diff --git a/tests/test_litellm/llms/bedrock/test_base_aws_llm.py b/tests/test_litellm/llms/bedrock/test_base_aws_llm.py index f5856cd12d6..77eda432513 100644 --- a/tests/test_litellm/llms/bedrock/test_base_aws_llm.py +++ b/tests/test_litellm/llms/bedrock/test_base_aws_llm.py @@ -582,7 +582,8 @@ def test_eks_irsa_ambient_credentials_used(): ) # Should create STS client without explicit credentials (using ambient credentials) - mock_boto3_client.assert_called_once_with("sts") + # Note: verify parameter is passed for SSL verification + mock_boto3_client.assert_called_once_with("sts", verify=True) # Should call assume_role mock_sts_client.assume_role.assert_called_once_with( @@ -637,11 +638,13 @@ def test_explicit_credentials_used_when_provided(): ) # Should create STS client with explicit credentials + # Note: verify parameter is passed for SSL verification mock_boto3_client.assert_called_once_with( "sts", aws_access_key_id="explicit-access-key", aws_secret_access_key="explicit-secret-key", aws_session_token="assumed-session-token", + verify=True, ) # Should call assume_role @@ -701,6 +704,7 @@ def test_partial_credentials_still_use_ambient(): aws_access_key_id="AKIAEXAMPLE", aws_secret_access_key=None, aws_session_token=None, + verify=True, ) # Should still call assume_role @@ -748,7 +752,7 @@ def test_cross_account_role_assumption(): ) # Should use ambient credentials - mock_boto3_client.assert_called_once_with("sts") + mock_boto3_client.assert_called_once_with("sts", verify=True) # Should call assume_role with cross-account role mock_sts_client.assume_role.assert_called_once_with(