Skip to content

Bump litellm from 1.58.2 to 1.84.0 in /Complete Project - CrewAI Study Buddy/4 - Local LLM Configuration#29

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/Complete-Project---CrewAI-Study-Buddy/4---Local-LLM-Configuration/litellm-1.84.0
Open

Bump litellm from 1.58.2 to 1.84.0 in /Complete Project - CrewAI Study Buddy/4 - Local LLM Configuration#29
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/Complete-Project---CrewAI-Study-Buddy/4---Local-LLM-Configuration/litellm-1.84.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown

Bumps litellm from 1.58.2 to 1.84.0.

Release notes

Sourced from litellm's releases.

v1.84.0

⚠️ Heads up — this release contains breaking changes. Read the full release notes here: v1.84.0 release notes


Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.84.0

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.84.0/cosign.pub \
  ghcr.io/berriai/litellm:v1.84.0

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

... (truncated)

Commits
  • e1fc955 Merge pull request #27909 from BerriAI/backport/27908-litellm_1.84.0rc2
  • fcd63b0 uv lock
  • 0f741fc bump: version 0.4.71 → 0.4.72
  • 321d576 Merge pull request #27904 from BerriAI/backport/27878-litellm_1.84.0rc2
  • fe18665 Merge remote-tracking branch 'origin/litellm_1.84.0rc2' into backport/27878-l...
  • 087003e Merge pull request #27903 from BerriAI/backport/27892-litellm_1.84.0rc2
  • d35d2a7 fix: harden /key/update authorization checks (#27878)
  • b2c93b1 fix: block SSRF fields in RAG ingest vector_store config
  • fdb55ab fix: block client-side pricing injection via request body
  • 08ea016 Merge pull request #27902 from BerriAI/litellm_/eager-euler-fd3639
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [litellm](https://github.com/BerriAI/litellm) from 1.58.2 to 1.84.0.
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.58.2...v1.84.0)

---
updated-dependencies:
- dependency-name: litellm
  dependency-version: 1.84.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jun 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Development

Successfully merging this pull request may close these issues.

0 participants