Commit graph

45729 commits

Author SHA1 Message Date
Yuneng Jiang
332a85f80c
chore(deps): bump multidict to 6.9.1 2026-10-05 18:51:05 -07:00
Yuneng Jiang
c803851610
chore(deps): bump mako to 1.4.2 2026-10-05 18:51:04 -07:00
Yuneng Jiang
eeade8f176
chore(deps): bump langgraph-sdk to 0.4.4 2026-10-05 18:51:04 -07:00
Yuneng Jiang
8f24976b52
chore(deps): bump oauthlib to 4.0.0 2026-10-05 18:51:03 -07:00
Yuneng Jiang
fd07082c0c
chore(deps): bump gitpython to 3.1.62 2026-10-05 18:51:03 -07:00
Yuneng Jiang
a10756f7c7
chore(deps): bump fsspec to 2026.6.0 2026-10-05 18:51:02 -07:00
Yuneng Jiang
065a66140a
chore(deps): bump tornado to 6.5.9 2026-10-05 18:51:01 -07:00
Yuneng Jiang
ad94f926fc
chore(deps): bump urllib3 to 2.8.0 2026-10-05 18:51:01 -07:00
Yuneng Jiang
e977d1b4c1
chore(deps): bump pypdf to 6.19.0 2026-10-05 18:51:00 -07:00
Yuneng Jiang
f5b1d9cb0d
chore(deps): bump pyjwt to 2.15.0 2026-10-05 18:50:59 -07:00
yuneng-jiang
40e57401b9
Merge pull request #44724 from BerriAI/litellm_chore_c52634
revert: restore stable/1.100.x to v1.100.4 plus the wolfi-base digest
2026-10-05 17:31:13 -07:00
yuneng-jiang
f99e2e1fab
chore(docker): bump wolfi-base digest to pick up glibc 2.44-r6 (#42643)
The pinned base's /etc/apk/world locks glibc-2.44=2.44-r1, so the apk upgrade in the runtime stage cannot move it. The new digest ships 2.44-r6 on amd64 and arm64

(cherry picked from commit bc911abdbb)
2026-10-05 17:30:21 -07:00
Yuneng Jiang
75d26439c1
Revert "Merge pull request #44151 from BerriAI/litellm_chore_75e0ca"
This reverts commit a17acca84f, reversing
changes made to dd2f80fdc3.
2026-10-05 17:27:53 -07:00
Yuneng Jiang
dd848b4a2a
Revert "Merge pull request #44159 from BerriAI/litellm_chore_1c29d6"
This reverts commit 90bd6e3de8, reversing
changes made to a17acca84f.
2026-10-05 17:27:53 -07:00
yuneng-jiang
90bd6e3de8
Merge pull request #44159 from BerriAI/litellm_chore_1c29d6
chore(release): backport #42643 to stable/1.100.x
2026-10-02 00:42:00 -07:00
yuneng-jiang
cb3e9fa710 chore(docker): bump wolfi-base digest to pick up glibc 2.44-r6 (#42643)
The pinned base's /etc/apk/world locks glibc-2.44=2.44-r1, so the apk upgrade in the runtime stage cannot move it. The new digest ships 2.44-r6 on amd64 and arm64

(cherry picked from commit bc911abdbb)
2026-10-02 07:24:10 +00:00
yuneng-jiang
a17acca84f
Merge pull request #44151 from BerriAI/litellm_chore_75e0ca
chore(release): backport #39590 to stable/1.100.x and cut 1.100.5
2026-10-02 00:02:36 -07:00
Yuneng Jiang
4673031cb9
chore: refresh uv.lock for 1.100.5 2026-10-01 22:15:59 -07:00
Yuneng Jiang
9493b98bde
bump: version 1.100.4 → 1.100.5 2026-10-01 22:15:49 -07:00
Yuneng Jiang
d6a2d5d7b0
chore: update Next.js build artifacts (2026-10-02 05:15 UTC, node v24.19.0) 2026-10-01 22:15:40 -07:00
Yuneng Jiang
10c97b7ec6
chore(deps): bump tornado to 6.5.9 2026-10-01 22:11:55 -07:00
Yuneng Jiang
78d65f63ec
chore(deps): bump urllib3 to 2.8.0 2026-10-01 22:11:55 -07:00
Yuneng Jiang
edfa762afd
chore(deps): bump pypdf to 6.19.0 2026-10-01 22:11:55 -07:00
Yuneng Jiang
b94f1d225b
chore(deps): bump pyjwt to 2.15.0 2026-10-01 22:11:55 -07:00
mateo
3651a47ee9
test: deflake JWT tamper assertions and fuzzy picker widget driver
Tamper tests rewrote the last two base64url characters of the signature,
which on roughly 1 in 250 RS256 tokens (1 in 1000 HS256) only touched
padding bits, so the decoded signature was unchanged and still verified.
Corrupt the decoded signature bytes instead.

The fuzzy picker driver sent keys after fixed sleeps, so a slow worker
could receive the filter text before the widget had highlighted the match.
Wait on the widget's highlighted choice instead.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 25c5f0d993)
2026-10-01 22:11:55 -07:00
devin-ai-integration[bot]
e5f93c008a
feat(caching): add semantic_cache_scope to isolate semantic cache hits per end user (#39590)
Semantic cache keys omit the prompt, so every end user behind one virtual key
shares a bucket and can be served another user's semantically similar response.
Add an opt-in cache_params.semantic_cache_scope (key | end_user) that appends the
authenticated end-user id to the tenant scope, read from metadata and
litellm_metadata so /v1/chat/completions, /v1/responses and /v1/messages are all
covered, falling back to the key scope when no end-user id is present. Expose the
setting in the cache settings API and the Admin UI cache settings form

Co-authored-by: yassin <yassin@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 16db51e2cf)
2026-10-01 22:01:11 -07:00
yuneng-jiang
dd2f80fdc3
Merge pull request #43821 from BerriAI/litellm_sync_stable_1_100_x
chore(release): sync stable/1.100.x to v1.100.4
2026-09-30 10:59:40 -07:00
yuneng-jiang
883282fb72
Merge pull request #10 from BerriAI/litellm_session_token_1_100_x
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context (stable/1.100.x)
2026-09-29 15:39:06 -07:00
Yuneng Jiang
241abaec79
chore(lint): scope a TRY004 suppression to the bearer-token salt key check
This line's ruff strict budget has no headroom for the one TRY004 the
backport adds; the raise reports missing configuration, not a bad type.
2026-09-29 15:34:34 -07:00
Yuneng Jiang
f7cd90f09e
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context
Backport of BerriAI/litellm-private#5 (12981f93d3) onto stable/1.100.x, applied as
the PR's net diff so main-only intermediate refactors stay out.

The dashboard and lite CLI SSO specs under tests/e2e/ui/oidc are left out
because this line has no OIDC e2e harness to run them.
2026-09-29 15:17:24 -07:00
yuneng-jiang
bdff5cb30c
Merge pull request #9 from BerriAI/litellm_bump_1_100_4
chore: bump litellm 1.100.3 -> 1.100.4
2026-09-28 17:05:44 -07:00
Yuneng Jiang
cd6eb1099f
bump: litellm 1.100.3 -> 1.100.4 2026-09-28 15:08:09 -07:00
yuneng-jiang
385266c14d
Merge pull request #43132 from BerriAI/litellm_backport_1_100_x_gpt6_budget_0924
chore(release): backport #39631, #39729, #40639 to stable/1.100.x and cut 1.100.3
2026-09-24 22:29:19 -07:00
Yuneng Jiang
04fcee8ff1
chore: refresh uv.lock for 1.100.3 2026-09-24 20:39:38 -07:00
Yuneng Jiang
5651c5a008
bump: version 1.100.2 → 1.100.3 2026-09-24 20:39:38 -07:00
Yuneng Jiang
78be1b7303
chore(deps): bump soupsieve to 2.9 2026-09-24 20:39:00 -07:00
Yuneng Jiang
559dce5c83
chore(deps): bump pypdf to 6.16.1 2026-09-24 20:39:00 -07:00
Yuneng Jiang
c18d0307da
chore(deps): bump tornado to 6.5.8 2026-09-24 20:39:00 -07:00
Yuneng Jiang
b830735f56
chore(deps): bump gitpython to 3.1.60 2026-09-24 20:39:00 -07:00
Yuneng Jiang
c8bc09ea51
chore(deps): bump anyio to 4.14.2 2026-09-24 20:39:00 -07:00
ryan-crabbe-berri
6b103ed064
fix(reset_budget_job): reset end users by budget link, not by user id (#40639)
Adapted for stable/1.100.x: added Final to the test module's typing import; upstream's test file already imported it.

(cherry picked from commit 8a4fae0e17)
2026-09-24 20:39:00 -07:00
amasen02
bc9712f045
fix(proxy): invalidate end-user spend counter and cache on budget reset (#39726)
Adapted for stable/1.100.x: reflowed one generator to this line's ruff format (upstream reformatted it in a later style commit).

Signed-off-by: amasen02 <amasen02@users.noreply.github.com>
(cherry picked from commit daced81f20)
2026-09-24 20:39:00 -07:00
Mateo Wang
b68fcee3ca
fix: treat gpt-6 names as the gpt-5 request family in OpenAI and Azure configs (#39631)
Adapted for stable/1.100.x: import-context conflict only (upstream's neighbouring custom_tools import is not on this line); the added and removed lines are identical to upstream.

(cherry picked from commit 025a3ca42f)
2026-09-24 20:38:59 -07:00
Mateo Wang
9c1216a427
Merge pull request #42597 from BerriAI/litellm_cherrypick_1_100_x
feat(typesafe): backport #41607 to stable/1.100.x for v1.100.2
2026-09-22 20:01:40 -07:00
mateo-berri
1ebc488f07 feat(typesafe): add TypeSafe Jev passthrough with logging and cost tracking
Backport of #41607 to stable/1.100.x.
Cherry-picked from deb9d8aedd (main).

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-22 21:34:24 +00:00
Mateo Wang
35f5b7c1b3
Merge pull request #42532 from BerriAI/litellm_cherrypick_safeguards_1_100_x
fix(anthropic): backport #42152 and #42288 to stable/1.100.x for v1.100.2
2026-09-22 14:29:28 -07:00
kerry
4438739b46 fix(test): run the all-beta-headers bedrock cases on Claude Fable 5.1
Backport of #42048 to stable/1.100.x.
Cherry-picked from 7966f50c34 (main). The safeguards backport maps the dangerous-tool-use-2026-09-03 beta for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock cases run on Claude Fable 5.1 as they do on main.
2026-09-22 12:55:12 -07:00
mateo-berri
8ccfd6a84e chore(types): keep the backported safeguards annotations within the line's budgets
The picked TypedDict fields use read-only Sequence[Mapping[str, object]] annotations and the picked Vertex test carries a test-quality-ok marker, so stable/1.100.x's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change.
2026-09-22 11:42:39 -07:00
mateo-berri
eb23cee8ff test: add the local_beta_headers_config fixture the safeguards tests use
Hand-ported to stable/1.100.x from 47b2479c94 on main (fix(bedrock): gate Invoke tool search on the model map's supports_tool_search flag), the one prerequisite the #42288 handler tests need; the rest of that commit stays on main.
2026-09-22 10:38:07 -07:00
mateo-berri
0d95fba73c fix(anthropic): forward Claude Code safeguards and dangerous-tool-use beta to Bedrock Invoke and Vertex on /v1/messages
Backport of #42288 to stable/1.100.x.
Cherry-picked from merge commit fc82f6e8fa (litellm_safeguards_bedrock_vertex_messages).
The line has no bedrock_mantle beta-header mapping and no Mantle /v1/messages route, so the Mantle mapping, its test file, and the bedrock_mantle test parameter are left out.
2026-09-22 10:16:54 -07:00