Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions DOCS.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,6 +213,7 @@ job-level `env:` entry and the CLI picks it up.
| Anthropic | `ANTHROPIC_API_KEY` |
| OpenAI | `OPENAI_API_KEY` |
| Google | `GEMINI_API_KEY` or `GOOGLE_API_KEY` |
| DeepSeek | `DEEPSEEK_API_KEY` |

Which key you need follows from `defaults.source_model` and `defaults.target_model` in your
`evalshift.yaml`. Comparing across two providers means both keys:
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,7 @@ CLI picks it up.
| Anthropic | `ANTHROPIC_API_KEY` |
| OpenAI | `OPENAI_API_KEY` |
| Google | `GEMINI_API_KEY` or `GOOGLE_API_KEY` |
| DeepSeek | `DEEPSEEK_API_KEY` |

Which key you need follows from `defaults.source_model` and
`defaults.target_model` in your `evalshift.yaml`. Comparing models across two
Expand Down
1 change: 1 addition & 0 deletions llms-full.txt
Original file line number Diff line number Diff line change
Expand Up @@ -519,6 +519,7 @@ stderr warnings; the gate still fails the job correctly.
| Anthropic | ANTHROPIC_API_KEY |
| OpenAI | OPENAI_API_KEY |
| Google | GEMINI_API_KEY or GOOGLE_API_KEY |
| DeepSeek | DEEPSEEK_API_KEY |

Which key is required follows from `defaults.source_model` / `defaults.target_model` in
`evalshift.yaml`. A cross-provider migration needs both keys. `EVALSHIFT_NONINTERACTIVE: "1"`
Expand Down
11 changes: 11 additions & 0 deletions tests/test_evalshift_action.py
Original file line number Diff line number Diff line change
Expand Up @@ -1948,3 +1948,14 @@ def create_status(self, *args: Any, **kwargs: Any) -> None:
)

assert "warning: could not set commit status" in capsys.readouterr().err


def test_provider_keys_are_redacted_including_deepseek() -> None:
# Keys reach the CLI through the job env untouched; the log redactor
# matches on the `_API_KEY` suffix, so a new provider needs no code change.
env = {
"ANTHROPIC_API_KEY": "sk-ant-secret",
"DEEPSEEK_API_KEY": "sk-deepseek-secret",
"HOME": "/home/runner",
}
assert sorted(action._secret_values(env)) == ["sk-ant-secret", "sk-deepseek-secret"]
Loading