LiteLLM 发布: v1.103.0-dev.2
来源摘要
## Verify Docker Image Signature All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0). **Verify using the pinned commit hash (recommended):** A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \ ghcr.io/berriai/litellm:v1.103.0-dev.2 ``` **Verify using the release tag (convenience):** Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.0-dev.2/cosign.pub \ ghcr.io/berriai/litellm:v1.103.0-dev.2 ``` Expected output: ``` The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key ``` --- ## What's Changed * fix(fireworks-ai): bill cache-write, reasoning and audio tokens via the shared cost calculator by @devin-ai-integration[bot] in https://github.com/BerriAI/litellm/pull/41339 * feat(guardrails): singulr v2 API contract with logging_only, pre_mcp_call and post_mcp_call by @yucheng-berri in https://github.com/BerriAI/litellm/pull/41329 * ci(image-scan): ignore zlib CVE-2026-85091 until Wolfi ships the fix by @yuneng-berri in https://github.com/BerriAI/litellm/pull/41353 * feat(e2e): reuse exact provider responses for 24 hours by @yuneng-berri in https://github.com/BerriAI/litellm/pull/41346 * fix(xai): ke
阅读原始来源- 来源
- LiteLLM 发布 · 官方来源
- 来源发布
- 2026/09/18 10:42
- 来源更新
- 2026/09/18 10:42
- 首次采集
- 2026/09/19 13:21
本文为公开信息索引与摘要,详情及后续变化请以原始来源为准。