Tools
LiteLLM's 1.103.0 dev cut requires admission for delegated MCP OAuth and bounds a LoggingWorker timeout burst
v1.103.0-dev.1, published 2026-09-16, includes fix(mcp) requiring admission for delegated OAuth (#40923), one bounded summary log for a burst of timed-out LoggingWorker callbacks instead of per-callback spam (#40912), bounding tool and guardrail index create_many by the spend-log statement budgets (#40561), and gating the webhook test alert on proxy admins (#40814). The release body also documents cosign verification of the Docker image against a key pinned to commit 0112e53, recommending the commit-hash form over the tag form because tag protection is a weaker guarantee.
Source
↳ Follow the thread