v1.86.5

BerriAI/litellmv1.86.5Jun 11, 2026by github-actions[bot]

AI Summary

A minor maintenance release ensuring Docker image integrity through cryptographic signing and backporting three specific PRs to the stable 1.86.x branch.

Key Highlights

  • Docker images are now signed with cosign for cryptographic verification
  • Backport of PR #30064
  • Backport of PR #29991
  • Backport of PR #30009

New Features

  • Docker image signature verification
  • Backported features from PRs #30064, #29991, and #30009

Full Release Notes

## Verify Docker Image Signature

All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0).

**Verify using the pinned commit hash (recommended):**

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.86.5
```

**Verify using the release tag (convenience):**

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.86.5/cosign.pub \
  ghcr.io/berriai/litellm:v1.86.5
```

Expected output:

```
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key
```

---
## What's Changed
* chore(release): backport #30064, #29991, #30009 to stable/1.86.x and cut 1.86.5 by @mateo-berri in https://github.com/BerriAI/litellm/pull/30148


**Full Changelog**: https://github.com/BerriAI/litellm/compare/v1.86.4...v1.86.5