Commit graph

35671 commits

Author SHA1 Message Date
Bipin Rimal
e6dc5320b3 fix: address all remaining Greptile review comments
- Remove self-promotional scanner references (keep neutral resource links)
- Fix GDPR controller/processor: entities not software, qualify "typically"
- Remove unverifiable "70-80%" coverage claim
- Rewrite Article 13: provider→deployer documentation, not end-user transparency
- Fix retention: Article 18 (10yr providers), Article 26(5) (6mo deployers)
- Remove pip install instructions from official docs
- Article 50 bullets now match actual deployer obligations
2026-03-23 13:50:22 +05:45
Bipin Rimal
ede48a942b fix: correct misleading 'header' comment in Article 50 code example 2026-03-23 13:23:11 +05:45
Bipin Rimal
c11019164c fix: clarify Article 50(2) provider vs deployer obligation
Article 50(2) machine-readable marking is a provider obligation,
not a deployer obligation. Deployers have 50(1) chatbot disclosure
and 50(4) deepfake disclosure. Revised to distinguish roles.
2026-03-23 13:04:08 +05:45
Bipin Rimal
980b60cda1 fix: correct Article 26 citation and add Article 50 section
Address Greptile review:
- P1: Article 26(6) → Article 26(5) for deployer log retention
- P1: Add dedicated Article 50 section for user-facing transparency
  (was referenced in scope section but had no corresponding section)
2026-03-23 12:43:35 +05:45
Bipin Rimal
9de47978b4 fix: add provider vs deployer role clarification
Address Greptile P1: guide conflated provider and deployer obligations.
- Added section explaining Article 3(3) provider vs Article 3(4) deployer
- Most LiteLLM users building custom apps are providers (heavier obligations)
- Clarified that system-level compliance is the user's responsibility,
  separate from foundation model providers' own obligations
2026-03-23 11:51:35 +05:45
Bipin Rimal
1949a32eca fix: replace placeholder callback with real LiteLLM patterns
Address Greptile P1: 'your_logging_backend' is not a valid callback.
Show both built-in integration (langfuse/s3/datadog) and CustomLogger
class pattern with actual Article 12 field references.
2026-03-23 11:28:18 +05:45
Bipin Rimal
e101cdb848 fix: add eu-ai-act-compliance to Extras sidebar navigation 2026-03-23 11:14:59 +05:45
Bipin Rimal
6a6ef5751b fix: rewrite Article 14 section and fix Mermaid node shapes
Address Greptile review:
- P1: Article 14 table incorrectly mapped automated controls as human
  oversight. Rewritten to clarify that guardrails are Art 9/15 controls,
  not Art 14 human oversight. New table shows actual Art 14 requirements.
- P2: Consistent stadium/pill shapes for all provider nodes in diagram.
2026-03-23 11:07:19 +05:45
Bipin Rimal
067988ac24 fix: correct Annex III scoping language and align provider list with diagram
Address Greptile review feedback:
- 'less likely to apply' → 'do not apply via the Annex III pathway'
- Add full scope check section (Is your system in scope?)
- Align provider list with data flow diagram examples
2026-03-23 01:49:43 +05:45
Bipin Rimal
6f8df7253f fix: Article 50 end-user scope + Article 13 logs vs documentation distinction 2026-03-22 23:51:06 +05:45
Bipin Rimal
5652eb674e fix: Article 14 human oversight distinction + GDPR cross-border scope 2026-03-22 23:41:56 +05:45
Bipin Rimal
fe85640c2d fix: Soften scope check — do not self-classify without legal review 2026-03-21 03:06:15 +05:45
Bipin Rimal
9f814f6fad fix: Add scope check, correct retention to 10yr/6mo, qualify GDPR roles
- Add "Is your system in scope?" section with Annex III checklist
- Fix retention: Article 18 requires 10 years for providers, Article 26(6)
  requires minimum 6 months for deployers (was incorrectly "6+ months")
- Qualify GDPR processor role as provider-dependent
2026-03-21 02:46:32 +05:45
Bipin Rimal
4159b1603f fix: Qualify GDPR processor role as provider-dependent 2026-03-21 02:43:26 +05:45
Bipin Rimal
b06f8996af fix: Split Article 13 (provider→deployer) from Article 50 (deployer→user) 2026-03-21 02:36:18 +05:45
Bipin Rimal
4946c4896c fix: Address review feedback on compliance guide
- Remove third-party tool promotion (pip install blocks, scanner stats)
- Fix GDPR misclassification: controller is the organization, not software
- Replace unverifiable "70-80%" coverage claim with qualitative statement
- Reduce tool references to zero; keep only official EU/LiteLLM resources
2026-03-21 02:29:10 +05:45
Bipin Rimal
94e867aa16 docs: Add EU AI Act compliance guide for LiteLLM deployers
Maps LiteLLM's existing logging, callbacks, and guardrails to
EU AI Act Articles 12, 13, and 14. Includes data flow diagram
showing gateway architecture with GDPR role classifications.

Scanner analysis: 4,861 files, 7 AI providers, 112 model identifiers,
12 external services.
2026-03-21 02:15:10 +05:45
Krish Dholakia
0d7425a437
Merge pull request #23774 from michelligabriele/fix/model-level-guardrails-non-streaming-postcall
fix(proxy): model-level guardrails not executing for non-streaming post_call
2026-03-18 08:26:02 -07:00
Krish Dholakia
b4a5e51668
Merge pull request #23820 from joereyna/release-notes/v1.82.3-v2 2026-03-18 07:10:24 -07:00
Krish Dholakia
cec3e9e7d4
Merge pull request #23808 from voidborne-d/fix/shared-aiohttp-session-auto-recovery
fix: auto-recover shared aiohttp session when closed
2026-03-17 22:23:01 -07:00
joereyna
8a4ef0bd05 revert: restore full changelog base to v1.82.0-stable 2026-03-17 22:17:12 -07:00
joereyna
19f82c229b fix: update full changelog base from v1.82.0-stable to v1.82.0 2026-03-17 22:11:43 -07:00
yuneng-jiang
cfeafbe388
Merge pull request #23921 from BerriAI/litellm_mar17_extras
[Infra] Security and Proxy Extras for Nightly

Only known flaky tests failing. The fix for security and proxy extras worked
2026-03-17 18:01:19 -07:00
Krish Dholakia
5e570b3a66
Merge pull request #23911 from kelvin-tran/fix/cache-control-params-anthropic-document-file-message-blocks 2026-03-17 18:00:05 -07:00
Krish Dholakia
3bd4422a97
Merge pull request #23881 from xianzongxie-stripe/xianzong-upstream-changes 2026-03-17 17:58:36 -07:00
d 🔹
88f59e1465 fix: use AsyncMock for concurrent test consistency
Address review feedback from greptile — use new_callable=AsyncMock
on the concurrent test's patch.object to ensure the mock is properly
typed as async, even though side_effect already handles the coroutine.
2026-03-18 00:54:23 +00:00
Ishaan Jaffer
bae2eddd73 docs fix sidebar 2026-03-17 17:50:58 -07:00
Ishaan Jaff
fc315ab4af
docs(mcp_zero_trust): add MCP zero trust auth guide (#23918)
* docs(mcp_zero_trust): add MCP zero trust auth guide with hero image

* fix(docs): move hero image to static/img/ for Docusaurus build
2026-03-17 17:45:16 -07:00
yuneng-jiang
62835ff03d adding package-lock 2026-03-17 17:44:01 -07:00
yuneng-jiang
3e2845181c bumping next version 2026-03-17 17:38:09 -07:00
yuneng-jiang
cc37bf5934 adding build 2026-03-17 17:37:25 -07:00
yuneng-jiang
9fa1809c30 bump: version 0.4.56 → 0.4.57 2026-03-17 17:37:04 -07:00
yuneng-jiang
ac0de1d6a2
Merge pull request #23919 from BerriAI/mar17_ver_bump
[Infra] bump: version 1.82.3 → 1.82.4
2026-03-17 17:33:21 -07:00
yuneng-jiang
709581c5f9 bump: version 1.82.3 → 1.82.4 2026-03-17 17:31:45 -07:00
yuneng-jiang
195c0ee54d
Merge pull request #23917 from BerriAI/litellm_/loving-noyce
[Fix] Add contents:write permission to ghcr_deploy release job
2026-03-17 17:27:36 -07:00
yuneng-jiang
b8ffbba352 [Fix] Add contents:write permission to release job in ghcr_deploy workflow
The release job was failing with "Resource not accessible by integration"
because other jobs explicitly set permissions, causing GitHub to scope the
default token down for all jobs. The release job needs contents:write to
create GitHub releases.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-17 17:23:39 -07:00
Kelvin Tran
c6e9a2a40f
Merge branch 'main' into fix/cache-control-params-anthropic-document-file-message-blocks 2026-03-17 15:34:00 -07:00
Kelvin Tran
d0c5f494a8 fix: cache_control directive dropped anthropic document/file blocks 2026-03-17 14:30:12 -07:00
joereyna
a51c670f2f revert: remove provider_endpoints_support.json changes, docs only 2026-03-17 12:56:25 -07:00
voidborne-d
ca8f5cffa0 style: apply black formatting to fix CI lint check 2026-03-17 18:52:57 +00:00
Xianzong Xie
cb88836486 Add incomplete response error propagation test
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
2026-03-17 11:39:12 -07:00
Xianzong Xie
bd5c39c4d1 Log incomplete details in background streaming
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
2026-03-17 11:35:50 -07:00
Xianzong Xie
3ff4ac3de3 Capture incomplete terminal error in background streaming
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
2026-03-17 11:21:26 -07:00
d 🔹
ef22144854 address P2 feedback: add lock docstring warning, remove redundant mock write
- Add WARNING docstring to _get_shared_session_lock() about not resetting
  the lock to None while coroutines may be in the recovery path
- Remove redundant proxy_server_module.shared_aiohttp_session assignment
  in mock_init (add_shared_session_to_data overwrites it synchronously)
2026-03-17 18:07:15 +00:00
ryan-crabbe
ef9cc33ee3
Merge pull request #23822 from BerriAI/litellm_ryan_march_16
Litellm ryan's daily branch march 16
2026-03-17 10:03:01 -07:00
yuneng-jiang
a622a1fa35
Merge pull request #23827 from BerriAI/litellm_internal_dev_03_16_2026
[Infra] Merge daily dev branch with main
2026-03-17 09:58:06 -07:00
yuneng-jiang
b4c9c8a9f0
Merge pull request #23868 from BerriAI/revert-22188-litellm_langfuse_key_leakage
Revert "fix: langfuse trace leak key on model params"
2026-03-17 08:58:30 -07:00
yuneng-jiang
467706ea30
Revert "fix: langfuse trace leak key on model params" 2026-03-17 08:58:07 -07:00
d
32ecd24116 fix: address P2 review feedback - exception handling and warning accuracy
- Add try/except around _initialize_shared_aiohttp_session call to catch
  and log exceptions (instead of letting them bubble to outer handler)
- Fix warning message when re-checked session is None (was incorrectly
  logging closed session ID on a None session)
- Add debug logging to outer except handler instead of bare pass
- Add test for _initialize_shared_aiohttp_session raising exception
2026-03-17 13:09:26 +00:00
d 🔹
9e09bbc1df fix: reset _shared_session_lock in all tests for event loop isolation
Address Greptile P1 review: tests that exercise the closed-session code
path need to reset the module-level lock to avoid RuntimeError on
Python < 3.10 when asyncio.Lock is reused across different event loops.
2026-03-17 09:54:01 +00:00