Commit fae4ca4
committed
fix: pin liteLLM upper bound to 1.82.6 to mitigate supply chain attack
liteLLM versions 1.82.7 and 1.82.8 were compromised by the TeamPCP group
via a supply chain attack. This pins the upper bound to the last known
safe version.
References:
- BerriAI/litellm#24512
- https://osv.dev/vulnerability/MAL-2026-21441 parent 4b38c86 commit fae4ca4
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
0 commit comments