Conversation
📝 WalkthroughWalkthroughThe project updates Scala and SBT versions, adds binary compatibility and Scalafmt configuration, reformats source files, and replaces inline CI and release jobs with reusable workflows. ChangesBuild and automation modernization
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 10-11: Update the reusable release workflow reference in the
workflow job to use commit SHA b4557d9a82c03596dc2425e19b3cb9a6280a4739 instead
of the mutable v5 tag, while retaining the # v5 annotation. Replace secrets:
inherit with explicit exposure of only JFROG_ACCESS_TOKEN and GITHUB_TOKEN.
In `@build.sbt`:
- Line 1: Update the compatibility configuration in build.sbt to align with
crossScalaVersions: either restore Scala 2.12 support, or set
versionPolicyIntention to Compatibility.None and increment the major version for
the next release. Preserve the existing binary compatibility policy only when
Scala 2.12 remains published.
In `@src/main/scala/com/evolutiongaming/crypto/Crypto.scala`:
- Around line 124-127: Update the Scaladoc heading for AES_V2 to say “AES legacy
V2 mode support” instead of “AES legacy V1 mode support”; leave the surrounding
documentation unchanged.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 3cfdf9fa-14f0-4977-b056-f617e1ddabac
📒 Files selected for processing (11)
.github/workflows/ci.yml.github/workflows/release.yml.scalafmt.confbuild.sbtproject/build.propertiesproject/plugins.sbtsrc/main/scala/com/evolutiongaming/crypto/Crypto.scalasrc/main/scala/com/evolutiongaming/crypto/DecryptConfig.scalasrc/main/scala/com/evolutiongaming/crypto/Encrypt.scalasrc/test/scala/com/evolutiongaming/crypto/CryptoSpec.scalaversion.sbt
💤 Files with no reviewable changes (1)
- version.sbt
| uses: evolution-gaming/scala-github-actions/.github/workflows/release.yml@v5 | ||
| secrets: inherit |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
repo="evolution-gaming/scala-github-actions"
sha="$(gh api "repos/${repo}/commits/v5" --jq '.sha')"
printf 'Pin release.yml to: %s\n' "$sha"
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
--jq '.content' | base64 --decodeRepository: evolution-gaming/crypto
Length of output: 2250
🏁 Script executed:
#!/bin/bash
set -euo pipefail
repo="evolution-gaming/scala-github-actions"
tag_ref="$(gh api "repos/${repo}/git/refs/tags/v5")"
printf '%s\n' "$tag_ref" | jq '{ref, object}'
type="$(printf '%s' "$tag_ref" | jq -r '.object.type')"
sha="$(printf '%s' "$tag_ref" | jq -r '.object.sha')"
if [ "$type" = "tag" ]; then
sha="$(gh api "repos/${repo}/git/tags/${sha}" --jq '.object.sha')"
fi
printf 'Dereferenced v5 commit: %s\n' "$sha"
gh api "repos/${repo}/commits/${sha}" --jq '.sha'
printf '\nSecret references in the called workflow:\n'
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
--jq '.content' | base64 --decode | rg -n 'secrets\.|secrets:|JFROG_ACCESS_TOKEN|GITHUB_TOKEN' || trueRepository: evolution-gaming/crypto
Length of output: 713
Pin the reusable release workflow to commit b4557d9a82c03596dc2425e19b3cb9a6280a4739.
The workflow references only JFROG_ACCESS_TOKEN and GITHUB_TOKEN. Replace @v5 with the commit SHA and retain # v5. Avoid secrets: inherit if the caller exposes additional secrets.
🧰 Tools
🪛 zizmor (1.29.0)
[warning] 10-10: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow
(secrets-inherit)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/release.yml around lines 10 - 11, Update the reusable
release workflow reference in the workflow job to use commit SHA
b4557d9a82c03596dc2425e19b3cb9a6280a4739 instead of the mutable v5 tag, while
retaining the # v5 annotation. Replace secrets: inherit with explicit exposure
of only JFROG_ACCESS_TOKEN and GITHUB_TOKEN.
Source: Linters/SAST tools
| @@ -1,31 +1,34 @@ | |||
| import sbtversionpolicy.Compatibility.BinaryCompatible | |||
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
sbt -batch 'show crossScalaVersions' versionPolicyCheckRepository: evolution-gaming/crypto
Length of output: 202
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- build.sbt ---'
cat -n build.sbt
printf '%s\n' '--- relevant version-policy references ---'
rg -n -C 3 'crossScalaVersions|versionPolicyIntention|versionPolicyCheck|Compatibility\.' --glob '*.sbt' --glob '*.scala' --glob '*.md' .
printf '%s\n' '--- project files ---'
git ls-files 'project/*' '.github/*' | sed -n '1,120p'Repository: evolution-gaming/crypto
Length of output: 2499
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- current and parent build metadata ---'
git show HEAD^:build.sbt 2>/dev/null | cat -n || true
printf '%s\n' '--- current version and release configuration ---'
rg -n -C 4 'version :=|versionPolicy|crossScalaVersions|release|publish|previousVersion' \
build.sbt project .github README.md 2>/dev/null || true
printf '%s\n' '--- concise recent history ---'
git log --oneline -8 -- build.sbt project/plugins.sbt .github/workflows/release.yml
printf '%s\n' '--- plugin declarations ---'
cat -n project/plugins.sbt
cat -n project/build.propertiesRepository: evolution-gaming/crypto
Length of output: 3701
🌐 Web query:
sbt-version-policy Compatibility.BinaryCompatible crossScalaVersions dropping Scala version semantics
💡 Result:
The interaction between sbt-version-policy, Compatibility.BinaryCompatible, and crossScalaVersions does not involve "dropping Scala version semantics." Instead, these components work together to enforce binary compatibility across the different Scala versions specified in your build [1][2][3]. Compatibility.BinaryCompatible is a setting for the versionPolicyIntention key [1][2]. When set, it instructs the sbt-version-policy plugin to ensure that your project maintains binary compatibility with the previous release [1][3]. It accomplishes this by: 1. Using MiMa (Migration Manager) to check for binary or source incompatibilities against the previous release [1][2][3]. 2. Using the versionPolicyReportDependencyIssues subtask to ensure that none of your project's dependencies are bumped or removed in a way that would break binary compatibility [1][3]. When you use crossScalaVersions, the plugin verifies these compatibility rules for the various Scala versions you have defined [4][5]. If your project is cross-built, the compatibility checks apply to the artifacts generated for each version in crossScalaVersions [4][5]. There is no automatic dropping of Scala version semantics; rather, you must ensure that your versioning scheme and dependencies are compatible across all Scala versions targeted by your build [4]. If you are encountering issues where dependencies fail during cross-building (e.g., conflicting Scala versions), this is typically a configuration issue within sbt's cross-build mechanics rather than a feature of sbt-version-policy [6]. Common solutions involve ensuring that your dependency operators (e.g., using %% for Scala libraries) correctly handle the Scala binary version suffix, or adjusting your project's CrossVersion settings if full version alignment is required [4][5][7].
Citations:
- 1: https://github.com/scalacenter/sbt-version-policy
- 2: https://github.com/scalacenter/sbt-version-policy/blob/b7fc360d8b55a78e018a45d970a959ffee4d357b/README.md
- 3: https://github.com/scalacenter/sbt-version-policy/blob/main/README.md
- 4: https://www.mintlify.com/sbt/sbt/guides/cross-building
- 5: https://www.scala-sbt.org/1.x/docs/Cross-Build.html
- 6: cross-build no longer works when
CrossVersion.fullprojects depend onCrossVersion.binaryones sbt/sbt#7327 - 7: https://www.scala-sbt.org/2.x/docs/en/reference/cross-building-setup.html
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- current commit and parent ---'
git log -1 --format='%H%n%P%n%s' HEAD
printf '%s\n' '--- Scala 2.12 removal commit ---'
git show --stat --oneline 546bb98
git show --format= --unified=30 546bb98 -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml
printf '%s\n' '--- current commit diff ---'
git diff --stat HEAD^ HEAD
git diff --unified=12 HEAD^ HEAD -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml
printf '%s\n' '--- version and tags ---'
git describe --tags --always --dirty
git tag --sort=-version:refname | sed -n '1,20p'Repository: evolution-gaming/crypto
Length of output: 3182
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
python3 - <<'PY'
from urllib.request import urlopen
urls = {
"README": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md",
"plugin": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala",
}
for name, url in urls.items():
print(f"--- {name}: {url} ---")
try:
text = urlopen(url, timeout=10).read().decode()
except Exception as exc:
print(type(exc).__name__, exc)
continue
lines = text.splitlines()
for i, line in enumerate(lines, 1):
if any(term in line for term in (
"BinaryCompatible", "Compatibility.None", "crossScalaVersions",
"versionPolicyIntention", "previousVersion",
)):
lo, hi = max(1, i - 3), min(len(lines), i + 6)
print("\n".join(f"{n}: {lines[n-1]}" for n in range(lo, hi + 1)))
print()
PYRepository: evolution-gaming/crypto
Length of output: 696
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT
curl -fsSLk https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md > "$tmp"
printf '%s\n' '--- compatibility policy documentation ---'
rg -n -C 8 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|cross-build' "$tmp" || true
printf '%s\n' '--- plugin source references ---'
for path in \
plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala \
plugin/src/main/scala/sbtversionpolicy/Compatibility.scala \
plugin/src/main/scala/sbtversionpolicy/VersionPolicyKeys.scala
do
url="https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/$path"
body=$(curl -fsSLk "$url" 2>/dev/null || true)
if [ -n "$body" ]; then
printf '%s\n' "--- $path ---"
printf '%s\n' "$body" | rg -n -C 6 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|previousVersion' || true
fi
doneRepository: evolution-gaming/crypto
Length of output: 12354
Align the compatibility policy with the dropped Scala 2.12 artifact.
crossScalaVersions omits Scala 2.12, so existing Scala 2.12 consumers cannot use the next release. Set versionPolicyIntention to Compatibility.None and publish a major version, or retain Scala 2.12.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@build.sbt` at line 1, Update the compatibility configuration in build.sbt to
align with crossScalaVersions: either restore Scala 2.12 support, or set
versionPolicyIntention to Compatibility.None and increment the major version for
the next release. Preserve the existing binary compatibility policy only when
Scala 2.12 remains published.
| * AES legacy V1 mode support: | ||
| * - no restrictions on key size - SHA256 hash is used to obtain key entropy | ||
| * - AES/CTR/NoPadding (128 bit key) cipher with IV | ||
| */ |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Correct the AES version in the Scaladoc.
This block documents AES_V2, but the heading says AES legacy V1 mode support. Change V1 to V2.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/main/scala/com/evolutiongaming/crypto/Crypto.scala` around lines 124 -
127, Update the Scaladoc heading for AES_V2 to say “AES legacy V2 mode support”
instead of “AES legacy V1 mode support”; leave the surrounding documentation
unchanged.



Summary by CodeRabbit
Build & Compatibility
Release Process
Code Quality
Maintenance