Skip to content

chore(deps): bump litellm from 1.102.0 to 1.103.2 in /backend - #312

Merged
purvanshjoshi merged 1 commit into
mainfrom
dependabot/pip/backend/litellm-1.103.1
Oct 4, 2026
Merged

purvanshjoshi merged 1 commit into
mainfrom
dependabot/pip/backend/litellm-1.103.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps litellm from 1.102.0 to 1.103.2.

Release notes

Sourced from litellm's releases.

v1.103.2

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.103.1...v1.103.2

v1.103.1

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

... (truncated)

Commits
  • f69b210 Merge pull request #43984 from BerriAI/litellm_backport_lit9020_stable_1_103_x
  • 2869a6f fix(proxy): restore pre-config-wins handling of pass-through endpoints (#43962)
  • afbda35 Merge pull request #43662 from BerriAI/litellm_backport_safeguards_stable_1_1...
  • f146256 Merge pull request #43897 from BerriAI/litellm_backport_usage_attribution_sta...
  • fe87252 chore(release): bump litellm-enterprise 0.1.69 -> 0.1.69.post1 for stable/1.1...
  • 1bbc9ee test(integration): register the daily activity key metadata contracts on stab...
  • 460d51f bump: version 1.103.2
  • 97f670a fix(proxy): look up hashed key names with two spend log rows per key (#43656)
  • 00b8664 fix(proxy): recover session key owners from daily spend for usage attribution...
  • 74952e9 test(integration): add the scratch_database harness helper
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: python. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
auto-maintainer Ready Ready Preview Oct 4, 2026 8:39am UTC

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b954328a-d235-428b-b707-f5168f42dcf9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@purvanshjoshi purvanshjoshi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: Legitimate dependabot patch/minor update with bug fixes and security improvements.

@purvanshjoshi

Copy link
Copy Markdown
Contributor

@dependabot rebase

1 similar comment
@purvanshjoshi

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [litellm](https://github.com/BerriAI/litellm) from 1.102.0 to 1.103.2.
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.102.0...v1.103.2)

---
updated-dependencies:
- dependency-name: litellm
  dependency-version: 1.103.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump litellm from 1.102.0 to 1.103.1 in /backend chore(deps): bump litellm from 1.102.0 to 1.103.2 in /backend Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/backend/litellm-1.103.1 branch from c896888 to 199d303 Compare October 4, 2026 08:35
@purvanshjoshi
purvanshjoshi merged commit 8fc9207 into main Oct 4, 2026
17 of 19 checks passed
@purvanshjoshi
purvanshjoshi deleted the dependabot/pip/backend/litellm-1.103.1 branch October 4, 2026 08:36

This branch was successfully deployed

1 active deployment
Preview — 199d3037 Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants