LiteLLM v1.104.0: Docker Image Signing, Stricter Auth, and Video Gen Updates
LiteLLM's latest release brings Docker image signing with cosign, breaking changes to proxy auth requiring a strong master key, new password security features, and support for Seedance video generation via FAL queue API.
What changed?
LiteLLM v1.104.0 introduces several security-focused, API, and feature changes: - All Docker images are now signed with Cosign for provenance verification. Each release is signed with the same key, anchored to commit 0112e53. - Breaking security enhancement: The LiteLLM proxy will now refuse to start unless the master key is set to a value that is neither unset, empty, nor a publicly known key. Default values in configs like "sk-1234" are now invalid and blocked. - Authentication improvements: breached password detection is added to the password policy, self-service password change is enabled, and forced password resets apply to breached or admin-set passwords. - New integration: Support for Seedance 2.5/2.0 video generation via the FAL queue API. - Various fixes and small enhancements, including improved JWT user deactivation checks, error handling, and expanded parameter passing for Google GenAI.
Why does it matter to an everyday developer?
These updates directly improve the security and usability of LiteLLM deployments: - Docker image signing with Cosign enables developers to verify they are running official, unmodified containers. This is critical for supply chain security. - The master key change is a breaking change: deployments with unset, empty, or common master keys will now fail to start. Developers must ensure strong, unique keys are set for deployments. - Breached password detection, forced password resets, and self-service account management harden authentication—protecting both developers and end users against common security threats. - Expanded video generation support allows developers building media, creative, or LLM-powered video tooling to leverage the latest Seedance models via FAL.
What can the developer do now?
- Verify Docker images before deployment using Cosign and the provided public key and commit hash.
