Vendor-reported

LiteLLM v1.99.0 release notes describe Docker image signature verification

Published: 1 September 2026 Last checked: 1 September 2026 Source: primary

Summary

The release notes for LiteLLM v1.99.0 state that all Docker images are signed with cosign, using a key introduced in a specific commit. The notes explain how to verify the image signature.

TRACE Analysis

The source is a release note excerpt that focuses solely on the security feature of image signing. It does not mention any functional changes or bug fixes, so the update may be primarily a security or documentation enhancement. However, the excerpt is partial, so there may be other changes not covered.

Why this matters

This matters because it provides users with a method to verify the integrity and authenticity of LiteLLM Docker images, reducing supply chain risk.

vendor_reported

Information originates from a vendor. Independent verification is pending or not yet available.

Why this rating?
Source class primary

Primary source — direct from official documentation, research paper, or specification.

Source tier Not assessed

Claim-level source tier has not yet been determined from reviewed evidence records.

Corroboration Not assessed

Independent corroboration has not yet been determined from reviewed claim assertions.

Independent verification Not assessed

Independent verification has not yet been determined from reviewed claim assertions.

Conflict of interest Low risk

No obvious commercial conflict of interest identified.

Timeliness 8 days ago

Last checked 8 days ago — still within acceptable range.

Reproducibility Not assessed

Reproducibility has not yet been determined from reviewed claim assertions.

Sources

Claim-level evidence

No claim-level evidence has been publicly resolved for this story yet. The source links above are references, not a claim-level corroboration count.