Commit graph

48791 commits

Author SHA1 Message Date
Yuneng Jiang
b85766d4e4
bump: version 1.102.2 → 1.102.3 2026-10-05 18:54:26 -07:00
Yuneng Jiang
355e3cb5a3
chore(deps): bump source-map-js and smol-toml in the dashboard lockfile 2026-10-05 18:52:50 -07:00
Yuneng Jiang
6c0106db5b
chore(deps): bump next, moment and brace-expansion in the dashboard 2026-10-05 18:52:50 -07:00
Yuneng Jiang
9c62fc8aa3
chore(deps): bump werkzeug to 3.1.9 2026-10-05 18:51:06 -07:00
Yuneng Jiang
f0ae177dca
chore(deps): bump multidict to 6.9.1 2026-10-05 18:51:06 -07:00
Yuneng Jiang
1bfe9d6883
chore(deps): bump mako to 1.4.2 2026-10-05 18:51:05 -07:00
Yuneng Jiang
c474132e8a
chore(deps): bump langgraph-sdk to 0.4.4 2026-10-05 18:51:04 -07:00
Yuneng Jiang
b7b7cfea19
chore(deps): bump oauthlib to 4.0.0 2026-10-05 18:51:04 -07:00
Yuneng Jiang
9a170f0834
chore(deps): bump gitpython to 3.1.62 2026-10-05 18:51:03 -07:00
Yuneng Jiang
4a7212d329
chore(deps): bump fsspec to 2026.6.0 2026-10-05 18:51:03 -07:00
Yuneng Jiang
3b24b4c146
chore(deps): bump tornado to 6.5.9 2026-10-05 18:51:02 -07:00
Yuneng Jiang
9f9aca4655
chore(deps): bump urllib3 to 2.8.0 2026-10-05 18:51:01 -07:00
Yuneng Jiang
6d5cb46eae
chore(deps): bump pypdf to 6.19.0 2026-10-05 18:51:01 -07:00
Yuneng Jiang
c2c339390d
chore(deps): bump pyjwt to 2.15.0 2026-10-05 18:51:00 -07:00
yuneng-jiang
15448f30b3
Merge pull request #43823 from BerriAI/litellm_sync_stable_1_102_x
Some checks failed
ai-gateway image / ai-gateway release image (push) Has been cancelled
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
chore(release): sync stable/1.102.x to v1.102.2
2026-09-30 10:59:56 -07:00
yuneng-jiang
a0c4a3347a
Merge pull request #12 from BerriAI/litellm_session_token_1_102_x
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context (stable/1.102.x)
2026-09-29 15:39:18 -07:00
Yuneng Jiang
02a0dc1480
chore(lint): scope a TRY004 suppression to the bearer-token salt key check
This line's ruff strict budget has no headroom for the one TRY004 the
backport adds; the raise reports missing configuration, not a bad type.
2026-09-29 15:34:34 -07:00
Yuneng Jiang
1d5fdc87fe
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context
Backport of BerriAI/litellm-private#5 (12981f93d3) onto stable/1.102.x, applied as
the PR's net diff so main-only intermediate refactors stay out.

The dashboard and lite CLI SSO specs under tests/e2e/ui/oidc are left out
because this line has no OIDC e2e harness to run them.
2026-09-29 15:17:24 -07:00
yuneng-jiang
5f8561bdc2
Merge pull request #7 from BerriAI/litellm_bump_1_102_2
chore: bump litellm 1.102.1 -> 1.102.2
2026-09-28 17:06:17 -07:00
Yuneng Jiang
fec5028abf
bump: litellm 1.102.1 -> 1.102.2 2026-09-28 15:07:47 -07:00
Mateo Wang
d09bbae1c6
Merge pull request #42618 from BerriAI/litellm_backport_stable_1_102_x_realtime_otel
Some checks failed
ai-gateway image / ai-gateway release image (push) Has been cancelled
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
chore(release): backport #42388 and #41462 to stable/1.102.x
2026-09-22 20:04:11 -07:00
Mateo Wang
188c9d1f9f
Merge pull request #42595 from BerriAI/litellm_cherrypick_1_102_x
feat(typesafe): backport the jev change set to stable/1.102.x for v1.102.1
2026-09-22 20:01:25 -07:00
mateo-berri
d1cd2dccaf chore(backport): regenerate the openapi snapshot and dashboard api types for stable/1.102.x
The committed schema.d.ts and lazy OpenAPI snapshot were taken verbatim from main by the #41615 and #41757 picks, so they described classifier types, routing causes, and a guardrail that this line does not ship and lacked the /auto_router/manage permission. Regenerated under Python 3.12, the interpreter the check-ui-api-types workflow uses.
2026-09-22 19:13:48 -07:00
mateo-berri
5aa45f1bca test(realtime): drop legacy InvalidStatusCode tests and pin websockets imports
The two redaction tests raised the deprecated InvalidStatusCode, which the
websockets 15 asyncio client never raises, and asserted the raw 403 close
code that the handshake refusal path replaced with 1008. The refusal path
builds its close reason from the status code alone, so there is no secret
to redact there, and the handshake refusal tests already cover the error
event and the 1008 close.

Those refusal tests only passed when run after a sibling test had imported
websockets.asyncio.client, since websockets lazy-loads its exceptions
submodule. Importing InvalidStatus, Response, and Headers from their own
submodules makes them pass in any order.

(cherry picked from commit 54dbe8eb9a)
2026-09-23 00:46:03 +00:00
mateo-berri
4bfac88281 fix(ui): adapt the jev dashboard pieces to stable/1.102.x 2026-09-22 17:40:03 -07:00
yuneng
da246e9282 chore(deps): bump anyio to 4.14.2 and soupsieve to 2.9.0
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-22 23:03:52 +00:00
Yassin Kortam
9a46f1f53e Merge pull request #41462 from BerriAI/litellm_otel_promote_nested_request_metadata_keys
feat(otel): promote nested request metadata keys to litellm.metadata.* span attributes

(cherry picked from commit 79fc5153d3)
2026-09-22 23:02:58 +00:00
devin-ai-integration[bot]
96e7739dcb fix(realtime): surface an upstream handshake refusal as an error event and policy close (#42388)
* fix(realtime): surface an upstream handshake refusal as an error event and policy close

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(realtime): tidy the handshake refusal e2e

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(realtime): keep upstream exception text out of the Azure client error

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor(realtime): map handshake refusal close codes with a lookup

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 2bab39e374)
2026-09-22 23:02:53 +00:00
devin-ai-integration[bot]
d0687347a7 feat(openrouter): price typesafe/jev-1.13 and add an openrouter decisions pass-through (#42301)
Backport of #42301 to stable/1.102.x.
Cherry-picked from 1106b16745 (main).
2026-09-22 22:49:10 +00:00
moe-berri
e20cfbeaeb feat(auto-router): add JEV classifier alongside LLM classifier
Backport of #41886 to stable/1.102.x.
Cherry-picked from a83773cfa5 (main).
2026-09-22 22:49:10 +00:00
moe-berri
92a2a2f924 fix(proxy): enforce virtual key budgets for JEV test routing
Backport of #41879 to stable/1.102.x.
Cherry-picked from 1e161f516c (main).
2026-09-22 22:49:10 +00:00
Yassin Kortam
4b0ffcdf41 feat(guardrails): add TypeSafe Jev relevance-based compaction guardrail
Backport of #41757 to stable/1.102.x.
Cherry-picked from 2edda5aec3 (main).
2026-09-22 22:49:10 +00:00
yuneng-jiang
79b72b8594 fix(proxy): forward every method on the typesafe pass-through route
Backport of #41723 to stable/1.102.x.
Cherry-picked from 34718f0da6 (main).
2026-09-22 22:49:10 +00:00
Mateo Wang
b5ac61374e feat(router): add TypeSafe Jev as a complexity router classifier
Backport of #41615 to stable/1.102.x.
Cherry-picked from cf42b607c3 (main).
2026-09-22 22:49:10 +00:00
Tin Chi Lo
1a3cec8f5e feat(auto-router): allow opted-in team members to manage their routers
Prerequisite for #41615 and #41879 on stable/1.102.x.
Cherry-picked from 109ca70f66 (main).
2026-09-22 22:49:10 +00:00
mateo-berri
3b483c80f6 feat(typesafe): add TypeSafe Jev passthrough with logging and cost tracking
Backport of #41607 to stable/1.102.x.
Cherry-picked from deb9d8aedd (main).

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-22 21:34:24 +00:00
Mateo Wang
89000e402f
Merge pull request #42538 from BerriAI/litellm_cherrypick_safeguards_1_102_x
fix(anthropic): backport #42152 and #42288 to stable/1.102.x for v1.102.1
2026-09-22 14:29:04 -07:00
kerry
0fee6fcc76 fix(test): run the all-beta-headers bedrock cases on Claude Fable 5.1
Backport of #42048 to stable/1.102.x.
Cherry-picked from 7966f50c34 (main). The safeguards backport maps the dangerous-tool-use-2026-09-03 beta for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock cases run on Claude Fable 5.1 as they do on main.
2026-09-22 12:54:44 -07:00
mateo-berri
712428eded chore(types): keep the backported safeguards annotations within the line's budgets
The picked TypedDict fields use read-only Sequence[Mapping[str, object]] annotations and the picked Vertex test carries a test-quality-ok marker, so stable/1.102.x's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change.
2026-09-22 12:18:27 -07:00
mateo-berri
4f4ed1121a bump: version 1.102.1 2026-09-22 10:46:02 -07:00
mateo-berri
60c019166a test: add the local_beta_headers_config fixture the safeguards tests use
Hand-ported to stable/1.102.x from 47b2479c94 on main (fix(bedrock): gate Invoke tool search on the model map's supports_tool_search flag), the one prerequisite the #42288 handler tests need; the rest of that commit stays on main.
2026-09-22 10:45:59 -07:00
mateo-berri
b6f77c32b5 fix(anthropic): forward Claude Code safeguards and dangerous-tool-use beta to Bedrock Invoke and Vertex on /v1/messages
Backport of #42288 to stable/1.102.x.
Cherry-picked from merge commit fc82f6e8fa (litellm_safeguards_bedrock_vertex_messages).
The line has no bedrock_mantle beta-header mapping and no Mantle /v1/messages route, so the Mantle mapping, its test file, and the bedrock_mantle test parameter are left out.
2026-09-22 10:45:57 -07:00
yassin
e714ab4b20 fix(anthropic): forward safeguards and anthropic-beta unchanged on native /v1/messages
Backport of #42152 to stable/1.102.x.
Cherry-picked from merge commit e912ebe999 (litellm_claude_code_safeguards_passthrough).
2026-09-22 10:38:43 -07:00
yuneng-jiang
95293834e8
Merge pull request #42059 from BerriAI/litellm_backport_42053_rc_1_102_0
test(e2e): backport the Nova Sonic nova-2-sonic model fix to rc/1.102.0
2026-09-19 17:36:17 -07:00
Yuneng Jiang
64db6e1d3b
test(e2e): cite the source and date for the pinned Nova Sonic model id
AGENTS.md allows a vendor-owned literal only when its source and date are cited
next to it. A live realtime test cannot avoid naming a model, so record how the
id was checked, and record that a retired id fails as a hang rather than an
error so the next reader does not start by suspecting litellm.

(cherry picked from commit 9f84382a24)
2026-09-19 17:32:32 -07:00
Yuneng Jiang
c48532e21b
test(e2e): point the Nova Sonic realtime test at nova-2-sonic
AWS retired amazon.nova-sonic-v1:0. GetFoundationModel now answers
ResourceNotFoundException "This model version has reached the end of its life",
and opening a bidirectional stream against it fails with ValidationException
"The provided model identifier is invalid". amazon.nova-2-sonic-v1:0 is the
active replacement.

The test passed on builds 219 (2026-09-16) and 246 (2026-09-17) and has failed
every run since, three attempts per build, with no litellm change to the
realtime path in between. The symptom was a clean websocket close: Bedrock ends
the stream rather than erroring, the forwarder treats a None receive as a normal
stream end and closes the client socket, so the client sees ConnectionClosedOK
and the test fails waiting for response.done.

litellm already carries both models in the cost map, with
"deprecation_date": "2026-09-14" on the old one, and the promptStart
transformation already sends the audioOutputConfiguration that nova-2-sonic
requires; only the test constant was left behind.

Verified against live Bedrock with the promptStart shape the transformation
builds: amazon.nova-sonic-v1:0 raises "The provided model identifier is
invalid", amazon.nova-2-sonic-v1:0 opens a session and returns a usageEvent.

The mocked handler and provider-cache tests keep the old id: it is only a label
there, no call reaches AWS.

(cherry picked from commit ca18755b64)
2026-09-19 17:32:31 -07:00
Mateo Wang
eebb3cb17d
Merge pull request #41935 from BerriAI/litellm_backport_41347_rc_1_102_0
Some checks failed
ai-gateway image / ai-gateway release image (push) Has been cancelled
fix(team): apply team_member_budget updates to members still on the team default (backport of #41347 to rc/1.102.0)
2026-09-19 00:01:54 -07:00
mateo-berri
868052b1ac fix(team): apply team_member_budget updates to members still on the team default
Backport of #41347 to rc/1.102.0.
Cherry-picked from merge commit 4bb1ae115b (main), originally by app/devin-ai-integration.

Conflicts: main's #41349 (membership rows written through upsert) is not on this line, so add_new_member keeps its create call and still writes no membership row when no budget resolves. The picked tests are adapted to that and to this line's _check_team_member_budget, which loads the membership itself.
2026-09-18 23:18:38 -07:00
Mateo Wang
1a993c3d28
Merge pull request #41854 from BerriAI/litellm_backport_stable_batch_rc_1_102_0
Some checks failed
ai-gateway image / ai-gateway release image (push) Waiting to run
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
fix: backport eight backport-stable fixes to rc/1.102.0 (#40596, #41046, #41086, #41171, #41178, #41283, #41495, #41689)
2026-09-18 12:16:09 -07:00
mateo-berri
3a7a204b9b fix(responses): keep the addressed response id off bridged provider requests
Backport of #41689 to rc/1.102.0.
Cherry-picked from merge commit 07b5051c0d (main), originally by app/devin-ai-integration.

Both conflicts were in test files: the rc line lacks the Codex additional_tools tests that sit next to the new test in test_handler.py on main, and its test_utils.py imports all_litellm_params on a separate line, so only this PR's own additions (the imports, the recording handler, and the two new tests) are taken.
2026-09-18 11:15:56 -07:00