Commit graph

31986 commits

Author SHA1 Message Date
Alexsander Hamir
79296baabc fix: address security scan failures (Node, orjson, diff)
- Pin Node to 24.13.0 (nodejs-24-24.13.0-r0) in Dockerfile and
  Dockerfile.database to fix Node CVEs (CVE-2025-55130, etc.)
- Upgrade orjson to 3.11.7 in requirements.txt (CVE-2025-67221)
- Add npm override for diff>=8.0.3 in litellm-dashboard (GHSA-73rr-hh4g-fpgx)
- Remove Node CVEs from .grype.yaml and security_scans.sh allowlist;
  keep Python 3.13 / zlib ignores (no fix in Wolfi yet)
2026-02-10 12:37:15 -08:00
Alexsander Hamir
7df89930b4 fix: resolve bedrock base model to cost map key in test_get_model_info_bedrock_models
get_base_model() returns model id without 'bedrock/' prefix; cost map
keys use 'bedrock/<model>'. Resolve base_model to actual key (try
base_model then bedrock/base_model) and skip when not in map to fix
KeyError for moonshotai.kimi-k2-thinking.
2026-02-10 12:06:49 -08:00
Alexsander Hamir
ebd4f3d947 test: pass dummy api_key for AIML mocked test so validate_environment passes; add flaky(retries=0) 2026-02-10 11:41:15 -08:00
Alexsander Hamir
ca7c74e358 test: use mocked HTTP for AIML image generation test (no API key/credits needed) 2026-02-10 11:34:02 -08:00
Alexsander Hamir
e3b070ea83 test: fix schema and env override tests - add supports_preset to model prices schema; use LITELLM_MAX_CALLBACKS for MAX_CALLBACKS override test 2026-02-10 11:09:34 -08:00
Alexsander Hamir
9b9926bb59 test: ignore metadata.additional_usage_values.speed in spend logs payload comparison 2026-02-10 11:04:44 -08:00
Alexsander Hamir
6019afb644 bump: version 1.81.9 → 1.81.10 2026-02-10 11:01:27 -08:00
Alexsander Hamir
af0617cce8 Document envs 2026-02-10 10:47:06 -08:00
Alexsander Hamir
3c0a10f05a fix: prefix OpenAI model with 'responses/' when thinking is enabled
- Add model prefixing to route OpenAI thinking requests to Responses API
- Fixes test failure where model should be 'responses/gpt-5.2' instead of 'gpt-5.2'
- Ensures OpenAI models with thinking parameter use Responses API for reasoning summary
- Prevents double-prefixing with existing 'responses/' check
2026-02-10 10:42:53 -08:00
Alexsander Hamir
c15632d626 fix: add safeguards to _convert_to_json_serializable_dict to prevent infinite recursion
- Add max_depth parameter (default 20) to prevent infinite recursion
- Add circular reference protection using visited set
- Add function to recursive_detector ignore list with proper safeguards
- Fixes CPU usage spikes caused by unguarded recursive function
2026-02-10 10:36:51 -08:00
Alexsander Hamir
205b08703b fix: resolve test failures - budget mock_table and MCP openapi async
- test_budget_endpoints: define mock_table in client_and_mocks fixture to fix NameError in 5 tests
- mcp_server_manager: make _register_openapi_tools async and use load_openapi_spec_async to avoid RuntimeError when called from running event loop; await in load_servers_from_config
- test_mcp_server_manager: await _register_openapi_tools in test_register_openapi_tools_includes_static_headers
2026-02-10 10:26:44 -08:00
Alexsander Hamir
16a678e9ba Revert "Bump litellm-proxy-extras to 0.4.34"
This reverts commit a096544f46.
2026-02-10 10:25:30 -08:00
Alexsander Hamir
5db3820a1d fix: authorize urllib3/filelock in liccheck, replace pkg_resources with packaging
- Add urllib3 (MIT) and filelock (Unlicense) to [Authorized Packages] in liccheck.ini
- Fix DeprecationWarning by using packaging.requirements.Requirement instead of pkg_resources
2026-02-10 10:24:19 -08:00
Alexsander Hamir
ddc590ab2e Merge branch 'litellm_release_day_02_10_2026' of https://github.com/BerriAI/litellm into litellm_release_day_02_10_2026 2026-02-10 10:23:33 -08:00
Alexsander Hamir
1eb53b3f03 Add canonical bedrock/moonshotai.kimi-k2-thinking to model cost map 2026-02-10 10:22:43 -08:00
Alexsander Hamir
a096544f46 Bump litellm-proxy-extras to 0.4.34 2026-02-10 09:56:04 -08:00
Alexsander Hamir
40e1baa7e0 fix(dashboard): import TeamMembersComponent from TeamMemberTab instead of missing team_member_view 2026-02-10 09:51:25 -08:00
Alexsander Hamir
8eeb3a39ff fix: remove duplicate PerplexityResponsesConfig key in lazy imports registry 2026-02-10 09:47:37 -08:00
Sameer Kankute
0f01802dde
Merge pull request #20845 from BerriAI/litellm_gemini_image_handling
Handle image in assitant message for gemini
2026-02-10 18:24:09 +05:30
Sameer Kankute
3de892b8ca
Merge pull request #20860 from BerriAI/litellm_perplexity_research_api_support
[Feat] Perplexity research api support
2026-02-10 18:22:30 +05:30
Sameer Kankute
cdab87dec0
Merge pull request #20838 from BerriAI/litellm_managed_error_file
Add support managed error file
2026-02-10 18:20:26 +05:30
Sameer Kankute
f6228fda3e Fix mypy issues 2026-02-10 18:18:41 +05:30
Sameer Kankute
0b4c511576
Merge pull request #20863 from BerriAI/litellm_moonshotai.kimi-k2.5
Add moonshotai.kimi-k2.5
2026-02-10 18:12:36 +05:30
Sameer Kankute
7166ca8c59 Add moonshotai.kimi-k2.5 2026-02-10 18:10:37 +05:30
Sameer Kankute
63eedc26b0 Fix test_async_post_call_success_hook_for_unified_finetuning_job 2026-02-10 18:08:23 +05:30
Sameer Kankute
fda64caa28
Merge pull request #20855 from BerriAI/litellm_bedrock_kimi2
Add Kimi model pricing by region
2026-02-10 18:05:25 +05:30
Sameer Kankute
5222fd4795
Merge pull request #20783 from BerriAI/litellm_oss_staging_02_09_2026
litellm oss staging 09/02/2026
2026-02-10 18:02:14 +05:30
Sameer Kankute
45133fab53
Merge pull request #20854 from BerriAI/litellm_oss_staging_02_05_2026_3
Litellm oss staging 02 05 2026 3
2026-02-10 17:59:56 +05:30
Sameer Kankute
7d5141c28c Fix mypy issues 2026-02-10 17:58:15 +05:30
Sameer Kankute
19628f6187 Fix mypy issues 2026-02-10 17:52:17 +05:30
Sameer Kankute
f4ae6ed181 Fix mypy issues 2026-02-10 17:48:41 +05:30
Sameer Kankute
2eb52db3e9 Add documentation for perplexity 2026-02-10 17:44:00 +05:30
Sameer Kankute
9c1bf84729 Fix mypy issues 2026-02-10 17:41:03 +05:30
Sameer Kankute
ac65524d9f Use openai base config 2026-02-10 17:37:08 +05:30
Sameer Kankute
be0ebb153e Add perplexity response api routing 2026-02-10 17:01:08 +05:30
Sameer Kankute
849d6b7cdb Add perplexity response api class 2026-02-10 17:00:49 +05:30
Sameer Kankute
8663ec8610 Add Kimi model pricing by region 2026-02-10 16:43:32 +05:30
Seongho Bae
d56a0a97f8 fix(ui): allow editing MCP stdio transport config (#20241)
* fix(ui): enable stdio transport edits for MCP servers

* fix(ui): use antd Input in MCP edit stdio

Align MCP Server Edit with UI guidelines by replacing deprecated Tremor TextInput, and relax stdio args validation to match create flow while improving test stability.

* fix(otel): make semantic log LogRecord import mypy-safe

Prefer the OTEL >=1.39.0 LogRecord import path and keep an ignored fallback for older versions so MyPy doesn't fail on newer SDK stubs.

* fix(otel): tolerate LogRecord ctor changes across SDK versions

Create semantic LogRecords via a best-effort wrapper that falls back when the `resource` kwarg is unsupported (OTEL >= 1.39), and avoid MyPy overload/no-redef failures.

* fix(otel): silence mypy no-redef on versioned LogRecord import

MyPy sees both branches of the version-compat import and flags a redefinition. Ignore no-redef on the legacy import path to keep CI passing.

* fix(ui): ensure mcp_info.server_name is always populated

When using stdio transport there may be no URL to fall back on; prefer existing server_name/url/alias to avoid sending an empty mcp_info.server_name on update.

* chore(otel): format opentelemetry; ignore ui export output

* fix: guard optional a2a resolver + make OTEL semantic logs mypy-safe

* chore: format A2A resolver and OTEL semantic logs

* fix: address review feedback for MCP stdio edit

* fix: keep MCP stdio edit PR scoped

* fix(otel): make semantic logs mypy-safe
2026-02-10 16:16:59 +05:30
milan-berri
aa3325c1d5 fix: map global location to us-central1 for vertex's claude models count_tokens endpoint (#20348)
* fix: map global location to us-east5 for Claude count_tokens endpoint

- Vertex AI doesn't support count_tokens endpoint for Claude models with global location
- Map global -> us-east5 for count_tokens only, keeping global for inference
- Fixes 404 error when calling count_tokens with vertex_location: global
- Reference: https://docs.cloud.google.com/vertex-ai/generative-ai/docs/partner-models/claude/count-tokens

* Update handler.py
2026-02-10 16:13:45 +05:30
Harshit Jain
dfbc0e2156 fix:Parse embedded JSON in the message field of logs (#20366)
* fix:Parse embedded JSON in the message field of logs

* Update litellm/_logging.py

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

---------

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-10 16:13:33 +05:30
Neha Prasad
def910b086 fix: Sanitize empty text content blocks for databricks provider (#20384)
* fix(databricks): sanitize empty text content blocks for Anthropic Messages API

* test(databricks): add tests for empty content block sanitization
2026-02-10 16:12:57 +05:30
Shivam Rawat
90cd6538d4 added functionality to propagate bedrock guardrail errors down to litellm (#20395) 2026-02-10 16:12:13 +05:30
Seongho Bae
eb39582547 fix(proxy): allow safe MCP server discovery for virtual keys (#20421) 2026-02-10 16:10:18 +05:30
Lei Nie
08824f9912 [Bug] Fix missing image_tokens in Responses API output_tokens_details (#20404)
When transforming chat completion responses to Responses API format,
image_tokens from completion_tokens_details was not being included
in output_tokens_details. This affected Vertex AI/Gemini models that
return image token counts in candidatesTokensDetails with modality="IMAGE".

The fix adds image_tokens handling alongside existing reasoning_tokens
and text_tokens transformation.
2026-02-10 16:10:07 +05:30
Sameer Kankute
fc9cf1c870 Fix indentation error 2026-02-10 16:03:18 +05:30
Emerson Gomes
28e15f4fd6 fix(responses): preserve cached tool call objects in tool result recovery (#20700)
* fix(responses): preserve cached tool call objects in tool result recovery

* fix(responses): support attr-based cached tool call recovery

* Update litellm/responses/litellm_completion_transformation/transformation.py

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

---------

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-10 16:00:36 +05:30
Neel Harsola
4256c547c2 fix(bedrock): handle concatenated JSON in tool call arguments (#20742)
* fix(responses): preserve streamed tool deltas when id is omitted

* fix(responses): guard ambiguous tool-call index reuse

* add missing indexes on VerificationToken table

* fix(bedrock): handle concatenated JSON in tool call arguments

When using Bedrock Claude Sonnet 4.5 with tools enabled, the model
sometimes returns multiple tool call arguments as concatenated JSON
objects in a single arguments string, e.g.
  '{"command":["curl",...]}{"command":["curl",...]}{"command":["curl",...]}'

json.loads() fails on this with "Extra data", crashing the entire
request in _convert_to_bedrock_tool_call_invoke.

This commit:
- Adds split_concatenated_json_objects() helper in common_utils.py
  that uses json.JSONDecoder.raw_decode() to walk a string and extract
  each JSON object individually.
- Updates _convert_to_bedrock_tool_call_invoke() to catch JSONDecodeError
  and attempt splitting concatenated objects into separate Bedrock
  toolUse blocks (first block keeps original ID, subsequent blocks get
  suffixed IDs).
- Fixes duplicate json.loads calls and a shadowed 'id' builtin.
- Adds 12 unit tests covering normal, empty, concatenated, and edge cases.

Fixes #20543

---------

Co-authored-by: Emerson Gomes <emerson.gomes@thalesgroup.com>
Co-authored-by: Sameer Kankute <sameer@berri.ai>
Co-authored-by: Carlo Alberto Ferraris <cafxx@mercari.com>
2026-02-10 16:00:36 +05:30
moophlo
96206ec141 mcp: support http(s) URLs for spec_path in OpenAPI MCP loader (#20753)
* fix(responses): preserve streamed tool deltas when id is omitted

* fix(responses): guard ambiguous tool-call index reuse

* add missing indexes on VerificationToken table

* mcp: support http(s) URLs for spec_path in OpenAPI MCP loader

* test(mcp): add unit test for OpenAPI spec_path URL support

* Fix OpenAPI spec URL loading to use shared MCP httpx client

Ensure URL-based OpenAPI loading honors LiteLLM’s custom httpx configuration, add missing imports, and harden tests to prevent regressions or accidental direct httpx usage.

* removed unused import urlparse

* removed unsupported timeout argument

---------

Co-authored-by: Emerson Gomes <emerson.gomes@thalesgroup.com>
Co-authored-by: Sameer Kankute <sameer@berri.ai>
Co-authored-by: Carlo Alberto Ferraris <cafxx@mercari.com>
Co-authored-by: Andrea Odorisio <Andrea@BR-FHH9MWDQ2PMAC.local>
2026-02-10 16:00:36 +05:30
Rohith sai
59c81a30a0 fix(anthropic): route thinking requests through OpenAI responses (#20755)
* fix(anthropic): route thinking requests through OpenAI responses

* Apply suggestion from @greptile-apps[bot]

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

---------

Co-authored-by: Krish Dholakia <krrishdholakia@gmail.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-02-10 16:00:36 +05:30
Zero Clover
7f89508806 fix(sso): handle opaque access tokens in process_sso_jwt_access_token (#20726)
OIDC providers like Logto may return opaque (non-JWT) access tokens,
which caused jwt.decode() to raise DecodeError and crash the SSO
callback with a 500 error. Catch DecodeError and skip JWT-based
extraction gracefully, since user info is already available from
the UserInfo endpoint.

Fixes #20724
2026-02-10 16:00:36 +05:30