Skip to content

fix(container): update image ghcr.io/berriai/litellm-non_root (v1.96.0 ➔ v1.96.2) - #7234

Merged
drag0n141 merged 1 commit into
masterfrom
renovate/ghcr.io-berriai-litellm-non_root-1.x
Aug 12, 2026
Merged

drag0n141 merged 1 commit into
masterfrom
renovate/ghcr.io-berriai-litellm-non_root-1.x

Conversation

@drag0n141-bot

@drag0n141-bot drag0n141-bot Bot commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/berriai/litellm-non_root (source) patch v1.96.0 → v1.96.2

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

BerriAI/litellm (ghcr.io/berriai/litellm-non_root)

v1.96.2

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.96.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.96.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.96.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.96.0...v1.96.2

v1.96.2

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.96.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.96.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.96.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.96.0...v1.96.2


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@drag0n141-bot drag0n141-bot Bot added renovate/container type/patch area/kubernetes Changes made in the kubernetes directory labels Aug 11, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

litellm-non_root: v1.96.0 → v1.96.2

Verdict: Safe to merge

This is a patch bump. Upstream context (no GitHub tag/release exists for either v1.96.1 or v1.96.2 — both were release-engineering fixes rather than tagged releases):

  • v1.96.1 (litellm #36494) backported a single commit, fix(proxy)!: apply request-parameter checks consistently across body, path and form inputs (originally #36011), onto the stable/1.96.x line. Upstream marks it breaking.
  • v1.96.2 (litellm #36570) is a version-only re-cut of 1.96.1 after a PyPI storage quota failure corrupted that release's artifacts — no additional code changes.

So the only functional change between v1.96.0 and v1.96.2 running in this cluster is the backported request-parameter-validation fix. It has two effects:

  1. /health/test_connection (Admin UI "test connection" feature) no longer merges configured api_base/api_key into a request that overrides any other field — previously the configured connection details were inherited even when unrelated params were overridden.
  2. URL-valued model supplied via URL path/query and bracket-notation form fields (e.g. metadata[...]) are now rejected the same way their JSON-body equivalents already were — a validation-consistency/security hardening, not a new restriction on JSON requests.

Checked this against how the repo actually deploys and consumes LiteLLM (kubernetes/apps/ai/litellm/app/resources/config.yaml, and consumers in open-webui, paperless-gpt, paperless-ai, hermes):

  • All four models in config.yaml are statically defined with explicit api_base/api_key per entry — nothing relies on /health/test_connection field-merging behavior, and general_settings.allow_client_side_credentials (the documented workaround) isn't set.
  • The liveness/readiness probes hit / directly (helmrelease.yaml), not /health/test_connection, so probe behavior is unaffected.
  • No consumer in this repo sends URL-path-based model names or bracket-notation form fields; all integrations use standard OpenAI-compatible JSON request bodies.

No actionable breaking changes or deprecations for this deployment.

Sources consulted:

@drag0n141-bot
drag0n141-bot Bot force-pushed the renovate/ghcr.io-berriai-litellm-non_root-1.x branch from ea8ae4d to d7dbc7d Compare August 12, 2026 05:02
@drag0n141-bot

drag0n141-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor Author
--- kubernetes/apps/ai/litellm/app Kustomization: ai/litellm HelmRelease: ai/litellm

+++ kubernetes/apps/ai/litellm/app Kustomization: ai/litellm HelmRelease: ai/litellm

@@ -42,13 +42,13 @@

               TZ: Europe/Berlin
             envFrom:
             - secretRef:
                 name: litellm-secret
             image:
               repository: ghcr.io/berriai/litellm-non_root
-              tag: v1.96.0@sha256:8b64d0fa562739649932b6f654a03dee9a511e7dd0a60bdba9d37b8fd3ffd69d
+              tag: v1.96.2@sha256:f106967e9b4d8f43c97c1cc8b4d5ad31cd95f7d37ab5b20a48ff4a609e82da73
             probes:
               liveness:
                 custom: true
                 enabled: true
                 spec:
                   failureThreshold: 3

@drag0n141-bot

drag0n141-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor Author
--- HelmRelease: ai/litellm Deployment: ai/litellm

+++ HelmRelease: ai/litellm Deployment: ai/litellm

@@ -55,13 +55,13 @@

           value: '6379'
         - name: TZ
           value: Europe/Berlin
         envFrom:
         - secretRef:
             name: litellm-secret
-        image: ghcr.io/berriai/litellm-non_root:v1.96.0@sha256:8b64d0fa562739649932b6f654a03dee9a511e7dd0a60bdba9d37b8fd3ffd69d
+        image: ghcr.io/berriai/litellm-non_root:v1.96.2@sha256:f106967e9b4d8f43c97c1cc8b4d5ad31cd95f7d37ab5b20a48ff4a609e82da73
         livenessProbe:
           failureThreshold: 3
           httpGet:
             path: /
             port: 4000
           initialDelaySeconds: 5

@drag0n141
drag0n141 merged commit 680189d into master Aug 12, 2026
11 checks passed
@drag0n141
drag0n141 deleted the renovate/ghcr.io-berriai-litellm-non_root-1.x branch August 12, 2026 05:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/kubernetes Changes made in the kubernetes directory renovate/container type/patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant