verification

  • The GitHub release enrichment did not list a v1.103.1 tag among the captured releases (the list is truncated and the note states "No release tags matched target version 1.103.1"). However, konflate's upstream check returned ✅, confirming the image exists in the registry. This is most likely a truncation artifact in the enrichment rather than a missing release. No action required.

@faust-renovate
faust-renovate Bot force-pushed the renovate/ghcr.io-berriai-litellm-1.x branch from e168808 to 6be1d81 Compare October 1, 2026 09:02
@faust-renovate faust-renovate Bot changed the title feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.1) feat(container): update image ghcr.io/berriai/litellm (v1.102.1 ➔ v1.103.2) Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

AI Automated Review

Analysis engine: self-qwen3.8@http://modelrouter-router-proxy.ai.svc.cluster.local:8080/v1 (openai)

Recommendation: ✅ Approve

Routine Renovate minor-version bump for the LiteLLM proxy image. Single-line change, verified upstream release, no cautions from rendered diff.

Change Summary

File Change
kubernetes/apps/ai/litellm/app/litellmproxy.yaml ghcr.io/berriai/litellm:v1.102.1@sha256:87f349… → v1.103.2@sha256:f63fb8…

The image is pinned by both tag and SHA-256 digest. The upstream release v1.103.2 (published 2026-10-01) is confirmed via the GitHub API. The version span (v1.102.1 → v1.103.2) covers:

  • v1.103.0 – minor release (2 943 commits ahead of v1.102.2): proxy, provider, and CI improvements.
  • v1.103.1 – auth refactor binding UI/CLI session tokens to a dedicated AES-GCM context.
  • v1.103.2 – backported proxy fixes (PR 40541, PR 43642, PR 43656, PR 43962) and Anthropic safeguards/beta forwarding fixes (PR 42152, PR 42288).

No breaking changes are called out in the release notes. The Konflate rendered diff confirms the only cluster impact is the image field on the single LiteLLMProxy resource in namespace ai.

Evidence Provider Findings

Konflate rendered-diff (status: ok, severity: info):

  • 1 resource changed: LiteLLMProxy ai/litellm – image field only.
  • Classified as Routine: "only container-image and chart-version changes; 1 resource across 1 app."
  • No cautions (no data-loss, immutable-field, RBAC, or suspend/prune signals).
  • No render failures.

Tool Harness Findings

  • mcp__konflate__list_pull_requests – ok. PR PR 1463 not yet in the tracked list (render pending at time of call), consistent with a freshly opened PR.
  • gh_api (release lookup for v1.103.2) – ok. Release confirmed: tag v1.103.2, published 2026-10-01T06:37:31Z, not a prerelease, no assets.

@faust-review

faust-review Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

kritika review

1 finding · 1 important

This is a Renovate image bump for the LiteLLM proxy from v1.102.1 to v1.103.2, with the sha256 digest updated in lockstep; konflate confirms only the container image changes across the one affected resource. I pulled the upstream release notes for the three releases in range (v1.103.0, v1.103.1, v1.103.2) via the BerriAI/litellm GitHub API to check for breaking changes affecting this deployment. Safe to merge: the only breaking change in range, the new default that re-checks key/user budgets on router fallback targets, does not apply to anything configured in this repo's manifest (no fallbacks, no paid targets, no max_budget), so it is a no-op here unless such things are set up later in the LiteLLM UI.

Findings

Sources consulted

Reviewed d3c50ae by kritika with self-qwen3.8.

@faust-renovate
faust-renovate Bot force-pushed the renovate/ghcr.io-berriai-litellm-1.x branch from 6be1d81 to d3c50ae Compare October 2, 2026 11:41
generalSettings:
health_check_endpoint: /v1/health
image: ghcr.io/berriai/litellm:v1.102.1@sha256:87f34979b9f8cb274fac90ca8a4fdda07d8480de22755562a26adeb95ce20d02
image: ghcr.io/berriai/litellm:v1.103.2@sha256:f63fb81b831b170ec16851e23c36ac5bf52ef106b271406429524a2ed730bbfd

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[important · correctness] v1.103.0 adds a default-on budget re-check on router fallbacks

This bump crosses v1.103.0, which ships fix!: re-check budget on router fallback targets (BerriAI/litellm#41379) — the only !-marked change in the v1.102.1…v1.103.2 range. It is on by default and needs no config to take effect: once enabled, a key/user that has already exhausted its max_budget is refused the paid fallback target (returns the primary model's own error) instead of silently billing against it. The PR's truncated release notes never surface this, so it's easy to miss. It does not change anything for the values written here (no fallbacks, no paid model_list entries, no max_budget in the manifest), but LiteLLM keys and model fallbacks can also be managed at runtime in the proxy UI/DB; if that is done here, over-budget callers that previously fell through to a paid model will now get an error after this deploy. The behavior change is a security improvement, so it is worth a one-time check rather than a revert.

Suggested fix

No code change needed. After the upgrade, if any LiteLLM keys or models are managed in the proxy UI/DB, verify no configured fallback pair relies on an over-budget caller reaching a paid target; if any deployment genuinely needs the old fall-through behavior, add generalSettings.enforce_fallback_budget: false to this manifest.

@Faustvii
Faustvii merged commit 3aae1d5 into main Oct 2, 2026
5 checks passed
@Faustvii
Faustvii deleted the renovate/ghcr.io-berriai-litellm-1.x branch October 2, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant