mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-06 08:16:43 +00:00
Add a security gate workflow that scans pull requests for malicious .pth file additions or renames. .pth files are a known Python security risk as they allow arbitrary code execution at interpreter startup. The workflow will fail the check if any .pth files are detected, prompting the author to rename legitimate fixtures to .pth.txt. chore: remove malicious.pth file The file was identified as potentially harmful and has been deleted to maintain repository security. ci: update actions/github-script to pinned version v7.0.1 Update the GitHub Actions workflow to use a pinned version tag instead of a commit hash for the `actions/github-script` action. This improves maintainability and security by using an official, versioned release. docs: add security gate check to PR templates and improve scan Update CONTRIBUTING.md and pull request template to document the new Critical Entry Point Scan requirement. Enhance the security-gate workflow with a warning for large PRs exceeding GitHub API limits and add configuration notes for branch protection. |
||
|---|---|---|
| .. | ||
| _test-unit-base.yml | ||
| _test-unit-services-base.yml | ||
| auto_update_price_and_context_window.yml | ||
| auto_update_price_and_context_window_file.py | ||
| check-schema-sync.yml | ||
| check_duplicate_issues.yml | ||
| codeql.yml | ||
| codspeed.yml | ||
| create_daily_staging_branch.yml | ||
| helm_unit_test.yml | ||
| issue-keyword-labeler.yml | ||
| label-component.yml | ||
| llm-translation-testing.yml | ||
| publish_to_pypi.yml | ||
| read_pyproject_version.yml | ||
| README.md | ||
| results_stats.csv | ||
| run_llm_translation_tests.py | ||
| run_observatory_tests.yml | ||
| scan_duplicate_issues.yml | ||
| scorecard.yml | ||
| security-gate.yml | ||
| stale.yml | ||
| sync-schema.yml | ||
| test-linting.yml | ||
| test-litellm-matrix.yml | ||
| test-litellm-ui-build.yml | ||
| test-litellm.yml | ||
| test-mcp.yml | ||
| test-model-map.yaml | ||
| test-proxy-e2e-azure-batches.yml | ||
| test-unit-caching-redis.yml | ||
| test-unit-core-utils.yml | ||
| test-unit-documentation.yml | ||
| test-unit-enterprise-routing.yml | ||
| test-unit-integrations.yml | ||
| test-unit-llm-providers.yml | ||
| test-unit-misc.yml | ||
| test-unit-proxy-auth.yml | ||
| test-unit-proxy-db.yml | ||
| test-unit-proxy-endpoints.yml | ||
| test-unit-proxy-infra.yml | ||
| test-unit-proxy-legacy.yml | ||
| test-unit-responses-caching-types.yml | ||
| test-unit-security.yml | ||
| test_server_root_path.yml | ||
| update_release.py | ||
| zizmor.yml | ||
Simple PyPI Publishing
A GitHub workflow to manually publish LiteLLM packages to PyPI with a specified version.
How to Use
- Go to the Actions tab in the GitHub repository
- Select Simple PyPI Publish from the workflow list
- Click Run workflow
- Enter the version to publish (e.g.,
1.74.10)
What the Workflow Does
- Updates the version in
pyproject.toml - Copies the model prices backup file
- Builds the Python package
- Publishes to PyPI
Prerequisites
Make sure the following secret is configured in the repository:
PYPI_PUBLISH_PASSWORD: PyPI API token for authentication
Example Usage
- Version:
1.74.11→ Publishes as v1.74.11 - Version:
1.74.10-hotfix1→ Publishes as v1.74.10-hotfix1
Features
- ✅ Manual trigger with version input
- ✅ Automatic version updates in
pyproject.toml - ✅ Repository safety check (only runs on official repo)
- ✅ Clean package building and publishing
- ✅ Success confirmation with PyPI package link