logoalt Hacker News

kingreflexyesterday at 6:10 PM1 replyview on HN

we're using litellm via helm charts with tags main-v1.81.12-stable.2 and main-v1.80.8-stable.1 - assuming they're safe?

also how are we sure that docker images aren't affected?


Replies

saltyoldmanyesterday at 6:37 PM

Docker deployments are more safe even if affected because there is a lower chance (but not zero) that you didn't mount all your credentials into the image. It would have access to LLM keys of course, but that's not really what the hacker is after. He's after private SSH keys.

That being said this hack was a direct upload to PyPI in the last few days, so very unlikely those images are affected.