litellm/tests/logging_callback_tests
user 4af58e1f97
[Security] Clear AWS Inspector CVE findings on Docker image
- Narrow /root/.cache COPY in Dockerfile to /root/.cache/prisma{,-python}
  only — drops ~660MB of uv build cache including a setuptools wheel
  that surfaced as CVE-2024-6345 / CVE-2025-47273 even though it was
  never on the runtime sys.path.
- DiskCache: switch to dc.JSONDisk to neutralize the pickle code path
  (CVE-2025-69872, no upstream fix). Values must be JSON-serializable;
  cleanup get_cache to skip the now-dead json.loads(dict) branch by
  guarding on isinstance(str).
- pyproject.toml: drop diskcache pin from [caching] extra (no fixed
  version exists). Stub kept so `pip install litellm[caching]` doesn't
  warn; users who want disk caching install diskcache themselves.
- Bump black 24.10.0 → 26.3.1 (CVE-2026-32274) + apply 296-file mechanical
  reformat. Black is dev-only (not in the runtime image), but bumping
  clears the manifest-scan finding.
- Refresh ui/litellm-dashboard/package-lock.json to pick up next 16.2.4
  (was 16.1.7, GHSA-q4gf-8mx6-v5v3), uuid 14.0.0, postcss 8.5.13.
- Refresh litellm-js/spend-logs/package-lock.json to pick up
  hono 4.12.16 (GHSA-458j-xx4x-4375).
- uv lock: gitpython 3.1.46 → 3.1.49 (clears two High GHSAs),
  langchain-text-splitters 1.1.1 → 1.1.2.
- Add tests/test_litellm/caching/test_disk_cache.py covering JSONDisk
  enforcement, dict/string round-trip, TTL, increment, delete/flush.

Net delta on combined trivy + grype scans: 17 findings → 4 (all
remaining 4 are Wolfi system python-3.13 CVEs marked WONTFIX upstream
in CPython 3.14; CVE-2026-3298 is Windows-unreachable on Linux).

Existing on-disk caches written by the previous pickle-format Disk
will silently miss after upgrade — diskcache is intended to be
ephemeral so impact is recreate-on-next-write.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 20:21:15 +00:00
..
gcs_pub_sub_body test fixes 2026-03-30 16:59:27 -07:00
langfuse_expected_request_body [Test Fix] fix gov pricing tests (#25022) 2026-04-02 15:55:55 -07:00
base_test.py Litellm dev 11 11 2024 (#6693) 2024-11-12 00:16:35 +05:30
conftest.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
create_mock_standard_logging_payload.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
gettysburg.wav (Testing) - Add e2e testing for langfuse logging with tags (#7922) 2025-01-22 09:09:25 -08:00
log.txt test: update test 2025-04-10 14:04:57 -07:00
test_alerting.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_amazing_s3_logs.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_assemble_streaming_responses.py test(test_assemble_streaming_responses.py): update test to use correct type 2025-03-17 18:17:01 -07:00
test_bedrock_knowledgebase_hook.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_built_in_tools_cost_tracking.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_custom_callback_router.py test: test 2026-03-28 19:17:38 -07:00
test_datadog.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_datadog_llm_obs.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_dynamic_otel_keys.py Litellm fix langfuse otel trace (#20382) 2026-02-03 22:40:19 -08:00
test_gcs_pub_sub.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_generic_api_callback.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_humanloop_unit_tests.py HumanLoop integration for Prompt Management (#7479) 2024-12-30 22:26:03 -08:00
test_langfuse_dynamic_credentials.py fix(callbacks): preserve langfuse secret alias 2026-04-30 14:36:51 -07:00
test_langfuse_e2e_test.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_langfuse_unit_tests.py add tests for fix 2026-03-15 00:58:08 +05:30
test_langsmith_dynamic_credentials.py chore(callbacks): guard dynamic integration hosts 2026-04-30 14:27:19 -07:00
test_langsmith_unit_test.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_log_db_redis_services.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00
test_logging_redaction_e2e_test.py fix(proxy): sanitize redaction controls at ingress 2026-04-29 22:52:31 -07:00
test_moderations_api_logging.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_opentelemetry_unit_tests.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_otel_logging.py fix(logging): add litellm_call_id to StandardLoggingPayload and OTel span (#26133) 2026-04-21 15:24:32 -07:00
test_pagerduty_alerting.py [Refactor] Make Pagerduty a free feature (#10857) 2025-05-15 10:12:06 -07:00
test_posthog.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_spend_logs.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_sqs_logger.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_standard_logging_payload.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_standard_logging_payload_excluded_fields.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_token_counting.py test_stream_token_counting_anthropic_with_include_usage 2025-10-31 20:24:58 -07:00
test_unit_test_litellm_logging.py (performance improvement - litellm sdk + proxy) - ensure litellm does not create unnecessary threads when running async functions (#7680) 2025-01-10 17:57:22 -08:00
test_unit_tests_init_callbacks.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_view_request_resp_logs.py [Security] Clear AWS Inspector CVE findings on Docker image 2026-05-05 20:21:15 +00:00