Commit graph

36593 commits

Author SHA1 Message Date
user
51273a3ad3
build: refresh uv lock after upstream merge 2026-04-03 21:24:11 +00:00
user
0e9e203a7d
Merge remote-tracking branch 'upstream/main' into feat/uv-migration 2026-04-03 21:23:56 +00:00
user
da422f8ead
build: restore runtime deps moved into ci 2026-04-03 21:20:35 +00:00
user
fb114e5efc
test: run local proxy checks through uv python 2026-04-03 21:02:38 +00:00
ishaan-berri
fc885af994
docs(blog): add security hardening April 2026 post (#25101) (#25102) 2026-04-03 13:06:14 -07:00
user
1911a4c5c8
docker: preserve prisma cache across stages 2026-04-03 18:06:42 +00:00
user
448008080d
fix: keep psycopg binary in default test env 2026-04-03 07:10:24 +00:00
user
06d0ec1228
ci: persist uv path across circleci steps 2026-04-03 06:15:33 +00:00
user
861b4c667e
fix: restore proxy extras parity and venv migrations 2026-04-03 05:45:01 +00:00
mubashir1osmani
d4a3a5e530
fix gpt-5.4 pricing (#24748) 2026-04-02 21:51:21 -07:00
yuneng-jiang
50f4fdea3e
bump: version 1.83.0 → 1.83.1 (#25054) 2026-04-02 21:43:42 -07:00
michelligabriele
a6dfd02610
fix(guardrails): return HTTP 400 instead of 500 for Model Armor streaming blocks (#24693)
When Model Armor blocks a streaming response, it correctly raises
HTTPException(status_code=400) but create_response() catches it with a
bare except Exception and hardcodes a 500 response, discarding the
original status code.

Fix create_response() to preserve status_code from HTTPException instead
of hardcoding 500. Also update Model Armor's streaming hook to yield an
SSE error event instead of raising (matching the Prisma Airs pattern),
and fix make_model_armor_request() to return 400 for upstream API
failures instead of passing through the upstream status code.
2026-04-02 21:28:52 -07:00
Marty Sullivan
52a596d2a4
Bedrock Model Updates 2026-03-26 (#24645)
* add new bedrock models & remove duplicate vertexai entry

* adding non-regional entry for minimax-2.5
2026-04-02 21:26:04 -07:00
ishaan-berri
1e5b79d887
[Bedrock] Fix Anthropic file_id support - async path + document URL→base64 + beta header filtering (#25047) (#25050)
Co-authored-by: Ishaan Jaffer <ishaanjaffer0324@gmail.com>
2026-04-02 21:13:56 -07:00
Joe Reyna
ee3e848ded
allow hashed token_id in /key/update endpoint (#24969) 2026-04-02 21:13:33 -07:00
user
89df6c0907
Merge upstream/main into feat/uv-migration 2026-04-03 04:00:13 +00:00
user
78182a9418
fix: restore proxy runtime build parity 2026-04-03 03:48:48 +00:00
user
eb199c9c8f
fix: restore published docker and license coverage 2026-04-03 03:03:08 +00:00
yuneng-jiang
4094801b3c
Merge pull request #25037 from BerriAI/litellm_fix_non_root_docker_build
[Fix] Dockerfile.non_root: install node-gyp for npm ci
2026-04-02 17:52:27 -07:00
Yuneng Jiang
d4813a2a0f
adding poetry lock 2026-04-02 17:31:16 -07:00
Yuneng Jiang
fa629c307c
[Fix] Dockerfile.non_root: install node-gyp for npm ci
The wolfi-base npm@11.12.1 package does not bundle node-gyp, causing
`npm ci` to fail with `Cannot find module 'node-gyp/bin/node-gyp.js'`
when building the Admin UI in the non-root Docker image.

Install node-gyp@12.2.0 globally and symlink it into npm's internal
node_modules where @npmcli/run-script expects to find it.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 17:29:47 -07:00
yuneng-jiang
3604b600d3
[Infra] Merge internal dev branch with main (#25036)
* fix(proxy): enforce key-level model allowlist for custom auth

custom_auth_run_common_checks only runs common_checks (team/user/project model checks).
Custom auth now also enforces key-level model restrictions via can_key_call_model.

Move the custom-auth key-access regression tests to test_user_api_key_auth.py and keep test_custom_auth_end_user_budget.py focused on end-user budget behavior.

Made-with: Cursor

* fix(proxy): gate custom-auth key model checks behind opt-in

Keep key-level model allowlist enforcement in custom auth behind `custom_auth_run_common_checks` to preserve backwards compatibility, and update tests to verify default non-enforcement and opt-in enforcement behavior.

Made-with: Cursor

* test(proxy): isolate custom auth default check from shared settings state

Patch `proxy_server.general_settings` to an empty dict in the default custom-auth key-access test so it remains deterministic under shared module state.

Made-with: Cursor

* test(proxy): strengthen custom auth post-check assertions

Tighten custom auth regression tests by asserting exact can_key_call_model args and remove an unused common_checks mock from the default behavior path.

Made-with: Cursor

* fix(agentcore): parse A2A JSON-RPC responses in AgentCore provider

* fix(prompt-templates): ensure_alternating_roles handles tool-call chains

* feat(auth): add JWT claim routing overrides for OAuth2 validation

Made-with: Cursor

* docs(auth): document JWT-to-OAuth2 routing overrides

Add generic docs for running JWT and OAuth2 together, including routing_overrides YAML examples and list-based selector behavior for iss/client_id/aud.

Made-with: Cursor

---------

Co-authored-by: Milan <milan@berri.ai>
Co-authored-by: michelligabriele <gabriele.michelli@icloud.com>
2026-04-02 16:38:01 -07:00
shin-berri
f11cdf7934
Merge pull request #25034 from BerriAI/extras_apr2
[Infra] Bump extras version
2026-04-02 16:18:10 -07:00
Yuneng Jiang
3ad953e75c
bump: version 0.4.62 → 0.4.63 2026-04-02 16:10:32 -07:00
David Chen
b7ccc5b691
[Test Fix] fix gov pricing tests (#25022)
* fix pricing tests

* fix mypy

* fix cost expectation since us based model is used now.

* fix test get model info
2026-04-02 15:55:55 -07:00
Krrish Dholakia
06df8edf92
docs: cleanup (#25026) 2026-04-02 15:18:24 -07:00
yuneng-jiang
9c5fda435f
Merge pull request #25023 from BerriAI/litellm_/fervent-noether
[Infra] Harden supply chain: remove unused scripts, add pip binary-only install
2026-04-02 14:49:09 -07:00
Yuneng Jiang
51af6fedb3
[Infra] Harden supply chain: remove unused scripts, add pip binary-only install
Remove ci_cd/publish-proxy-extras.sh (dead, unreferenced PyPI publish script)
and .pre-commit-config.yaml (pulls external repos from GitHub on git commit).
Add --only-binary :all: to scripts/install.sh to prevent execution of
malicious setup.py during pip install.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 14:13:57 -07:00
user
5cd691bee4
ci: increase matrix test timeout headroom 2026-04-02 21:11:56 +00:00
Krrish Dholakia
cae8613660
Announce April Townhall (#25021)
* fix: replace hardcoded url

* docs: announce april townhall
2026-04-02 14:10:49 -07:00
user
a1de99d3f5
fix: stabilize remaining uv migration CI checks 2026-04-02 20:44:07 +00:00
yuneng-jiang
068e6e2a9e
Merge pull request #24951 from BerriAI/litellm_remove_neon_cli
[Fix] Remove Neon CLI and Pin All JS Dependencies
2026-04-02 12:47:46 -07:00
user
070b3428bb
ci: fix circleci publish workflow parsing 2026-04-02 19:36:51 +00:00
user
9052f8e314
ci: fix circleci no-op command steps 2026-04-02 19:32:57 +00:00
user
68858d8d8e
test: cover sandbox executor requirements flow 2026-04-02 19:22:49 +00:00
user
35e001a380
test: isolate bedrock image request formatting from suite state 2026-04-02 17:36:38 +00:00
user
0a1af4eceb
build: pin uv tooling and health check deps 2026-04-02 09:27:27 +00:00
user
2e69326c9a
fix: keep release and health check images self-contained 2026-04-02 08:50:43 +00:00
user
a7c11356f4
test: harden test_litellm isolation 2026-04-02 08:23:33 +00:00
user
2ad24218d0
chore: align auxiliary scripts and tests with uv 2026-04-02 05:09:27 +00:00
user
1ef1c5a6dd
docs: update install and deployment guidance for uv 2026-04-02 04:57:08 +00:00
user
c124963812
docker: migrate image builds and runtime setup to uv 2026-04-02 04:56:48 +00:00
user
0c814c87e6
ci: move automation and local tooling to uv 2026-04-02 04:56:35 +00:00
user
e103d3dcc6
build: migrate packaging metadata to uv 2026-04-02 04:56:27 +00:00
David Chen
d1df4e838b
Litellm fix update bedrock models (#24947)
* update bedrock models in tests

* updated more tests and model_prices_and_context_window

* fix model id and pricing

* replace more sonnet models

* update tests

* git push

* update pricing

* flaky total cost

* monkey patch

* relax the cost change

* fix and revert some changes

* revert the pricing

* chore: move cost/pricing changes to bedrock-cost-fixes branch

* chore: split Bedrock file-api beta stripping to separate branch

Removes strip_unsupported_file_api_betas_for_bedrock_invoke from this branch;
see litellm_bedrock_invoke_strip_file_api_betas for that fix.

Made-with: Cursor
2026-04-01 19:22:54 -07:00
michelligabriele
adedae2cfa
fix(auth): enforce budget for models not in cost map (#24949)
* fix(auth): enforce budget for models not in cost map

* fix log injection in debug messages + isolate test global state
2026-04-01 19:10:30 -07:00
Yuneng Jiang
006d481025
[Fix] Remove neon CLI dependency and pin all JS dependencies
Remove @neondatabase/api-client and neonctl to address CVE-2026-25639
(axios supply chain vulnerability). Pin all JS dependencies to exact
versions across all package.json files to prevent future supply chain
attacks via semver range resolution.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 16:15:32 -07:00
yuneng-jiang
7250cba3db
Merge pull request #24905 from BerriAI/litellm_pin_pip_2
[Infra] Pin All Docker Build Dependencies
2026-04-01 15:05:25 -07:00
Yuneng Jiang
d038093562
add poetry lock 2026-04-01 14:28:15 -07:00
Yuneng Jiang
0fb5ab515d
[Fix] Revert cryptography to 43.0.3 in pyproject.toml for Python 3.9.0/3.9.1 compat
cryptography 46.0.5 excludes Python 3.9.0 and 3.9.1, which conflicts
with pyproject.toml's python = ">=3.9,<4.0" range. Docker still uses
46.0.5 via requirements.txt.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-01 14:27:51 -07:00