LiteLLM v1.106.0-dev.3: Docker Images Now Signed, More Provider Support, and Observability Upgrades
The latest LiteLLM release improves Docker supply chain security through cosign signatures, provides expanded support for model providers, and introduces new observability features for rate limits and evaluation workflows.
What changed?
LiteLLM v1.106.0-dev.3 introduces verified cosign signatures for all LiteLLM Docker images, using a public key tied to a pinned commit for validation. The release also adds support for more model providers (TypeSafe, Strands Decider) in the UI, expands OAuth client identity handling, and exposes new Prometheus metrics for per-project and per-model rate limit usage. Developers can now use a command palette (Cmd+K) in the UI, add models in an evaluation mode, and handle new embedding file blocks for Gemini models.
Why does it matter to an everyday developer?
Docker image signature verification significantly reduces the risk of supply chain attacks, ensuring the images you pull are unmodified and authentic. Expanded provider support allows teams to integrate with a broader set of LLM backends, while enhanced Prometheus metrics let users monitor and set rate limits at finer granularity. Usability enhancements, like the command palette, improve workflow efficiency when managing models.
What can the developer do now?
Developers using LiteLLM should update their workflows to verify Docker images with cosign, using either the pinned commit hash (recommended for security) or the release tag for convenience. Teams can configure Prometheus dashboards to track rate usage by project and model, integrate additional providers through the UI, and take advantage of new evaluation and workflow improvements for model management.
