Unit Tests: Proxy DB Operations / proxy-db (auth-checks, tests/proxy_unit_tests/test_auth_checks.py tests/proxy_unit_tests/test_user_api_key_auth.py, 20, 8) (push) Has been cancelled
Unit Tests: Proxy DB Operations / proxy-db (remaining, tests/proxy_unit_tests --ignore=tests/proxy_unit_tests/test_key_generate_prisma.py --ignore=tests/proxy_unit_tests/test_auth_checks.py --ignore=tests/proxy_unit_tests/test_user_api_key_auth.py, 20, 8) (push) Has been cancelled
- Use with patch(): so mocks are active when get_secret() runs
- Patch HTTPHandler in main as fallback to avoid real httpx usage
- Fixes failures in CI (ConnectError / Google OIDC provider failed)
when decorator-based patches did not apply reliably
- test_oidc_azure_ad_token_success: use monkeypatch.delenv to force-unset
AZURE_FEDERATED_TOKEN_FILE so the Azure AD token provider path is always
exercised in CI (e.g. Azure Pipelines / GitHub Actions OIDC).
- test_video_content_handler_uses_get_for_openai: patch both
http_handler._get_httpx_client and llm_http_handler._get_httpx_client so
the mock is used regardless of import order / CI environment.
* feat(guardrail_hooks/): add guardrail logging to all unified guardrails
ensures unified guardrails use the 'log_guardrail_information' decorator for logging
* fix(custom_guardrail.py): don't log inputs on guardrail response - just emit state
* refactor: don't double log bedrock guardrail information
* feat: add in-product nudges for contributing + trying community custom code guardrails
allows users to contribute / share custom code guardrails
- Bump version in litellm-proxy-extras/pyproject.toml, pyproject.toml, requirements.txt
- Remove redundant 'cd litellm-proxy-extras' in Get new version and Publish to PyPI steps
(job already uses working_directory: ~/project/litellm-proxy-extras)
- Revert Dockerfile and Dockerfile.database to plain 'nodejs npm' (no pin, no apk update)
- Add Node CVEs and orjson/diff to .grype.yaml and security_scans.sh allowlist
- Keep orjson==3.11.7 in requirements.txt and diff>=8.0.3 override in package.json
(easy upgrades that do not change Docker image build)
- Pin Node to 24.13.0 (nodejs-24-24.13.0-r0) in Dockerfile and
Dockerfile.database to fix Node CVEs (CVE-2025-55130, etc.)
- Upgrade orjson to 3.11.7 in requirements.txt (CVE-2025-67221)
- Add npm override for diff>=8.0.3 in litellm-dashboard (GHSA-73rr-hh4g-fpgx)
- Remove Node CVEs from .grype.yaml and security_scans.sh allowlist;
keep Python 3.13 / zlib ignores (no fix in Wolfi yet)
get_base_model() returns model id without 'bedrock/' prefix; cost map
keys use 'bedrock/<model>'. Resolve base_model to actual key (try
base_model then bedrock/base_model) and skip when not in map to fix
KeyError for moonshotai.kimi-k2-thinking.
- Add model prefixing to route OpenAI thinking requests to Responses API
- Fixes test failure where model should be 'responses/gpt-5.2' instead of 'gpt-5.2'
- Ensures OpenAI models with thinking parameter use Responses API for reasoning summary
- Prevents double-prefixing with existing 'responses/' check
- Add max_depth parameter (default 20) to prevent infinite recursion
- Add circular reference protection using visited set
- Add function to recursive_detector ignore list with proper safeguards
- Fixes CPU usage spikes caused by unguarded recursive function
- test_budget_endpoints: define mock_table in client_and_mocks fixture to fix NameError in 5 tests
- mcp_server_manager: make _register_openapi_tools async and use load_openapi_spec_async to avoid RuntimeError when called from running event loop; await in load_servers_from_config
- test_mcp_server_manager: await _register_openapi_tools in test_register_openapi_tools_includes_static_headers
- Add urllib3 (MIT) and filelock (Unlicense) to [Authorized Packages] in liccheck.ini
- Fix DeprecationWarning by using packaging.requirements.Requirement instead of pkg_resources
* fix(aiohttp): respect ssl_verify with shared sessions
* fix(aiohttp): resolve mypy error for ssl parameter type
Pass ssl kwarg conditionally to aiohttp request() only when explicitly
configured, since None is not a valid value for the ssl parameter
(expected SSLContext | bool | Fingerprint).
When OpenTelemetry is configured via the UI, only OTEL_ENDPOINT and
OTEL_HEADERS are set, but OTEL_EXPORTER is not specified. This caused
the exporter to default to "console", meaning traces were printed to
stdout instead of being sent to the configured endpoint.
This fix adds logic in OpenTelemetryConfig.__post_init__ to automatically
infer "otlp_http" as the exporter when an endpoint is specified but the
exporter is still the default "console".
Fixes issue reported by Elastic team where traces weren't being sent
to their OTEL endpoint when configured through the LiteLLM UI.