Commit f049276
SECURITY: Pin litellm to safe versions (supply chain attack)
litellm PyPI versions 1.82.7 and 1.82.8 were compromised by attacker
TeamPCP with credential-stealing malware. See:
BerriAI/litellm#24518
Pinned to known-safe versions:
- backend: litellm==1.82.1
- notebooks: litellm==1.82.6
Do NOT upgrade until BerriAI confirms PyPI is clean.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>1 parent f234396 commit f049276
2 files changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | | - | |
| 17 | + | |
18 | 18 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
0 commit comments