From 9d43a8a7677e38b84cf565e354dd12d526197a14 Mon Sep 17 00:00:00 2001 From: Lukas Babaliauskas Date: Wed, 30 Sep 2026 00:47:49 +0200 Subject: [PATCH] docs: list DEEPSEEK_API_KEY among provider keys Co-Authored-By: Claude Opus 5.5 (1M context) --- DOCS.md | 1 + README.md | 1 + llms-full.txt | 1 + tests/test_evalshift_action.py | 11 +++++++++++ 4 files changed, 14 insertions(+) diff --git a/DOCS.md b/DOCS.md index 8fb52bd..31b79bd 100644 --- a/DOCS.md +++ b/DOCS.md @@ -213,6 +213,7 @@ job-level `env:` entry and the CLI picks it up. | Anthropic | `ANTHROPIC_API_KEY` | | OpenAI | `OPENAI_API_KEY` | | Google | `GEMINI_API_KEY` or `GOOGLE_API_KEY` | +| DeepSeek | `DEEPSEEK_API_KEY` | Which key you need follows from `defaults.source_model` and `defaults.target_model` in your `evalshift.yaml`. Comparing across two providers means both keys: diff --git a/README.md b/README.md index 23dc065..1d92342 100644 --- a/README.md +++ b/README.md @@ -147,6 +147,7 @@ CLI picks it up. | Anthropic | `ANTHROPIC_API_KEY` | | OpenAI | `OPENAI_API_KEY` | | Google | `GEMINI_API_KEY` or `GOOGLE_API_KEY` | +| DeepSeek | `DEEPSEEK_API_KEY` | Which key you need follows from `defaults.source_model` and `defaults.target_model` in your `evalshift.yaml`. Comparing models across two diff --git a/llms-full.txt b/llms-full.txt index ae438be..a30bf91 100644 --- a/llms-full.txt +++ b/llms-full.txt @@ -519,6 +519,7 @@ stderr warnings; the gate still fails the job correctly. | Anthropic | ANTHROPIC_API_KEY | | OpenAI | OPENAI_API_KEY | | Google | GEMINI_API_KEY or GOOGLE_API_KEY | +| DeepSeek | DEEPSEEK_API_KEY | Which key is required follows from `defaults.source_model` / `defaults.target_model` in `evalshift.yaml`. A cross-provider migration needs both keys. `EVALSHIFT_NONINTERACTIVE: "1"` diff --git a/tests/test_evalshift_action.py b/tests/test_evalshift_action.py index 63980b6..cf4615b 100644 --- a/tests/test_evalshift_action.py +++ b/tests/test_evalshift_action.py @@ -1948,3 +1948,14 @@ def create_status(self, *args: Any, **kwargs: Any) -> None: ) assert "warning: could not set commit status" in capsys.readouterr().err + + +def test_provider_keys_are_redacted_including_deepseek() -> None: + # Keys reach the CLI through the job env untouched; the log redactor + # matches on the `_API_KEY` suffix, so a new provider needs no code change. + env = { + "ANTHROPIC_API_KEY": "sk-ant-secret", + "DEEPSEEK_API_KEY": "sk-deepseek-secret", + "HOME": "/home/runner", + } + assert sorted(action._secret_values(env)) == ["sk-ant-secret", "sk-deepseek-secret"]