litellm/.github/workflows
Yuneng Jiang 30565581be
[Infra] Pin cosign.pub verification to initial commit hash
Pin all cosign public key references to the immutable commit hash
(0112e53) that first introduced the key, instead of fetching it from
the release tag. This addresses the concern that an attacker with push
access could replace the key on main/tags and re-sign tampered images.

Docs now show two verification methods: commit hash (recommended) and
release tag (convenience), with explanation of why the hash is stronger.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 22:53:23 -07:00
..
_test-unit-base.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
_test-unit-services-base.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
auto_update_price_and_context_window.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
auto_update_price_and_context_window_file.py only add/update vercel ai gateway models 2025-08-04 17:22:36 -07:00
check-schema-sync.yml [Infra] Fix zizmor artipacked warnings on schema sync workflows 2026-03-27 16:14:06 -07:00
check_duplicate_issues.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
codeql.yml Merge pull request #24697 from BerriAI/litellm_codeql_gha 2026-03-27 12:17:39 -07:00
codspeed.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
create-release.yml [Infra] Pin cosign.pub verification to initial commit hash 2026-04-06 22:53:23 -07:00
create_daily_staging_branch.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
helm_unit_test.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
issue-keyword-labeler.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
label-component.yml pin github scripts + remove unused 2026-03-25 17:38:36 -07:00
llm-translation-testing.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
publish_to_pypi.yml [Infra] Migrate PyPI publishing from CircleCI to GitHub Actions OIDC 2026-03-26 19:02:14 -07:00
read_pyproject_version.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
README.md build(github/manual_pypi_publish.yml): manual workflow to publish pip package - used for pushing dev releases (#12985) 2025-07-25 09:26:47 -07:00
results_stats.csv (fix) results_stats 2024-03-13 17:55:20 -07:00
run_llm_translation_tests.py [Docs] Add cosign Docker image verification steps to security blog posts (#25122) 2026-04-06 09:59:27 -07:00
run_observatory_tests.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
scan_duplicate_issues.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
scorecard.yml Fix broken codeql-action SHA in scorecard workflow 2026-04-03 11:36:02 -07:00
stale.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
sync-schema.yml [Infra] Fix zizmor artipacked warnings on schema sync workflows 2026-03-27 16:14:06 -07:00
test-linting.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
test-litellm-ui-build.yml chore: harden npm supply chain — pin overrides, enforce npm ci, add ignore-scripts (#24838) 2026-03-31 13:41:37 -07:00
test-litellm.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
test-mcp.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
test-model-map.yaml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
test-unit-caching-redis.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-core-utils.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-documentation.yml [Fix] Scope documentation workflow to match CircleCI and add missing router settings 2026-03-28 11:23:53 -07:00
test-unit-enterprise-routing.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-integrations.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-llm-providers.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-misc.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-proxy-auth.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-proxy-db.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-proxy-endpoints.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-proxy-infra.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-proxy-legacy.yml [Infra] Add isolated unit test workflows with hardened security posture 2026-03-28 09:56:58 -07:00
test-unit-responses-caching-types.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test-unit-security.yml [Infra] Remove Redundant Matrix Unit Test Workflow (#25251) 2026-04-06 16:52:38 -07:00
test_server_root_path.yml fix: address zizmor comments 2026-03-26 21:09:01 -07:00
update_release.py (fix) update load test result 2024-03-13 17:53:51 -07:00
zizmor.yml ci: add zizmor github action 2026-03-27 05:33:21 -07:00

Simple PyPI Publishing

A GitHub workflow to manually publish LiteLLM packages to PyPI with a specified version.

How to Use

  1. Go to the Actions tab in the GitHub repository
  2. Select Simple PyPI Publish from the workflow list
  3. Click Run workflow
  4. Enter the version to publish (e.g., 1.74.10)

What the Workflow Does

  1. Updates the version in pyproject.toml
  2. Copies the model prices backup file
  3. Builds the Python package
  4. Publishes to PyPI

Prerequisites

Make sure the following secret is configured in the repository:

  • PYPI_PUBLISH_PASSWORD: PyPI API token for authentication

Example Usage

  • Version: 1.74.11 → Publishes as v1.74.11
  • Version: 1.74.10-hotfix1 → Publishes as v1.74.10-hotfix1

Features

  • Manual trigger with version input
  • Automatic version updates in pyproject.toml
  • Repository safety check (only runs on official repo)
  • Clean package building and publishing
  • Success confirmation with PyPI package link