Conversation
- sbt 1.12.13 -> 1.13.0 (security fix for GHSA-943m-f264-54p4; verified boot with the full plugin set under the official launcher) - jsoniter-scala 2.38.17 -> 2.41.2 - kyo-prelude / kyo-schema 1.0.0-RC6 -> 1.0.0-RC7 - scalacheck 1.19.0 -> 1.20.0; vulcan 1.13.0 -> 1.14.0 - zio 2.1.24 -> 2.1.26; zio-prelude 1.0.0-RC41 -> 1.0.0-RC48 - sbt-scalafmt 2.5.6 -> 2.6.2; sbt-scalafix 0.14.7 -> 0.14.9 - sbt-stryker4s 0.20.3 -> 0.20.4 (multi-module invocation fix) - sbt-typelevel-ci-release/-settings/-site 0.8.6 -> 0.8.7 - typelevel-scalafix 0.5.0 -> 0.6.0
…stem Dependabot has supported the sbt package ecosystem since May 2026, and unlike Steward's GITHUB_TOKEN-opened PRs it runs the repo's CI on every update PR. Add the sbt ecosystem to dependabot.yml, retire the Steward workflow and its config (the jackson updates.ignore entries were inert, as jackson only arrives transitively via avro), drop the now-dangling validate-steward job from ci.yml, and point the release-note bot-author exclusion at dependabot[bot].
kyo-prelude/-schema 1.0.0-RC7 ship TASTy 28.9, produced by the Scala 3.9.0 compiler, which the 3.8.4 toolchain cannot read: TASTy file kyo/TypeMap$package.tasty could not be read ... Forward incompatible TASTy file has version 28.9, produced by Scala 3.9.0, expected stable TASTy from 28.0 to 28.8 Verified before bumping: scala3-library_3 3.9.0 and scalafix-cli_3.9.0:0.14.9 both resolve on Maven Central, so the scalafix/semanticdb lane follows the new toolchain.
Contributor
|
🚀 Cloudflare Pages preview for https://bb856ee6.cats-eo-docs.pages.dev Branch alias: https://deps-updates-and-dependabot.cats-eo-docs.pages.dev Built from commit |
The hand-edit that removed the validate-steward job is replaced by the regenerated file: with .scala-steward.conf gone, sbt-typelevel 0.8.7 no longer emits the job, so the generated ci.yml matches the migrated state.
Contributor
Benchmark A/BAllocation (B/op) — authoritative
442 more benchmarks
Timing (ns/op) — directional only, same-VM but shared runner
base_sha: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audited every pinned dependency against current Maven Central / GitHub release metadata and applied the updates. Two logical commits: dependency bumps, then the Steward → Dependabot migration.
Dependency updates
serverConnectionType = Tcp). Verified before bumping: the official sbt 1.13.0 launcher boots the fullproject/plugins.sbtplugin set and derived0.15-SNAPSHOTcorrectly (tlBaseVersionchain).sbt <module>/stryker; theproject <m>; strykerguidance still works and can be simplified in a follow-upDeliberately not bumped (follow-ups): zio-schema 1.9.0 / zio-json 1.1.0 (API-drift risk, need a compile pass), droste 0.10.0 (benchmark-only), scalafmt core 3.11.5 (its only diff vs 3.11.1 is a pre-existing formatting drift in
site/src/.../circedocs.scala, verified engine-independent), Scala 3.9/3.10, sbt 2.x (see below).Scala Steward → Dependabot
Dependabot has natively supported sbt since May 2026 and — unlike Steward's
GITHUB_TOKENPRs, which never ran CI here — its PRs trigger the full workflow set. Changes:dependabot.yml: added thesbtecosystem (weekly, labelled)scala-steward.yml+.scala-steward.conf(the jacksonupdates.ignoreentries were inert — jackson only arrives transitively via avro)validate-stewardjob fromci.yml(self-dropping on the nextsbt githubWorkflowGenerate).github/release.yml: bot-author exclusion now namesdependabot[bot]On sbt 2.x
sbt 2.0.9 is the current GA; 2.1 is at 2.1.0-M3 (milestone). The whole toolchain except sbt-typelevel already ships sbt 2 builds — typelevel has published none and its crossbuild is an open WIP (#899, draft PR #912:
ci-release/site/core/ciSigningunfinished). This repo's release/MiMa/site pipeline depends on sbt-typelevel, so the 2.x move should wait for that; 1.13.0 is the right current line.Verification status
-batchworks; typelevel version derivation works.sbt test,scalafmtCheckAll,scalafixAll --check,githubWorkflowCheck. CI is the gate — watch those four steps, plus the JDK 25 kyo lane.