mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-05 02:41:56 +00:00
* chore(deps): bump aiohttp to 3.14.1 and vitest to 3.2.6 Lockfile-only bump for aiohttp (3.13.5 -> 3.14.1, within the existing pyproject constraint) and dashboard devDependency bumps for vitest, @vitest/coverage-v8, @vitest/ui (3.2.4 -> 3.2.6) plus transitive brace-expansion (5.0.5 -> 5.0.6). Clears the currently published advisories flagged by osv.dev against uv.lock and the dashboard lockfile. Verified: 154 custom_httpx unit tests and all 3943 dashboard vitest tests pass; live proxy completion and streaming calls succeed on the bumped venv * chore(deps): raise aiohttp floor to 3.14.0 The lockfile bump alone only protects environments built from uv.lock. Raising the pyproject floor extends the same minimum to package consumers installing litellm from PyPI, and prevents a future lockfile regeneration from resolving below 3.14.0 * Revert "chore(deps): raise aiohttp floor to 3.14.0" This reverts commitd6c1c9dc0c. * revert(deps): roll back aiohttp to 3.13.5 vcrpy is incompatible with aiohttp >= 3.14 (the aiohttp_stubs module imports a symbol removed in 3.14) and the upstream fix is merged but unreleased, so every cassette-based test suite fails on 3.14. Hold aiohttp at 3.13.5 until a vcrpy release ships; the vitest and brace-expansion bumps stay * chore(deps): bump pypdf to 6.13.1 and tornado to 6.5.7 Lockfile-only bumps clearing the advisories published for both since this branch was opened * chore(deps): add regression guards for the bumped versions Raise the pypdf floor to 6.12.0 (direct dependency, applies to package consumers too) and add uv constraint-dependencies for the transitive pins: tornado >= 6.5.6, and aiohttp held in [3.13.5, 3.14) so a lockfile regeneration can neither fall back below the current version nor move onto 3.14 while vcrpy is incompatible. Constraints live in [tool.uv] and only affect this repo's resolution, not published metadata. Verified: uv lock -P with each out-of-range version fails to resolve; in-range resolutions unchanged (pypdf 6.13.1, tornado 6.5.7, aiohttp 3.13.5) Backport handling (stable/1.88.x): the manifest hunks (pyproject pypdf floor 6.10.2->6.12.0 plus the [tool.uv] tornado/aiohttp constraints, and the package.json vitest 3.2.4->3.2.6 bumps) are taken as-is; the staging lockfiles are not. uv.lock and package-lock.json are regenerated on this line so the closure stays minimal: uv.lock moves only pypdf 6.10.2->6.13.2 and tornado 6.5.5->6.5.7 (aiohttp held at 3.13.5 by the new constraint), and package-lock.json moves vitest and @vitest to 3.2.6. brace-expansion reached 5.0.6 transitively on staging but resolves to 5.0.5 on this line's tree, so a brace-expansion 5.0.6 override is added to clear the same advisory. No version bump: 1.88.2 is bumped but unreleased, so these ride the pending 1.88.2. (cherry picked from commitd96ab467f1)
99 lines
2.8 KiB
JSON
99 lines
2.8 KiB
JSON
{
|
|
"name": "litellm-dashboard",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"scripts": {
|
|
"dev": "next dev",
|
|
"dev:webpack": "next dev --webpack",
|
|
"build": "next build",
|
|
"start": "next start",
|
|
"lint": "next lint",
|
|
"test": "vitest",
|
|
"test:dot": "vitest --reporter=dot",
|
|
"test:watch": "vitest -w",
|
|
"test:coverage": "vitest run --coverage",
|
|
"format": "prettier --write .",
|
|
"format:check": "prettier --check .",
|
|
"e2e": "playwright test --config e2e_tests/playwright.config.ts",
|
|
"e2e:ui": "playwright test --ui --config e2e_tests/playwright.config.ts",
|
|
"knip": "knip",
|
|
"knip:fix": "knip --fix"
|
|
},
|
|
"dependencies": {
|
|
"@anthropic-ai/sdk": "0.92.0",
|
|
"@headlessui/tailwindcss": "0.2.2",
|
|
"@heroicons/react": "1.0.6",
|
|
"@remixicon/react": "4.9.0",
|
|
"@tanstack/react-pacer": "0.2.0",
|
|
"@tanstack/react-query": "5.100.7",
|
|
"@tanstack/react-table": "8.21.3",
|
|
"@tremor/react": "3.18.7",
|
|
"@types/papaparse": "5.5.2",
|
|
"antd": "5.29.3",
|
|
"cva": "1.0.0-beta.4",
|
|
"dayjs": "1.11.19",
|
|
"jwt-decode": "4.0.0",
|
|
"lucide-react": "0.513.0",
|
|
"moment": "2.30.1",
|
|
"next": "16.2.6",
|
|
"openai": "4.104.0",
|
|
"papaparse": "5.5.3",
|
|
"react": "18.3.1",
|
|
"react-copy-to-clipboard": "5.1.1",
|
|
"react-dom": "18.3.1",
|
|
"react-json-view-lite": "2.5.0",
|
|
"react-markdown": "9.1.0",
|
|
"react-syntax-highlighter": "15.6.6",
|
|
"remark-gfm": "4.0.1",
|
|
"tailwind-merge": "3.4.0",
|
|
"uuid": "14.0.0"
|
|
},
|
|
"devDependencies": {
|
|
"@playwright/test": "1.58.1",
|
|
"@tailwindcss/forms": "0.5.11",
|
|
"@testing-library/dom": "10.4.1",
|
|
"@testing-library/jest-dom": "6.9.1",
|
|
"@testing-library/react": "16.3.2",
|
|
"@testing-library/user-event": "14.6.1",
|
|
"@types/babel__traverse": "7.28.0",
|
|
"@types/lodash": "4.17.23",
|
|
"@types/node": "20.19.37",
|
|
"@types/react": "18.2.48",
|
|
"@types/react-copy-to-clipboard": "5.0.7",
|
|
"@types/react-dom": "18.3.7",
|
|
"@types/react-syntax-highlighter": "15.5.13",
|
|
"@types/uuid": "10.0.0",
|
|
"@vitest/coverage-v8": "3.2.6",
|
|
"@vitest/ui": "3.2.6",
|
|
"autoprefixer": "10.4.24",
|
|
"dotenv": "17.2.3",
|
|
"eslint": "9.39.2",
|
|
"eslint-config-next": "15.5.10",
|
|
"eslint-config-prettier": "10.1.8",
|
|
"eslint-plugin-unused-imports": "4.3.0",
|
|
"jsdom": "27.4.0",
|
|
"knip": "5.83.1",
|
|
"postcss": "8.5.13",
|
|
"prettier": "3.2.5",
|
|
"tailwindcss": "3.4.19",
|
|
"typescript": "5.9.3",
|
|
"vite": "7.3.2",
|
|
"vitest": "3.2.6"
|
|
},
|
|
"overrides": {
|
|
"prismjs": "1.30.0",
|
|
"js-yaml": "4.1.1",
|
|
"glob": "13.0.0",
|
|
"minimatch": "10.2.4",
|
|
"lodash": "4.18.1",
|
|
"ws": "8.20.1",
|
|
"braces": "3.0.3",
|
|
"brace-expansion": "5.0.6",
|
|
"axios": "1.13.6",
|
|
"postcss": "8.5.13"
|
|
},
|
|
"engines": {
|
|
"node": ">=20.9.0",
|
|
"npm": ">=8.3.0"
|
|
}
|
|
}
|