Alexsander Hamir
ebce0e5f8c
[Release - 02/10/2026] v1.81.10-nightly
2026-02-10 16:26:30 -08:00
Harshit Jain
3b043ee8bf
fix critical CVE vulnerabliltes ( #20683 )
2026-02-07 22:23:01 -08:00
Ishaan Jaffer
b6a75a1085
fix scans
2026-02-07 12:12:44 -08:00
Sameer Kankute
21e95c73e4
Fix litellm_security_tests
2026-02-03 15:24:31 +05:30
shin-bot-litellm
f9fbffa7cf
ci(security): allowlist GHSA-34x7-hfp2-rc4v (node-tar hardlink)
...
Not applicable - tar CLI not exposed in application code
2026-01-31 21:27:58 +00:00
shin-bot-litellm
df042f7545
litellm_fix(security): allowlist Next.js CVEs for 7 days ( #20169 )
...
Temporarily allowlist Next.js vulnerabilities in UI dashboard:
- GHSA-h25m-26qc-wcjf (HIGH: DoS via request deserialization)
- CVE-2025-59471 (MEDIUM: Image Optimizer DoS)
Fix: Upgrade to Next.js 15.5.10+ or 16.1.5+ (7-day timeline)
Changes:
- Added .trivyignore with Next.js CVEs
- Updated security_scans.sh to use --ignorefile flag
2026-01-31 10:25:57 -08:00
yuneng-jiang
5cacf56507
security scan
2026-01-23 11:55:56 -08:00
yuneng-jiang
89bf7e50c4
skipping flaky tests
2026-01-23 11:43:39 -08:00
yuneng-jiang
a0b2832300
fixing security checks
2026-01-23 11:03:18 -08:00
yuneng-jiang
ce586ec3d1
Overriding lodash-es with version 4.17.23 in docs
2026-01-22 12:13:40 -08:00
yuneng-jiang
3ddc15a081
Adding lodash-es to allowlist
2026-01-22 11:26:04 -08:00
yuneng-jiang
88c7b45aee
adding node-tar cve allowlist
2026-01-22 10:39:19 -08:00
Yuta Saito
f8e25aa016
chore: add ALLOWED_CVES. Because Wolfi glibc still flagged even on 2.42-r5.
2026-01-16 18:23:09 +09:00
Yuta Saito
4e78394b21
chore: address jaraco.context path traversal vulnerability (GHSA-58pv-8j8x-9vj2)
2026-01-16 14:20:24 +09:00
Yuta Saito
94e15a92b2
chore: add zlib to allow list
2026-01-16 11:41:54 +09:00
Yuta Saito
4daac9e332
chore: add ALLOWED_CVES
2026-01-13 10:30:34 +09:00
Yuta Saito
54b21cabf7
chore: add config option
2026-01-13 10:19:12 +09:00
Ishaan Jaffer
bdbbc9db62
run_secret_detection
2026-01-07 16:43:31 +05:30
Ishaan Jaffer
49f4005001
fix
2026-01-07 15:07:32 +05:30
Alexsander Hamir
936aa6821f
[Fix] CI/CD - litellm_security_tests ( #18567 )
2026-01-01 14:20:04 -08:00
Alexsander Hamir
5534038e93
Fix CI: Revert security scan changes and add GitGuardian ignore rules ( #18358 )
2025-12-22 17:03:53 -08:00
Ishaan Jaffer
bae488d9cd
skip GITGUARDIAN_API_KEY
2025-12-20 20:53:22 +05:30
Alexsander Hamir
4134fab74d
add: new security scan ( #18148 )
2025-12-17 12:53:15 -08:00
Ishaan Jaffer
8539aac85a
fix scans
2025-12-06 15:53:49 -08:00
Ishaan Jaffer
2f0ec47426
GHSA-5j98-mcp5-4vw2 fix
2025-11-22 12:12:28 -08:00
Ishaan Jaffer
a4e0869077
fix scan
2025-10-11 11:38:43 -07:00
Ishaan Jaffer
34579b640e
fix sec san
2025-10-11 10:15:35 -07:00
Ishaan Jaffer
2bce4ab74d
fix: sec scans
2025-10-11 09:34:48 -07:00
Ishaan Jaffer
13b0e97759
ALLOWED_IDS_JSON sec scan
2025-09-27 17:15:28 -07:00
Ishaan Jaffer
fbc5b73431
fix sec scans
2025-09-26 19:44:57 -07:00
Ishaan Jaff
ac2d349161
[Security] Ensure LiteLLM Images have 0 Critical, High, Medium vulnerabilities with CVSS ≥ 4.0 ( #14357 )
...
* updated scans
* fix scans
* fix litellm_security_tests
* fix
* fix count CVEE
* add readme
* fix Security Scans
* fix: starlette==0.47.2 # starlette fastapi dep
* bump fastapi==0.115.14
* bump 0.116.1
2025-09-08 16:49:52 -07:00