v1.90.5
BerriAI/litellmv1.90.5Jul 17, 2026by yuneng-berri
AI Summary
This release introduces cryptographic verification for LiteLLM Docker images using cosign and includes a backport of changes from PR #33592 to the stable branch.
Key Highlights
- Docker images are now signed with cosign for enhanced security verification.
- Instructions provided to verify images using either a pinned commit hash or the release tag.
- Includes backport of PR #33592 to stable/1.90.x.
- Standard release cut for version 1.90.5.
New Features
- Docker image signature verification using cosign.
- Verification methods via commit hash or release tag.
Full Release Notes
## Verify Docker Image Signature All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0). **Verify using the pinned commit hash (recommended):** A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \ ghcr.io/berriai/litellm:v1.90.5 ``` **Verify using the release tag (convenience):** Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules: ```bash cosign verify \ --key https://raw.githubusercontent.com/BerriAI/litellm/v1.90.5/cosign.pub \ ghcr.io/berriai/litellm:v1.90.5 ``` Expected output: ``` The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key ``` --- ## What's Changed * chore(release): backport #33592 to stable/1.90.x and cut 1.90.5 by @yuneng-berri in https://github.com/BerriAI/litellm/pull/33610 **Full Changelog**: https://github.com/BerriAI/litellm/compare/v1.90.4...v1.90.5