Skip to content

fix(container): update image ghcr.io/berriai/litellm-non_root ( v1.103.1 ➔ v1.103.2 ) - #1908

Open
mortyops[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-berriai-litellm-non_root-1.x
Open

mortyops[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-berriai-litellm-non_root-1.x

Conversation

@mortyops

@mortyops mortyops Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/berriai/litellm-non_root (source) patch v1.103.1 → v1.103.2

Release Notes

BerriAI/litellm (ghcr.io/berriai/litellm-non_root)

v1.103.2

Compare Source

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.103.1...v1.103.2


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

…3.1 ➔ v1.103.2 )

| datasource | package                          | from     | to       |
| ---------- | -------------------------------- | -------- | -------- |
| docker     | ghcr.io/berriai/litellm-non_root | v1.103.1 | v1.103.2 |
@mortyops

mortyops Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author
--- Deployment ai/opencode
+++ Deployment ai/opencode
@@ -43,7 +43,7 @@
         envFrom:
         - secretRef:
             name: opencode
-        image: ghcr.io/joryirving/opencode:2.0.21@sha256:60308f634451b972bc139ec89aee973b9eec90dc76cffd338dc635574802d9c8
+        image: ghcr.io/joryirving/opencode:2.0.20@sha256:c09cca0a23cf230028af830afed0ec35eb8418380ccf48f3dd878f87d701f8d4
         livenessProbe:
           failureThreshold: 5
           initialDelaySeconds: 30

@mortyops

mortyops Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author
--- LiteLLMProxy ai/litellm
+++ LiteLLMProxy ai/litellm
@@ -85,7 +85,7 @@
       target: http://127.0.0.1:9/anthropic-pass-through-locked
     store_model_in_db: false
     store_prompts_in_spend_logs: true
-  image: ghcr.io/berriai/litellm-non_root:v1.103.1
+  image: ghcr.io/berriai/litellm-non_root:v1.103.2
   litellmSettings:
     cache: true
     cache_params:

--- HelmRelease ai/opencode
+++ HelmRelease ai/opencode
@@ -51,7 +51,7 @@
                 name: opencode
             image:
               repository: ghcr.io/joryirving/opencode
-              tag: 2.0.21@sha256:60308f634451b972bc139ec89aee973b9eec90dc76cffd338dc635574802d9c8
+              tag: 2.0.20@sha256:c09cca0a23cf230028af830afed0ec35eb8418380ccf48f3dd878f87d701f8d4
             probes:
               liveness:
                 custom: true

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

✅ Automated recommendation: APPROVE

Analysis engine: pr-review-local@http://litellm.ai.svc.cluster.local:4000/v1 (openai)

Recommendation

Approve. This is a standard Renovate patch update for ghcr.io/berriai/litellm-non_root from v1.103.1 to v1.103.2. The diff is minimal, consistent, and safe.

Change-by-Change Findings

1. kubernetes/apps/base/ai/litellm/app/litellmproxy.yaml

  • Image Update: Updated image from v1.103.1 to v1.103.2.
  • Consistency: The version aligns with the Renovate constraint and the pin comment below the image field (floor v1.93.0).
  • Safety: This is a patch update within the 1.103.x stable branch, containing only bug fixes (proxy and Anthropic fixes) as per the release notes.

2. .github/workflows/validate.yaml

  • CI Consistency: Updated LITELLM_VERSION environment variable from v1.103.1 to v1.103.2.
  • Verification: This ensures the CI validation step uses the same version as the deployed manifest, preventing false negatives in CI due to version drift.

Standards Compliance

  • Renovate Handling: The PR is a pure patch bump with no other changes, which the standards explicitly state is "normally fine".
  • No Secrets: No secrets are present in the diff.
  • Flux/Kustomize: No changes to Kustomization overlays or Flux HelmRelease structures that would trigger postBuild.substitute issues.
  • Commit Message: Follows the fix(container): ... convention.

Tool Harness Findings

  • Tool harness was disabled.

Unknowns or Needs Verification

  • None. The change is self-contained and deterministic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants