SecurityLiteLLM
LiteLLM v1.103.2: Docker Image Signature Verification with cosign
LiteLLM v1.103.2 introduces a signed Docker image using cosign, with clear verification instructions, and includes several backported fixes.
Docker Image Signature Verification
All LiteLLM Docker images are now cryptographically signed using cosign. Every release uses the same public key introduced in commit 0112e53. This enhances supply chain security and allows developers to verify the authenticity of images before deploying them.
How to Verify Image Signatures
You should always verify the Docker image signature before use. There are two official methods:
- Using the pinned commit hash (recommended): ensures cryptographic immutability.
- Using the release tag: more convenient, relies on repository tag protection.
bashofficial example
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
ghcr.io/berriai/litellm:v1.103.2bashofficial example
cosign verify \
--key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.2/cosign.pub \
ghcr.io/berriai/litellm:v1.103.2Bug Fixes and Backports
This release also includes important proxy and Anthropic-related bug fixes that have been backported from recent pull requests to the stable branch.
