Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 5 additions & 37 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,42 +1,10 @@
name: CI

on: [push, pull_request]
on:
push:
branches: [ master ]
pull_request:

jobs:
test:

runs-on: ubuntu-latest

strategy:
matrix:
scala:
- 2.13.14
- 2.12.19
- 3.3.3

steps:
- uses: actions/checkout@v2

- uses: coursier/cache-action@v5

- name: scala
uses: olafurpg/setup-scala@v10
with:
java-version: openjdk@1.11

- name: build ${{ matrix.scala }}
run: sbt ++${{ matrix.scala }} clean coverage test

- name: test coverage
if: success()
env:
COVERALLS_REPO_TOKEN: ${{ secrets.COVERALLS_REPO_TOKEN }}
run: sbt ++${{ matrix.scala }} coverageReport coverageAggregate coveralls

- name: slack
uses: homoluctus/slatify@master
if: failure() && github.ref == 'refs/heads/master'
with:
type: ${{ job.status }}
job_name: Build
url: ${{ secrets.SLACK_WEBHOOK }}
uses: evolution-gaming/scala-github-actions/.github/workflows/ci.yml@dde27b9bd793d41d5aacf8fb74403c9de5da1146 # v6.3.0
10 changes: 5 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Publish new Release
name: Publish Release

on:
release:
types: [published]
branches: [master]
push:
tags:
- 'v*'

jobs:
release:
uses: evolution-gaming/scala-github-actions/.github/workflows/release.yml@v1
uses: evolution-gaming/scala-github-actions/.github/workflows/release.yml@v5
secrets: inherit
Comment on lines +10 to 11

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="evolution-gaming/scala-github-actions"
sha="$(gh api "repos/${repo}/commits/v5" --jq '.sha')"

printf 'Pin release.yml to: %s\n' "$sha"
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
  --jq '.content' | base64 --decode

Repository: evolution-gaming/crypto

Length of output: 2250


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="evolution-gaming/scala-github-actions"
tag_ref="$(gh api "repos/${repo}/git/refs/tags/v5")"
printf '%s\n' "$tag_ref" | jq '{ref, object}'

type="$(printf '%s' "$tag_ref" | jq -r '.object.type')"
sha="$(printf '%s' "$tag_ref" | jq -r '.object.sha')"
if [ "$type" = "tag" ]; then
  sha="$(gh api "repos/${repo}/git/tags/${sha}" --jq '.object.sha')"
fi

printf 'Dereferenced v5 commit: %s\n' "$sha"
gh api "repos/${repo}/commits/${sha}" --jq '.sha'
printf '\nSecret references in the called workflow:\n'
gh api "repos/${repo}/contents/.github/workflows/release.yml?ref=${sha}" \
  --jq '.content' | base64 --decode | rg -n 'secrets\.|secrets:|JFROG_ACCESS_TOKEN|GITHUB_TOKEN' || true

Repository: evolution-gaming/crypto

Length of output: 713


Pin the reusable release workflow to commit b4557d9a82c03596dc2425e19b3cb9a6280a4739.

The workflow references only JFROG_ACCESS_TOKEN and GITHUB_TOKEN. Replace @v5 with the commit SHA and retain # v5. Avoid secrets: inherit if the caller exposes additional secrets.

🧰 Tools
🪛 zizmor (1.29.0)

[warning] 10-10: secrets unconditionally inherited by called workflow (secrets-inherit): this reusable workflow

(secrets-inherit)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release.yml around lines 10 - 11, Update the reusable
release workflow reference in the workflow job to use commit SHA
b4557d9a82c03596dc2425e19b3cb9a6280a4739 instead of the mutable v5 tag, while
retaining the # v5 annotation. Replace secrets: inherit with explicit exposure
of only JFROG_ACCESS_TOKEN and GITHUB_TOKEN.

Source: Linters/SAST tools

96 changes: 96 additions & 0 deletions .scalafmt.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
# Main goals:
# - nicer commit diffs (trailing commas, no alignment for pattern matching, force new lines)
# - better interop with default IntelliJ IDEA setup (matching import and modifiers sorting logic)
# - better developer experience on laptop screens (like 16' MBPs) with IntelliJ IDEA (line wraps)

version = 3.11.5

runner.dialect = scala213source3

# only format files tracked by git
project.git = true

maxColumn = 120
trailingCommas = always

preset = default
# do not align to make nicer commit diffs
align.preset = none

indent {
# altering defnSite and extendSite to have this:
# final class MyErr extends RuntimeException(
# "super error message",
# )
# instead of this:
# final class MyErr extends RuntimeException(
# "super error message",
# )
defnSite = 2
extendSite = 0
}

spaces {
# makes string interpolation with curlies more visually distinct
inInterpolatedStringCurlyBraces = true
}

newlines {
# keep author new lines where possible
source = keep
# force new line after "(implicit" for multi-line arg lists
implicitParamListModifierForce = [after]
avoidForSimpleOverflow = [
tooLong, # if the line would be too long even after newline inserted, do nothing
slc, # do nothing if overflow caused by single line comment
]
}

verticalMultiline {
atDefnSite = true
arityThreshold = 4 # more than 3 args in a list will be turned vertical
newlineAfterOpenParen = true # for nicer commit diffs
}

# for nicer commit diffs - forces new line before last parenthesis:
# class MyCls(
# arg1: String,
# arg2: String,
# ) extends MyTrait {
#
# without it:
# class MyCls(
# arg1: String,
# arg2: String) extends MyTrait {
danglingParentheses.exclude = []

docstrings {
# easier to view diffs in IDEA on 16' MBP screen if docs max line are shorter than code
wrapMaxColumn = 100
# next settings make it similar to the default IDEA javadoc formatting
style = Asterisk
oneline = unfold
blankFirstLine = unfold
}

rewrite.rules = [
Imports,
RedundantParens,
SortModifiers,
prefercurlyfors,
]

# put visibility modifier first
rewrite.sortModifiers.preset = styleGuide

# Import sorting as similar as possible to scalafix's "OrganizeImports.preset = INTELLIJ_2020_3".
# Scalafix is not used as its commands mess up "all .." build aliases and it takes long time to run,
# while its code semantic based features are not needed here.
# I.e. detection of unused imports is done with Scala compiler options.
rewrite.imports {
sort = ascii
groups = [
[".*"],
["java\\..*", "javax\\..*", "scala\\..*"],
]
}
27 changes: 15 additions & 12 deletions build.sbt
Original file line number Diff line number Diff line change
@@ -1,31 +1,34 @@
import sbtversionpolicy.Compatibility.BinaryCompatible

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

sbt -batch 'show crossScalaVersions' versionPolicyCheck

Repository: evolution-gaming/crypto

Length of output: 202


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- build.sbt ---'
cat -n build.sbt

printf '%s\n' '--- relevant version-policy references ---'
rg -n -C 3 'crossScalaVersions|versionPolicyIntention|versionPolicyCheck|Compatibility\.' --glob '*.sbt' --glob '*.scala' --glob '*.md' .

printf '%s\n' '--- project files ---'
git ls-files 'project/*' '.github/*' | sed -n '1,120p'

Repository: evolution-gaming/crypto

Length of output: 2499


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- current and parent build metadata ---'
git show HEAD^:build.sbt 2>/dev/null | cat -n || true
printf '%s\n' '--- current version and release configuration ---'
rg -n -C 4 'version :=|versionPolicy|crossScalaVersions|release|publish|previousVersion' \
  build.sbt project .github README.md 2>/dev/null || true

printf '%s\n' '--- concise recent history ---'
git log --oneline -8 -- build.sbt project/plugins.sbt .github/workflows/release.yml

printf '%s\n' '--- plugin declarations ---'
cat -n project/plugins.sbt
cat -n project/build.properties

Repository: evolution-gaming/crypto

Length of output: 3701


🌐 Web query:

sbt-version-policy Compatibility.BinaryCompatible crossScalaVersions dropping Scala version semantics

💡 Result:

The interaction between sbt-version-policy, Compatibility.BinaryCompatible, and crossScalaVersions does not involve "dropping Scala version semantics." Instead, these components work together to enforce binary compatibility across the different Scala versions specified in your build [1][2][3]. Compatibility.BinaryCompatible is a setting for the versionPolicyIntention key [1][2]. When set, it instructs the sbt-version-policy plugin to ensure that your project maintains binary compatibility with the previous release [1][3]. It accomplishes this by: 1. Using MiMa (Migration Manager) to check for binary or source incompatibilities against the previous release [1][2][3]. 2. Using the versionPolicyReportDependencyIssues subtask to ensure that none of your project's dependencies are bumped or removed in a way that would break binary compatibility [1][3]. When you use crossScalaVersions, the plugin verifies these compatibility rules for the various Scala versions you have defined [4][5]. If your project is cross-built, the compatibility checks apply to the artifacts generated for each version in crossScalaVersions [4][5]. There is no automatic dropping of Scala version semantics; rather, you must ensure that your versioning scheme and dependencies are compatible across all Scala versions targeted by your build [4]. If you are encountering issues where dependencies fail during cross-building (e.g., conflicting Scala versions), this is typically a configuration issue within sbt's cross-build mechanics rather than a feature of sbt-version-policy [6]. Common solutions involve ensuring that your dependency operators (e.g., using %% for Scala libraries) correctly handle the Scala binary version suffix, or adjusting your project's CrossVersion settings if full version alignment is required [4][5][7].

Citations:


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- current commit and parent ---'
git log -1 --format='%H%n%P%n%s' HEAD

printf '%s\n' '--- Scala 2.12 removal commit ---'
git show --stat --oneline 546bb98
git show --format= --unified=30 546bb98 -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml

printf '%s\n' '--- current commit diff ---'
git diff --stat HEAD^ HEAD
git diff --unified=12 HEAD^ HEAD -- build.sbt project .github/workflows/ci.yml .github/workflows/release.yml

printf '%s\n' '--- version and tags ---'
git describe --tags --always --dirty
git tag --sort=-version:refname | sed -n '1,20p'

Repository: evolution-gaming/crypto

Length of output: 3182


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
from urllib.request import urlopen

urls = {
    "README": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md",
    "plugin": "https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala",
}
for name, url in urls.items():
    print(f"--- {name}: {url} ---")
    try:
        text = urlopen(url, timeout=10).read().decode()
    except Exception as exc:
        print(type(exc).__name__, exc)
        continue
    lines = text.splitlines()
    for i, line in enumerate(lines, 1):
        if any(term in line for term in (
            "BinaryCompatible", "Compatibility.None", "crossScalaVersions",
            "versionPolicyIntention", "previousVersion",
        )):
            lo, hi = max(1, i - 3), min(len(lines), i + 6)
            print("\n".join(f"{n}: {lines[n-1]}" for n in range(lo, hi + 1)))
            print()
PY

Repository: evolution-gaming/crypto

Length of output: 696


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT

curl -fsSLk https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/README.md > "$tmp"

printf '%s\n' '--- compatibility policy documentation ---'
rg -n -C 8 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|cross-build' "$tmp" || true

printf '%s\n' '--- plugin source references ---'
for path in \
  plugin/src/main/scala/sbtversionpolicy/VersionPolicyPlugin.scala \
  plugin/src/main/scala/sbtversionpolicy/Compatibility.scala \
  plugin/src/main/scala/sbtversionpolicy/VersionPolicyKeys.scala
do
  url="https://raw.githubusercontent.com/scalacenter/sbt-version-policy/main/$path"
  body=$(curl -fsSLk "$url" 2>/dev/null || true)
  if [ -n "$body" ]; then
    printf '%s\n' "--- $path ---"
    printf '%s\n' "$body" | rg -n -C 6 'BinaryCompatible|Compatibility.None|versionPolicyIntention|crossScalaVersions|previousVersion' || true
  fi
done

Repository: evolution-gaming/crypto

Length of output: 12354


Align the compatibility policy with the dropped Scala 2.12 artifact.

crossScalaVersions omits Scala 2.12, so existing Scala 2.12 consumers cannot use the next release. Set versionPolicyIntention to Compatibility.None and publish a major version, or retain Scala 2.12.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@build.sbt` at line 1, Update the compatibility configuration in build.sbt to
align with crossScalaVersions: either restore Scala 2.12 support, or set
versionPolicyIntention to Compatibility.None and increment the major version for
the next release. Preserve the existing binary compatibility policy only when
Scala 2.12 remains published.


name := "crypto"

organization := "com.evolutiongaming"

homepage := Some(url("https://github.com/evolution-gaming/crypto"))
homepage := Some(uri("https://github.com/evolution-gaming/crypto"))

startYear := Some(2016)

organizationName := "Evolution"

organizationHomepage := Some(url("https://evolution.com"))
organizationHomepage := Some(uri("https://evolution.com"))

publishTo := Some(Resolver.evolutionReleases)

scalaVersion := crossScalaVersions.value.head

crossScalaVersions := Seq("2.13.18", "2.12.19", "3.3.8")
crossScalaVersions := Seq("2.13.18", "3.3.8")

versionPolicyIntention := BinaryCompatible

libraryDependencies ++= Seq(
"com.typesafe" % "config" % "1.4.9",
"commons-codec" % "commons-codec" % "1.15" ,
"org.scalatest" %% "scalatest" % "3.2.20" % Test
"com.typesafe" % "config" % "1.4.9",
"commons-codec" % "commons-codec" % "1.15",
"org.scalatest" %% "scalatest" % "3.2.20" % Test,
)

licenses := Seq(("Apache-2.0", url("http://www.apache.org/licenses/LICENSE-2.0")))

releaseCrossBuild := true
licenses := Seq(("Apache-2.0", uri("https://www.apache.org/licenses/LICENSE-2.0")))

//addCommandAlias("check", "all versionPolicyCheck Compile/doc")
addCommandAlias("check", "show version")
addCommandAlias("build", "+all compile test")
// check is called with + from the release action
addCommandAlias("check", "all versionPolicyCheck Compile/doc scalafmtCheckRepo")
addCommandAlias("fmt", "+all scalafmtRepo")
addCommandAlias("build", "all compile testFull")
2 changes: 1 addition & 1 deletion project/build.properties
Original file line number Diff line number Diff line change
@@ -1 +1 @@
sbt.version=1.10.0
sbt.version = 2.0.6
10 changes: 6 additions & 4 deletions project/plugins.sbt
Original file line number Diff line number Diff line change
@@ -1,9 +1,11 @@
addSbtPlugin("org.scoverage" % "sbt-scoverage" % "2.4.4")

addSbtPlugin("org.scoverage" % "sbt-coveralls" % "1.3.11")

addSbtPlugin("com.github.sbt" % "sbt-release" % "1.0.15")
addSbtPlugin("com.github.sbt" % "sbt-dynver" % "5.1.1")

addSbtPlugin("com.evolution" % "sbt-scalac-opts-plugin" % "0.2.0")

addSbtPlugin("com.evolution" % "sbt-artifactory-plugin" % "0.1.2")
addSbtPlugin("com.evolution" % "sbt-artifactory-plugin" % "0.1.2")

addSbtPlugin("ch.epfl.scala" % "sbt-version-policy" % "3.3.0")

addSbtPlugin("org.scalameta" % "sbt-scalafmt" % "2.6.2")
Loading