- Bump version in litellm-proxy-extras/pyproject.toml, pyproject.toml, requirements.txt
- Remove redundant 'cd litellm-proxy-extras' in Get new version and Publish to PyPI steps
(job already uses working_directory: ~/project/litellm-proxy-extras)
- Revert Dockerfile and Dockerfile.database to plain 'nodejs npm' (no pin, no apk update)
- Add Node CVEs and orjson/diff to .grype.yaml and security_scans.sh allowlist
- Keep orjson==3.11.7 in requirements.txt and diff>=8.0.3 override in package.json
(easy upgrades that do not change Docker image build)
- Pin Node to 24.13.0 (nodejs-24-24.13.0-r0) in Dockerfile and
Dockerfile.database to fix Node CVEs (CVE-2025-55130, etc.)
- Upgrade orjson to 3.11.7 in requirements.txt (CVE-2025-67221)
- Add npm override for diff>=8.0.3 in litellm-dashboard (GHSA-73rr-hh4g-fpgx)
- Remove Node CVEs from .grype.yaml and security_scans.sh allowlist;
keep Python 3.13 / zlib ignores (no fix in Wolfi yet)
get_base_model() returns model id without 'bedrock/' prefix; cost map
keys use 'bedrock/<model>'. Resolve base_model to actual key (try
base_model then bedrock/base_model) and skip when not in map to fix
KeyError for moonshotai.kimi-k2-thinking.
- Add model prefixing to route OpenAI thinking requests to Responses API
- Fixes test failure where model should be 'responses/gpt-5.2' instead of 'gpt-5.2'
- Ensures OpenAI models with thinking parameter use Responses API for reasoning summary
- Prevents double-prefixing with existing 'responses/' check
- Add max_depth parameter (default 20) to prevent infinite recursion
- Add circular reference protection using visited set
- Add function to recursive_detector ignore list with proper safeguards
- Fixes CPU usage spikes caused by unguarded recursive function
- test_budget_endpoints: define mock_table in client_and_mocks fixture to fix NameError in 5 tests
- mcp_server_manager: make _register_openapi_tools async and use load_openapi_spec_async to avoid RuntimeError when called from running event loop; await in load_servers_from_config
- test_mcp_server_manager: await _register_openapi_tools in test_register_openapi_tools_includes_static_headers
- Add urllib3 (MIT) and filelock (Unlicense) to [Authorized Packages] in liccheck.ini
- Fix DeprecationWarning by using packaging.requirements.Requirement instead of pkg_resources
* fix(ui): enable stdio transport edits for MCP servers
* fix(ui): use antd Input in MCP edit stdio
Align MCP Server Edit with UI guidelines by replacing deprecated Tremor TextInput, and relax stdio args validation to match create flow while improving test stability.
* fix(otel): make semantic log LogRecord import mypy-safe
Prefer the OTEL >=1.39.0 LogRecord import path and keep an ignored fallback for older versions so MyPy doesn't fail on newer SDK stubs.
* fix(otel): tolerate LogRecord ctor changes across SDK versions
Create semantic LogRecords via a best-effort wrapper that falls back when the `resource` kwarg is unsupported (OTEL >= 1.39), and avoid MyPy overload/no-redef failures.
* fix(otel): silence mypy no-redef on versioned LogRecord import
MyPy sees both branches of the version-compat import and flags a redefinition. Ignore no-redef on the legacy import path to keep CI passing.
* fix(ui): ensure mcp_info.server_name is always populated
When using stdio transport there may be no URL to fall back on; prefer existing server_name/url/alias to avoid sending an empty mcp_info.server_name on update.
* chore(otel): format opentelemetry; ignore ui export output
* fix: guard optional a2a resolver + make OTEL semantic logs mypy-safe
* chore: format A2A resolver and OTEL semantic logs
* fix: address review feedback for MCP stdio edit
* fix: keep MCP stdio edit PR scoped
* fix(otel): make semantic logs mypy-safe
* fix: map global location to us-east5 for Claude count_tokens endpoint
- Vertex AI doesn't support count_tokens endpoint for Claude models with global location
- Map global -> us-east5 for count_tokens only, keeping global for inference
- Fixes 404 error when calling count_tokens with vertex_location: global
- Reference: https://docs.cloud.google.com/vertex-ai/generative-ai/docs/partner-models/claude/count-tokens
* Update handler.py
* fix:Parse embedded JSON in the message field of logs
* Update litellm/_logging.py
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
---------
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
When transforming chat completion responses to Responses API format,
image_tokens from completion_tokens_details was not being included
in output_tokens_details. This affected Vertex AI/Gemini models that
return image token counts in candidatesTokensDetails with modality="IMAGE".
The fix adds image_tokens handling alongside existing reasoning_tokens
and text_tokens transformation.
* fix(responses): preserve streamed tool deltas when id is omitted
* fix(responses): guard ambiguous tool-call index reuse
* add missing indexes on VerificationToken table
* fix(bedrock): handle concatenated JSON in tool call arguments
When using Bedrock Claude Sonnet 4.5 with tools enabled, the model
sometimes returns multiple tool call arguments as concatenated JSON
objects in a single arguments string, e.g.
'{"command":["curl",...]}{"command":["curl",...]}{"command":["curl",...]}'
json.loads() fails on this with "Extra data", crashing the entire
request in _convert_to_bedrock_tool_call_invoke.
This commit:
- Adds split_concatenated_json_objects() helper in common_utils.py
that uses json.JSONDecoder.raw_decode() to walk a string and extract
each JSON object individually.
- Updates _convert_to_bedrock_tool_call_invoke() to catch JSONDecodeError
and attempt splitting concatenated objects into separate Bedrock
toolUse blocks (first block keeps original ID, subsequent blocks get
suffixed IDs).
- Fixes duplicate json.loads calls and a shadowed 'id' builtin.
- Adds 12 unit tests covering normal, empty, concatenated, and edge cases.
Fixes#20543
---------
Co-authored-by: Emerson Gomes <emerson.gomes@thalesgroup.com>
Co-authored-by: Sameer Kankute <sameer@berri.ai>
Co-authored-by: Carlo Alberto Ferraris <cafxx@mercari.com>