Verify Docker Image Signature
All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.
Verify using the pinned commit hash (recommended):
A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:
cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \ ghcr.io/berriai/litellm:v1.82.6.rc.4
Verify using the release tag (convenience):
Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:
cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/v1.82.6.rc.4/cosign.pub \ ghcr.io/berriai/litellm:v1.82.6.rc.4
Expected output:
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
What's Changed
- feat(router): order-based fallback across deployment priority levels by @Sameerlite in #24611
- fix(routing): prevent cross-team deployment leakage in fallback path by @Sameerlite
- fix(routing): prevent stale model_aliases from interfering with team routing by @Sameerlite
- fix(management): query DB directly for sibling deployments on rename by @Sameerlite
- feat(router): add health-check-driven routing behind opt-in flag by @Sameerlite
- feat(router): add health_check_ignore_transient_errors flag by @Sameerlite
- feat(router): integrate allowed_fails_policy into health check failures by @Sameerlite
- docs(router): add health check driven routing guide by @Sameerlite
- fix(health-check-routing): fix P0 cooldown integration never firing by @Sameerlite
- fix(health-check-routing): fix P1 transient-error filter broken on cache hits by @Sameerlite
- fix: address Greptile review feedback on key rotation lock by @Harshit28j
- fix(docker): include enterprise bridge in non-root runtime image by @Sameerlite
- fix(docker): guard .npmrc mv in non-root Dockerfile by @yuneng-berri
- fix: sync circleci config with main, add node-gyp fix for non-root Dockerfile by @yuneng-berri
Full Changelog: v1.82.6.rc.2...v1.82.6.rc.4



