Skip to content

build(deps): bump litellm from 1.94.1 to 1.94.3 - #2559

Draft
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/litellm-1.94.3
Draft

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/litellm-1.94.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps litellm from 1.94.1 to 1.94.3.

Release notes

Sourced from litellm's releases.

v1.94.3

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.3

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.94.3/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.3

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.94.2...v1.94.3

v1.94.2

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

</tr></table> 

... (truncated)

Commits
  • 397859f Merge pull request #36317 from BerriAI/litellm_backport_1_94_x_bp-194x-0808sec
  • be47602 chore: refresh uv.lock for 1.94.3
  • ab3b2fc bump: version 1.94.2 → 1.94.3
  • d5efca5 fix(health): drop a stored-credential reference along with the credentials it...
  • 2d88b52 feat(health): let allow_client_side_credentials re-enable configured-credenti...
  • 2cf2e03 fix(health): stop inheriting configured credentials when a connection test se...
  • 2653829 fix(health)!: let configured deployment parameters win over request overrides
  • dde20e4 fix(proxy)!: parse bracket-notation form metadata the same way its JSON form ...
  • f916951 fix(proxy)!: share one destination check between body and path-supplied model
  • 892a285 chore(proxy): clean up request parameter validation and provider destination ...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [litellm](https://github.com/BerriAI/litellm) from 1.94.1 to 1.94.3.
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.94.1...v1.94.3)

---
updated-dependencies:
- dependency-name: litellm
  dependency-version: 1.94.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner October 2, 2026 05:51
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8f0d4b27-47f2-49ac-8b54-604f33b1f02c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR updates the litellm dependency from version 1.94.1 to 1.94.3 and updates the corresponding hashes in requirements-strix-ci-hashes.txt. This is a patch version increase, which typically ensures backward compatibility and focuses on bug fixes.

Reviewed changed lines

  • requirements-strix-ci-hashes.txt:1122 (RIGHT): The update bumps litellm from 1.94.1 to 1.94.3. This is a patch version update, which according to semantic versioning, is intended for backward-compatible bug fixes. Hypothesis: The update does not introduce regressions in LLM interactions. Verification: The change is limited to a patch bump (1.94.1 -> 1.94.3) and the corresponding hashes in requirements-strix-ci-hashes.txt (lines 1122-1158) have been updated to match the new version's distributions. No breaking changes are expected from a patch update of this nature.

Adversarial validation

  • requirements-strix-ci-hashes.txt:1122 (RIGHT) falsified: The version update from 1.94.1 to 1.94.3 introduces breaking changes in the litellm API used by strix-agent. — The diff shows only the version string change and the update of the accompanying hash list to match the 1.94.3 release distributions.
  • Residual risk: Low; patch updates carry minimal risk of behavioral regressions.

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: 8203e15af9381dd1406d954069cbd209a30648af
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

Copy link
Copy Markdown
Contributor

2026-10-03 exact-head lifecycle correction

  • Exact head remains 8203e15af9381dd1406d954069cbd209a30648af; the scoped Noema approval is preserved.
  • Required CodeQL 36970856814, Security Scan 36970857064, and Python Security 36970857025 are terminal failure. Trivy and pip-audit hard gates remain RED; SAST alone does not replace them.

The PR is therefore returned to Draft / Proposed / merge HOLD without discarding its LiteLLM delta. No rerun, synthetic result, bypass, auto-merge, merge, force update, rebase, or closure is used.

@seonghobae
seonghobae marked this pull request as draft October 2, 2026 21:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant