Skip to content

Update dependency sbt/sbt to v1.12.13#89

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/sbt-sbt-1.x
Open

Update dependency sbt/sbt to v1.12.13#89
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/sbt-sbt-1.x

Conversation

@renovate

@renovate renovate Bot commented Mar 4, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
sbt/sbt minor 1.10.71.12.13

Release Notes

sbt/sbt (sbt/sbt)

v1.12.13: 1.12.13

Compare Source

🐛 bug fixes

Full Changelog: sbt/sbt@v1.12.12...v1.12.13

v1.12.12: 1.12.12

Compare Source

bug fixes

behind the scenes

Full Changelog: sbt/sbt@v1.12.11...v1.12.12

v1.12.11: 1.12.11

Compare Source

bug fix

Full Changelog: sbt/sbt@v1.12.10...v1.12.11

v1.12.10: 1.12.10

Compare Source

updates

🐛 bug fixes

behind the scenes

new contributors

Full Changelog: sbt/sbt@v1.12.9...v1.12.10

v1.12.9: 1.12.9

Compare Source

Updates

Full Changelog: sbt/sbt@v1.12.8...v1.12.9

v1.12.8: 1.12.8

Compare Source

updates

behind the scenes

Full Changelog: sbt/sbt@v1.12.7...v1.12.8

v1.12.7: 1.12.7

Compare Source

CVE-2026-32948 Source dependency feature (via crafted VCS URL) leading to arbitrary code execution on Windows

sbt 1.12.7 fixes CVE-2026-32948 (GHSA-x4ff-q6h8-v7gw). Recently @​anatoliykmetyuk at Scala Center discovered a vulnerability in sbt's source dependency feature ProjectRef(...) and RootProject(...). The URL for the version control system allows branch specification via the URL fragment, which is passed to Windows cmd shell. A malicious user can craft an URL that allows arbitrary code execution.

Anatolii also provided a fix from a private fork 1ce945 and 3a474a. We recommend upgrading to sbt 1.12.7, especially if you're on Windows.

updates

Full Changelog: sbt/sbt@v1.12.6...v1.12.7

v1.12.6: 1.12.6

Compare Source

updates

Full Changelog: sbt/sbt@v1.12.5...v1.12.6

v1.12.5: 1.12.5

Compare Source

updates

🐛 bug fixes

Full Changelog: sbt/sbt@v1.12.4...v1.12.5

v1.12.4: 1.12.4

Compare Source

  • backport: Respect scalaOrganization in compiler bridge resolution by @​tanishiking in #​8799
  • backport: Fixes .jvmopts parse error on Windows Git Bash by reverting "Handle JVM parameters with spaces in dot files" by @​eed3si9n in #​8798

Full Changelog: sbt/sbt@v1.12.3...v1.12.4

v1.12.3: 1.12.3

Compare Source

updates

Full Changelog: sbt/sbt@v1.12.2...v1.12.3

v1.12.2: 1.12.2

Compare Source

updates

Full Changelog: sbt/sbt@v1.12.1...v1.12.2

v1.12.1: 1.12.1

Compare Source

bug fixes

behind the scenes

Full Changelog: sbt/sbt@v1.12.0...v1.12.1

v1.12.0: 1.12.0

Compare Source

changes with compatibility implications

  • dependencyTree displays internal config, which includes Provided by @​eed3si9n in #​8359
  • Scaladoc now requires Compile / doc / compilers scoped to doc task

🚀 updates

🐛 bug fixes

behind the scenes

new contributors

Full Changelog: sbt/sbt@v1.11.7...v1.12.0

v1.11.7: 1.11.7

Compare Source

🚀 updates
🐛 bug fixes
🎬 behind the scenes

Full Changelog: sbt/sbt@v1.11.6...v1.11.7

v1.11.6: 1.11.6

Compare Source

🚀 sbt launcher 1.5.0
🐛 bug fixes
🎬 behind the scene

Full Changelog: sbt/sbt@v1.11.5...v1.11.6

v1.11.5: 1.11.5

Compare Source

changes with compatibility implications
  • sbtn is built using ubuntu-22.04 image, which will require similar Linux version with glibc 2.32 and above.
🚀 features and other updates
  • Adds Scala 3.8.0 support. See below
  • Adds Scala Nightly repository resolver. See below
  • Adds --jvm-client to the sbt runner script to launch JVM client. See below
  • Central Repository publishing: Shows validation errors if present by @​unkarjedy in #​8191
  • Central Repository publishing: Includes the root subproject name into the deployment by @​jeanmarc in #​8219
  • Reduces sbtn outputs by @​eed3si9n in #​8234
Scala Nightly repository

Scala Team now publishes nightlies to a dedicated Artifactory instance. sbt 1.11.5 adds a new resolver for this:

resolvers += Resolver.scalaNightlyRepository

ThisBuild / scalaVersion := "3.8.0-RC1-bin-20250823-712d5bc-NIGHTLY"
Compile / scalacOptions += "-language:experimental.captureChecking"

This was contributed by @​hamzaremmal in sbt/librarymanagement#532

Scala 3.8.0 support

Scala 3.8.0 will in-source the Scala standard library (scala-library) instead of using one from Scala 2.13. sbt 1.11.5 relaxes the Coursier same-version enforcement to support Scala 3.8.0.

This was pair programmed by @​hamzaremmal + @​eed3si9n during Scala Days 2025 as #​8226

sbt --jvm-client

sbt 1.11.5 runner script adds new --jvm-client flag to launch the JVM version of the thin client. The implementation is the Scala code which sbtn is based on. This will be useful on platforms or CPU architectures that we do not build sbtn.

This was contributed by @​eed3si9n in #​8232

🎬 behind the scene
new contributors

Full Changelog: sbt/sbt@v1.11.4...v1.11.5

v1.11.4: 1.11.4

Compare Source

Updates

Full Changelog: sbt/sbt@v1.11.3...v1.11.4

v1.11.3: 1.11.3

Compare Source

updates

  • Adds sonaUploadRequestTimeout setting to configure the upload timeout when publishing to the Central Repo by @​guizmaii in #​8171
  • fix: Adds support for pluginCrossBuild/sbtBinaryVersion "1.3", which is used by IntelliJ Scala plugin (fixes #​8166) by @​unkarjedy in #​8167
  • fix: Fixes the import order to satisfy SemanticDB by @​inglor in #​8162

new contributors

Full Changelog: sbt/sbt@v1.11.2...v1.11.3

v1.11.2: 1.11.2

Compare Source

updates

Full Changelog: sbt/sbt@v1.11.1...v1.11.2

v1.11.1: 1.11.1

Compare Source

updates

behind the scene

Full Changelog: sbt/sbt@v1.11.0...v1.11.1

v1.11.0: 1.11.0

Compare Source

Central Repository publishing

The Central Repository (aka Maven Central) has long been the pillar of the JVM ecosystem including Scala. The mechanism to publish libraries to the Central has been hosted by Sonatype as OSS Repository Hosting (OSSRH) via HTTP PUT, but in March it was announced that the endpoint will be sunset in June 2025 in favor of the Central Portal at https://central.sonatype.com/.

sbt 1.11.0 implements a built-in support to publish to Central Repository via the Central Portal. To publish to the Central Portal, first set ThisBuild / publishTo setting to the localStaging repository:

ThisBuild / publishTo := {
  val centralSnapshots = "https://central.sonatype.com/repository/maven-snapshots/"
  if (isSnapshot.value) Some("central-snapshots" at centralSnapshots)
  else localStaging.value
}

Add credentials to the host central.sonatype.com using the generated user token user name and password. sbt 1.11.0 will read from the environment variables SONATYPE_USERNAME and SONATYPE_PASSWORD and append a credential for central.sonatype.com out-of-box, which might be useful for automatic publishing from the CI environment, such as GitHub Actions.

- run: sbt ci-release
  env:
    PGP_PASSPHRASE: ${{ secrets.PGP_PASSPHRASE }}
    PGP_SECRET: ${{ secrets.PGP_SECRET }}
    SONATYPE_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }}
    SONATYPE_USERNAME: ${{ secrets.SONATYPE_USERNAME }}

When you're ready to publish, call publishSigned task (available via sbt-pgp). At this point, the JARs and POM files will be staged to your local target/sona-staging directory.

Next, call sonaUpload to upload to the Central Portal and manually release the bundle, or call sonaRelease to upload and automatically release to the Central Repository.

This was contributed by @​eed3si9n in #​8126. The feature was inspired by sbt-sonatype workflow pioneered by Taro Saito, and sonatype-central-client spearheaded by David Doyle at Lumidion.

Other updates

Full Changelog: sbt/sbt@v1.10.11...v1.11.0

v1.10.11: 1.10.11

Compare Source

updates

🐛 bug fixes

Full Changelog: sbt/sbt@v1.10.10...v1.10.11

v1.10.10: 1.10.10

Compare Source

🐛 bug fixes

  • fix: Fixes compilation error causing the compilation to retry ten times by @​eed3si9n in #​8054

Full Changelog: sbt/sbt@v1.10.9...v1.10.10

v1.10.9: 1.10.9

Compare Source

🚀 features and other updates

🐛 bug fixes

🎬 behind the scene

new contributors

Full Changelog: sbt/sbt@v1.10.7...v1.10.9

v1.10.8: 1.10.8

Compare Source

sbt 1.10.8 is dead on arrival, please use 1.10.9 when it comes out.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.10.9 Update dependency sbt/sbt to v1.10.10 Mar 4, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 8d2e092 to fd63494 Compare March 4, 2025 11:14
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.10.10 Update dependency sbt/sbt to v1.10.11 Mar 17, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from fd63494 to dd2f997 Compare March 17, 2025 07:03
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from dd2f997 to dc713ed Compare May 24, 2025 09:43
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.10.11 Update dependency sbt/sbt to v1.11.0 May 24, 2025
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.0 Update dependency sbt/sbt to v1.11.1 Jun 2, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from dc713ed to 1938183 Compare June 2, 2025 09:17
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.1 Update dependency sbt/sbt to v1.11.2 Jun 7, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 1938183 to 49b5e1b Compare June 7, 2025 21:31
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.2 Update dependency sbt/sbt to v1.11.3 Jul 6, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 49b5e1b to 963b20a Compare July 6, 2025 02:04
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.3 Update dependency sbt/sbt to v1.11.4 Aug 4, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 963b20a to d8df919 Compare August 4, 2025 15:23
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from d8df919 to 946de6e Compare August 24, 2025 21:02
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.4 Update dependency sbt/sbt to v1.11.5 Aug 24, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 946de6e to 8c9f6a0 Compare September 7, 2025 00:40
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.5 Update dependency sbt/sbt to v1.11.6 Sep 7, 2025
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 8c9f6a0 to 9805dd3 Compare October 5, 2025 20:36
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.6 Update dependency sbt/sbt to v1.11.7 Oct 5, 2025
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.11.7 Update dependency sbt/sbt to v1.12.0 Jan 5, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 9805dd3 to d4a5f3a Compare January 5, 2026 04:56
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from d4a5f3a to 008a440 Compare January 26, 2026 12:49
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.0 Update dependency sbt/sbt to v1.12.1 Jan 26, 2026
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.1 Update dependency sbt/sbt to v1.12.2 Feb 4, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 008a440 to aae48e8 Compare February 4, 2026 09:38
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.2 Update dependency sbt/sbt to v1.12.3 Feb 15, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from aae48e8 to b1eced1 Compare February 15, 2026 01:06
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from b1eced1 to 344e30d Compare February 23, 2026 12:56
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.3 Update dependency sbt/sbt to v1.12.4 Feb 23, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 344e30d to f072908 Compare March 2, 2026 02:18
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.4 Update dependency sbt/sbt to v1.12.5 Mar 2, 2026
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.5 Update dependency sbt/sbt to v1.12.6 Mar 16, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from f072908 to 365fafd Compare March 16, 2026 05:14
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 365fafd to 96f0f2c Compare March 24, 2026 01:55
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.6 Update dependency sbt/sbt to v1.12.7 Mar 24, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 96f0f2c to 8d8c80a Compare March 25, 2026 05:32
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.7 Update dependency sbt/sbt to v1.12.8 Mar 25, 2026
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.8 Update dependency sbt/sbt to v1.12.9 Apr 7, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 8d8c80a to 157c0cb Compare April 7, 2026 05:34
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 157c0cb to 73eb101 Compare April 27, 2026 09:27
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.9 Update dependency sbt/sbt to v1.12.10 Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 73eb101 to 5e35b6a Compare May 3, 2026 01:12
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.10 Update dependency sbt/sbt to v1.12.11 May 3, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 5e35b6a to 4d66d72 Compare June 14, 2026 08:53
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.11 Update dependency sbt/sbt to v1.12.12 Jun 14, 2026
@renovate renovate Bot force-pushed the renovate/sbt-sbt-1.x branch from 4d66d72 to 069b422 Compare June 22, 2026 02:57
@renovate renovate Bot changed the title Update dependency sbt/sbt to v1.12.12 Update dependency sbt/sbt to v1.12.13 Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants