fix(container): update image ghcr.io/berriai/litellm (v1.103.0 ➔ v1.103.1) #2247

Open
renovate-bot wants to merge 1 commit from renovate/ghcr.io-berriai-litellm-1.x into main
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/berriai/litellm (source) patch v1.103.0 → v1.103.1

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

BerriAI/litellm (ghcr.io/berriai/litellm)

v1.103.1

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

Full Changelog: https://github.com/BerriAI/litellm/compare/v1.103.0...v1.103.1


Configuration

📅 Schedule: (in timezone Europe/Rome)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/berriai/litellm](https://images.chainguard.dev/directory/image/wolfi-base/overview) ([source](https://github.com/BerriAI/litellm)) | patch | `v1.103.0` → `v1.103.1` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/6) for more information. --- ### Release Notes <details> <summary>BerriAI/litellm (ghcr.io/berriai/litellm)</summary> ### [`v1.103.1`](https://github.com/BerriAI/litellm/releases/tag/v1.103.1) [Compare Source](https://github.com/BerriAI/litellm/compare/v1.103.0...v1.103.1) #### Verify Docker Image Signature All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0). **Verify using the pinned commit hash (recommended):** A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \ ghcr.io/berriai/litellm:v1.103.1 ``` **Verify using the release tag (convenience):** Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.1/cosign.pub \ ghcr.io/berriai/litellm:v1.103.1 ``` Expected output: ``` The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key ``` *** **Full Changelog**: <https://github.com/BerriAI/litellm/compare/v1.103.0...v1.103.1> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
fix(container): update image ghcr.io/berriai/litellm (v1.103.0 ➔ v1.103.1)
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 5s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 36s
Konflate 1 resource changed
c280bb23c8
Collaborator

✅ Automated recommendation: APPROVE

Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)

Approve — patch version bump of ghcr.io/berriai/litellm from v1.103.0 to v1.103.1 with updated SHA digest.

Changed file: kubernetes/apps/ai/litellm/app/litellmproxy.yaml

  • Image tag updated: v1.103.0 → v1.103.1
  • SHA digest updated to match new tag
  • renovate: datasource=docker depName=... hint preserved
  • Konflate rendered-diff: no findings
<!-- ai-pr-reviewer --> <!-- ai-pr-reviewer:{"version":1,"head_sha":"c280bb23c870c3bde0d74dc5c7f9b4f51d152cc6","base_sha":"8844a1398d519e2929ab91410f42e6f1ac8b4a15","review_scope":"full","review_result":"clean"} --> <!-- ai-pr-review-sha:c280bb23c870c3bde0d74dc5c7f9b4f51d152cc6 --> <!-- ai-pr-review-fingerprint:405d30fdb4b6b21390030ebcc8cd5cd6bb9fe9892a25a4fa3bb56535020f98ea|cfg:d27ea58bdbdafc403f62b1b84c70d905cc97c77c6d72d767872b88951af9ea8d --> ✅ **Automated recommendation: APPROVE** _Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)_ **Approve** — patch version bump of ghcr.io/berriai/litellm from v1.103.0 to v1.103.1 with updated SHA digest. **Changed file:** `kubernetes/apps/ai/litellm/app/litellmproxy.yaml` - Image tag updated: `v1.103.0` → `v1.103.1` - SHA digest updated to match new tag - `renovate: datasource=docker depName=...` hint preserved - Konflate rendered-diff: no findings
Collaborator

Routine: only container-image and chart-version changes; 1 resource across 1 app

image from to upstream
ghcr.io/berriai/litellm v1.103.0@sha256:bd089a… v1.103.1@sha256:df1540… ❔

konflate 0.6.4 · rendered c280bb2 · full diff →

<!-- konflate:pr-2247 --> **Routine**: only container-image and chart-version changes; 1 resource across 1 app | image | from | to | upstream | |---|---|---|---| | `ghcr.io/berriai/litellm` | `v1.103.0@sha256:bd089a…` | `v1.103.1@sha256:df1540…` | ❔ | <sub>konflate 0.6.4 · rendered `c280bb2` · [full diff →](https://konflate.aresu.eu/#/pr/2247)</sub>
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 5s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 36s
Konflate 1 resource changed
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/ghcr.io-berriai-litellm-1.x:renovate/ghcr.io-berriai-litellm-1.x
git switch renovate/ghcr.io-berriai-litellm-1.x

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/ghcr.io-berriai-litellm-1.x
git switch renovate/ghcr.io-berriai-litellm-1.x
git rebase main
git switch main
git merge --ff-only renovate/ghcr.io-berriai-litellm-1.x
git switch renovate/ghcr.io-berriai-litellm-1.x
git rebase main
git switch main
git merge --no-ff renovate/ghcr.io-berriai-litellm-1.x
git switch main
git merge --squash renovate/ghcr.io-berriai-litellm-1.x
git switch main
git merge --ff-only renovate/ghcr.io-berriai-litellm-1.x
git switch main
git merge renovate/ghcr.io-berriai-litellm-1.x
git push origin main
Sign in to join this conversation.
No description provided.