Commit graph

31 commits

Author SHA1 Message Date
Alexsander Hamir
ebce0e5f8c
[Release - 02/10/2026] v1.81.10-nightly 2026-02-10 16:26:30 -08:00
Harshit Jain
3b043ee8bf
fix critical CVE vulnerabliltes (#20683) 2026-02-07 22:23:01 -08:00
Ishaan Jaffer
b6a75a1085 fix scans 2026-02-07 12:12:44 -08:00
Sameer Kankute
21e95c73e4 Fix litellm_security_tests 2026-02-03 15:24:31 +05:30
shin-bot-litellm
f9fbffa7cf ci(security): allowlist GHSA-34x7-hfp2-rc4v (node-tar hardlink)
Not applicable - tar CLI not exposed in application code
2026-01-31 21:27:58 +00:00
shin-bot-litellm
df042f7545
litellm_fix(security): allowlist Next.js CVEs for 7 days (#20169)
Temporarily allowlist Next.js vulnerabilities in UI dashboard:
- GHSA-h25m-26qc-wcjf (HIGH: DoS via request deserialization)
- CVE-2025-59471 (MEDIUM: Image Optimizer DoS)

Fix: Upgrade to Next.js 15.5.10+ or 16.1.5+ (7-day timeline)

Changes:
- Added .trivyignore with Next.js CVEs
- Updated security_scans.sh to use --ignorefile flag
2026-01-31 10:25:57 -08:00
yuneng-jiang
5cacf56507 security scan 2026-01-23 11:55:56 -08:00
yuneng-jiang
89bf7e50c4 skipping flaky tests 2026-01-23 11:43:39 -08:00
yuneng-jiang
a0b2832300 fixing security checks 2026-01-23 11:03:18 -08:00
yuneng-jiang
ce586ec3d1 Overriding lodash-es with version 4.17.23 in docs 2026-01-22 12:13:40 -08:00
yuneng-jiang
3ddc15a081 Adding lodash-es to allowlist 2026-01-22 11:26:04 -08:00
yuneng-jiang
88c7b45aee adding node-tar cve allowlist 2026-01-22 10:39:19 -08:00
Yuta Saito
f8e25aa016 chore: add ALLOWED_CVES. Because Wolfi glibc still flagged even on 2.42-r5. 2026-01-16 18:23:09 +09:00
Yuta Saito
4e78394b21 chore: address jaraco.context path traversal vulnerability (GHSA-58pv-8j8x-9vj2) 2026-01-16 14:20:24 +09:00
Yuta Saito
94e15a92b2 chore: add zlib to allow list 2026-01-16 11:41:54 +09:00
Yuta Saito
4daac9e332 chore: add ALLOWED_CVES 2026-01-13 10:30:34 +09:00
Yuta Saito
54b21cabf7 chore: add config option 2026-01-13 10:19:12 +09:00
Ishaan Jaffer
bdbbc9db62 run_secret_detection 2026-01-07 16:43:31 +05:30
Ishaan Jaffer
49f4005001 fix 2026-01-07 15:07:32 +05:30
Alexsander Hamir
936aa6821f
[Fix] CI/CD - litellm_security_tests (#18567) 2026-01-01 14:20:04 -08:00
Alexsander Hamir
5534038e93
Fix CI: Revert security scan changes and add GitGuardian ignore rules (#18358) 2025-12-22 17:03:53 -08:00
Ishaan Jaffer
bae488d9cd skip GITGUARDIAN_API_KEY 2025-12-20 20:53:22 +05:30
Alexsander Hamir
4134fab74d
add: new security scan (#18148) 2025-12-17 12:53:15 -08:00
Ishaan Jaffer
8539aac85a fix scans 2025-12-06 15:53:49 -08:00
Ishaan Jaffer
2f0ec47426 GHSA-5j98-mcp5-4vw2 fix 2025-11-22 12:12:28 -08:00
Ishaan Jaffer
a4e0869077 fix scan 2025-10-11 11:38:43 -07:00
Ishaan Jaffer
34579b640e fix sec san 2025-10-11 10:15:35 -07:00
Ishaan Jaffer
2bce4ab74d fix: sec scans 2025-10-11 09:34:48 -07:00
Ishaan Jaffer
13b0e97759 ALLOWED_IDS_JSON sec scan 2025-09-27 17:15:28 -07:00
Ishaan Jaffer
fbc5b73431 fix sec scans 2025-09-26 19:44:57 -07:00
Ishaan Jaff
ac2d349161
[Security] Ensure LiteLLM Images have 0 Critical, High, Medium vulnerabilities with CVSS ≥ 4.0 (#14357)
* updated scans

* fix scans

* fix litellm_security_tests

* fix

* fix count CVEE

* add readme

* fix Security Scans

* fix: starlette==0.47.2 # starlette fastapi dep

* bump fastapi==0.115.14

* bump 0.116.1
2025-09-08 16:49:52 -07:00