Skip to content

updates - #197

Merged
mr-git merged 5 commits into
masterfrom
updates
Aug 11, 2026
Merged

mr-git merged 5 commits into
masterfrom
updates

Conversation

@mr-git

@mr-git mr-git commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor
  • update SBT to 2.0.6
  • introduce and apply scalafmt and bin-check
  • replace sbt-release with sbt-dynver
  • drop Scala 2.12 support
  • update CI and Release workflows

Summary by CodeRabbit

  • Build & Compatibility

    • Added support for Scala 2.13.18 and Scala 3.3.8.
    • Added binary compatibility checks to help prevent breaking changes.
    • Updated the build system and development tooling.
  • Release Process

    • Releases are now published when version tags are pushed.
    • Continuous integration runs for pushes and pull requests.
  • Code Quality

    • Standardized formatting and expanded automated validation.
    • Updated documentation and license metadata.
  • Maintenance

    • Reformatted source code and tests without changing application behavior.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The project updates Scala and SBT versions, adds binary compatibility and Scalafmt configuration, reformats source files, and replaces inline CI and release jobs with reusable workflows.

Changes

Build and automation modernization

Layer / File(s) Summary
Scala, SBT, and build policy updates
build.sbt, project/build.properties, project/plugins.sbt
The build targets Scala 2.13.18 and 3.3.8, uses SBT 2.0.6, adds binary compatibility checks, and updates build commands and plugins.
Scalafmt configuration and adoption
.scalafmt.conf, src/main/scala/com/evolutiongaming/crypto/*, src/test/scala/com/evolutiongaming/crypto/CryptoSpec.scala
The project adds Scalafmt rules and applies formatting changes to production and test sources without changing cryptographic behavior.
CI and release workflow delegation
.github/workflows/ci.yml, .github/workflows/release.yml
CI now uses a reusable workflow for pushes and pull requests. Release publishing now uses v* tag pushes and an updated reusable workflow.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Suggested reviewers: scala-steward

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title "updates" is too generic and does not identify the build, release, Scala, or CI changes. Replace "updates" with a concise title that identifies the primary build and release configuration changes.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch updates

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@mr-git
mr-git merged commit a29b4f0 into master Aug 11, 2026
5 of 6 checks passed
@mr-git
mr-git deleted the updates branch August 11, 2026 08:28
@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage is 85.039% — updates into master. No base build found for master.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release.yml:
- Around line 10-11: Update the reusable release workflow reference in the
workflow job to use commit SHA b4557d9a82c03596dc2425e19b3cb9a6280a4739 instead
of the mutable v5 tag, while retaining the # v5 annotation. Replace secrets:
inherit with explicit exposure of only JFROG_ACCESS_TOKEN and GITHUB_TOKEN.

In `@build.sbt`:
- Line 1: Update the compatibility configuration in build.sbt to align with
crossScalaVersions: either restore Scala 2.12 support, or set
versionPolicyIntention to Compatibility.None and increment the major version for
the next release. Preserve the existing binary compatibility policy only when
Scala 2.12 remains published.

In `@src/main/scala/com/evolutiongaming/crypto/Crypto.scala`:
- Around line 124-127: Update the Scaladoc heading for AES_V2 to say “AES legacy
V2 mode support” instead of “AES legacy V1 mode support”; leave the surrounding
documentation unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 3cfdf9fa-14f0-4977-b056-f617e1ddabac

📥 Commits

Reviewing files that changed from the base of the PR and between f7a78b8 and 03c2c71.

📒 Files selected for processing (11)
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • .scalafmt.conf
  • build.sbt
  • project/build.properties
  • project/plugins.sbt
  • src/main/scala/com/evolutiongaming/crypto/Crypto.scala
  • src/main/scala/com/evolutiongaming/crypto/DecryptConfig.scala
  • src/main/scala/com/evolutiongaming/crypto/Encrypt.scala
  • src/test/scala/com/evolutiongaming/crypto/CryptoSpec.scala
  • version.sbt
💤 Files with no reviewable changes (1)
  • version.sbt

Comment on lines +10 to 11
uses: evolution-gaming/scala-github-actions/.github/workflows/release.yml@v5
secrets: inherit

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="evolution-gaming/scala-github-actions"
sha="$(gh api "repos/${repo}/commits/v5" --jq '.sha')"

printf 'Pin release.yml to: %s\n' "$sha"
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
  --jq '.content' | base64 --decode

Repository: evolution-gaming/crypto

Length of output: 2250


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="evolution-gaming/scala-github-actions"
tag_ref="$(gh api "repos/${repo}/git/refs/tags/v5")"
printf '%s\n' "$tag_ref" | jq '{ref, object}'

type="$(printf '%s' "$tag_ref" | jq -r '.object.type')"
sha="$(printf '%s' "$tag_ref" | jq -r '.object.sha')"
if [ "$type" = "tag" ]; then
  sha="$(gh api "repos/${repo}/git/tags/${sha}" --jq '.object.sha')"
fi

printf 'Dereferenced v5 commit: %s\n' "$sha"
gh api "repos/${repo}/commits/${sha}" --jq '.sha'
printf '\nSecret references in the called workflow:\n'
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
  --jq '.content' | base64 --decode | rg -n 'secrets\.|secrets:|JFROG_ACCESS_TOKEN|GITHUB_TOKEN' || true

Repository: evolution-gaming/crypto

Length of output: 713


Pin the reusable release workflow to commit b4557d9a82c03596dc2425e19b3cb9a6280a4739.

The workflow references only JFROG_ACCESS_TOKEN and GITHUB_TOKEN. Replace @v5 with the commit SHA and retain # v5. Avoid secrets: inherit if the caller exposes additional secrets.

🧰 Tools
🪛 zizmor (1.29.0)

[warning] 10-10: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow

(secrets-inherit)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release.yml around lines 10 - 11, Update the reusable
release workflow reference in the workflow job to use commit SHA
b4557d9a82c03596dc2425e19b3cb9a6280a4739 instead of the mutable v5 tag, while
retaining the # v5 annotation. Replace secrets: inherit with explicit exposure
of only JFROG_ACCESS_TOKEN and GITHUB_TOKEN.

Source: Linters/SAST tools

Comment thread build.sbt
@@ -1,31 +1,34 @@
import sbtversionpolicy.Compatibility.BinaryCompatible

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

sbt -batch 'show crossScalaVersions' versionPolicyCheck

Repository: evolution-gaming/crypto

Length of output: 202


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- build.sbt ---'
cat -n build.sbt

printf '%s\n' '--- relevant version-policy references ---'
rg -n -C 3 'crossScalaVersions|versionPolicyIntention|versionPolicyCheck|Compatibility\.' --glob '*.sbt' --glob '*.scala' --glob '*.md' .

printf '%s\n' '--- project files ---'
git ls-files 'project/*' '.github/*' | sed -n '1,120p'

Repository: evolution-gaming/crypto

Length of output: 2499


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- current and parent build metadata ---'
git show HEAD^:build.sbt 2>/dev/null | cat -n || true
printf '%s\n' '--- current version and release configuration ---'
rg -n -C 4 'version :=|versionPolicy|crossScalaVersions|release|publish|previousVersion' \
  build.sbt project .github README.md 2>/dev/null || true

printf '%s\n' '--- concise recent history ---'
git log --oneline -8 -- build.sbt project/plugins.sbt .github/workflows/release.yml

printf '%s\n' '--- plugin declarations ---'
cat -n project/plugins.sbt
cat -n project/build.properties

Repository: evolution-gaming/crypto

Length of output: 3701


🌐 Web query:

sbt-version-policy Compatibility.BinaryCompatible crossScalaVersions dropping Scala version semantics

💡 Result:

The interaction between sbt-version-policy, Compatibility.BinaryCompatible, and crossScalaVersions does not involve "dropping Scala version semantics." Instead, these components work together to enforce binary compatibility across the different Scala versions specified in your build [1][2][3]. Compatibility.BinaryCompatible is a setting for the versionPolicyIntention key [1][2]. When set, it instructs the sbt-version-policy plugin to ensure that your project maintains binary compatibility with the previous release [1][3]. It accomplishes this by: 1. Using MiMa (Migration Manager) to check for binary or source incompatibilities against the previous release [1][2][3]. 2. Using the versionPolicyReportDependencyIssues subtask to ensure that none of your project's dependencies are bumped or removed in a way that would break binary compatibility [1][3]. When you use crossScalaVersions, the plugin verifies these compatibility rules for the various Scala versions you have defined [4][5]. If your project is cross-built, the compatibility checks apply to the artifacts generated for each version in crossScalaVersions [4][5]. There is no automatic dropping of Scala version semantics; rather, you must ensure that your versioning scheme and dependencies are compatible across all Scala versions targeted by your build [4]. If you are encountering issues where dependencies fail during cross-building (e.g., conflicting Scala versions), this is typically a configuration issue within sbt's cross-build mechanics rather than a feature of sbt-version-policy [6]. Common solutions involve ensuring that your dependency operators (e.g., using %% for Scala libraries) correctly handle the Scala binary version suffix, or adjusting your project's CrossVersion settings if full version alignment is required [4][5][7].

Citations:


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- current commit and parent ---'
git log -1 --format='%H%n%P%n%s' HEAD

printf '%s\n' '--- Scala 2.12 removal commit ---'
git show --stat --oneline 546bb98
git show --format= --unified=30 546bb98 -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml

printf '%s\n' '--- current commit diff ---'
git diff --stat HEAD^ HEAD
git diff --unified=12 HEAD^ HEAD -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml

printf '%s\n' '--- version and tags ---'
git describe --tags --always --dirty
git tag --sort=-version:refname | sed -n '1,20p'

Repository: evolution-gaming/crypto

Length of output: 3182


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
from urllib.request import urlopen

urls = {
    "README": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md",
    "plugin": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala",
}
for name, url in urls.items():
    print(f"--- {name}: {url} ---")
    try:
        text = urlopen(url, timeout=10).read().decode()
    except Exception as exc:
        print(type(exc).__name__, exc)
        continue
    lines = text.splitlines()
    for i, line in enumerate(lines, 1):
        if any(term in line for term in (
            "BinaryCompatible", "Compatibility.None", "crossScalaVersions",
            "versionPolicyIntention", "previousVersion",
        )):
            lo, hi = max(1, i - 3), min(len(lines), i + 6)
            print("\n".join(f"{n}: {lines[n-1]}" for n in range(lo, hi + 1)))
            print()
PY

Repository: evolution-gaming/crypto

Length of output: 696


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT

curl -fsSLk https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md > "$tmp"

printf '%s\n' '--- compatibility policy documentation ---'
rg -n -C 8 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|cross-build' "$tmp" || true

printf '%s\n' '--- plugin source references ---'
for path in \
  plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala \
  plugin/src/main/scala/sbtversionpolicy/Compatibility.scala \
  plugin/src/main/scala/sbtversionpolicy/VersionPolicyKeys.scala
do
  url="https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/$path"
  body=$(curl -fsSLk "$url" 2>/dev/null || true)
  if [ -n "$body" ]; then
    printf '%s\n' "--- $path ---"
    printf '%s\n' "$body" | rg -n -C 6 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|previousVersion' || true
  fi
done

Repository: evolution-gaming/crypto

Length of output: 12354


Align the compatibility policy with the dropped Scala 2.12 artifact.

crossScalaVersions omits Scala 2.12, so existing Scala 2.12 consumers cannot use the next release. Set versionPolicyIntention to Compatibility.None and publish a major version, or retain Scala 2.12.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@build.sbt` at line 1, Update the compatibility configuration in build.sbt to
align with crossScalaVersions: either restore Scala 2.12 support, or set
versionPolicyIntention to Compatibility.None and increment the major version for
the next release. Preserve the existing binary compatibility policy only when
Scala 2.12 remains published.

Comment on lines +124 to +127
* AES legacy V1 mode support:
* - no restrictions on key size - SHA256 hash is used to obtain key entropy
* - AES/CTR/NoPadding (128 bit key) cipher with IV
*/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Correct the AES version in the Scaladoc.

This block documents AES_V2, but the heading says AES legacy V1 mode support. Change V1 to V2.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/main/scala/com/evolutiongaming/crypto/Crypto.scala` around lines 124 -
127, Update the Scaladoc heading for AES_V2 to say “AES legacy V2 mode support”
instead of “AES legacy V1 mode support”; leave the surrounding documentation
unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants