fix(container): update image ghcr.io/berriai/litellm-non_root (v1.96.0 ➔ v1.96.2) - #7234
Merged
Merged
Conversation
There was a problem hiding this comment.
litellm-non_root: v1.96.0 → v1.96.2
Verdict: Safe to merge
This is a patch bump. Upstream context (no GitHub tag/release exists for either v1.96.1 or v1.96.2 — both were release-engineering fixes rather than tagged releases):
v1.96.1(litellm#36494) backported a single commit,fix(proxy)!: apply request-parameter checks consistently across body, path and form inputs(originally#36011), onto thestable/1.96.xline. Upstream marks it breaking.v1.96.2(litellm#36570) is a version-only re-cut of1.96.1after a PyPI storage quota failure corrupted that release's artifacts — no additional code changes.
So the only functional change between v1.96.0 and v1.96.2 running in this cluster is the backported request-parameter-validation fix. It has two effects:
/health/test_connection(Admin UI "test connection" feature) no longer merges configuredapi_base/api_keyinto a request that overrides any other field — previously the configured connection details were inherited even when unrelated params were overridden.- URL-valued
modelsupplied via URL path/query and bracket-notation form fields (e.g.metadata[...]) are now rejected the same way their JSON-body equivalents already were — a validation-consistency/security hardening, not a new restriction on JSON requests.
Checked this against how the repo actually deploys and consumes LiteLLM (kubernetes/apps/ai/litellm/app/resources/config.yaml, and consumers in open-webui, paperless-gpt, paperless-ai, hermes):
- All four models in
config.yamlare statically defined with explicitapi_base/api_keyper entry — nothing relies on/health/test_connectionfield-merging behavior, andgeneral_settings.allow_client_side_credentials(the documented workaround) isn't set. - The liveness/readiness probes hit
/directly (helmrelease.yaml), not/health/test_connection, so probe behavior is unaffected. - No consumer in this repo sends URL-path-based model names or bracket-notation form fields; all integrations use standard OpenAI-compatible JSON request bodies.
No actionable breaking changes or deprecations for this deployment.
Sources consulted:
- BerriAI/litellm#36494
- BerriAI/litellm#36570
- https://docs.litellm.ai/release_notes (no notes published for 1.96.1/1.96.2 patch versions)
kubernetes/apps/ai/litellm/app/resources/config.yamlkubernetes/apps/ai/litellm/app/helmrelease.yaml
drag0n141-bot
Bot
force-pushed
the
renovate/ghcr.io-berriai-litellm-non_root-1.x
branch
from
August 12, 2026 05:02
ea8ae4d to
d7dbc7d
Compare
Contributor
Author
--- kubernetes/apps/ai/litellm/app Kustomization: ai/litellm HelmRelease: ai/litellm
+++ kubernetes/apps/ai/litellm/app Kustomization: ai/litellm HelmRelease: ai/litellm
@@ -42,13 +42,13 @@
TZ: Europe/Berlin
envFrom:
- secretRef:
name: litellm-secret
image:
repository: ghcr.io/berriai/litellm-non_root
- tag: v1.96.0@sha256:8b64d0fa562739649932b6f654a03dee9a511e7dd0a60bdba9d37b8fd3ffd69d
+ tag: v1.96.2@sha256:f106967e9b4d8f43c97c1cc8b4d5ad31cd95f7d37ab5b20a48ff4a609e82da73
probes:
liveness:
custom: true
enabled: true
spec:
failureThreshold: 3 |
Contributor
Author
--- HelmRelease: ai/litellm Deployment: ai/litellm
+++ HelmRelease: ai/litellm Deployment: ai/litellm
@@ -55,13 +55,13 @@
value: '6379'
- name: TZ
value: Europe/Berlin
envFrom:
- secretRef:
name: litellm-secret
- image: ghcr.io/berriai/litellm-non_root:v1.96.0@sha256:8b64d0fa562739649932b6f654a03dee9a511e7dd0a60bdba9d37b8fd3ffd69d
+ image: ghcr.io/berriai/litellm-non_root:v1.96.2@sha256:f106967e9b4d8f43c97c1cc8b4d5ad31cd95f7d37ab5b20a48ff4a609e82da73
livenessProbe:
failureThreshold: 3
httpGet:
path: /
port: 4000
initialDelaySeconds: 5 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.96.0→v1.96.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
BerriAI/litellm (ghcr.io/berriai/litellm-non_root)
v1.96.2Compare Source
Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit
0112e53.Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
Expected output:
What's Changed
Full Changelog: BerriAI/litellm@v1.96.0...v1.96.2
v1.96.2Compare Source
Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit
0112e53.Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
Expected output:
What's Changed
Full Changelog: BerriAI/litellm@v1.96.0...v1.96.2
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate CLI.