diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 61644ccc..a487b876 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,8 +1,10 @@ version: 2 updates: - # Keep GitHub Actions pinned versions current. Scala / sbt-plugin - # updates are tracked by Scala Steward (.github/workflows/scala-steward.yml); - # Dependabot doesn't natively understand sbt. + # Keep GitHub Actions pinned versions current (github-actions ecosystem) and + # sbt library / plugin / Scala version upgrades (sbt ecosystem). Dependabot + # has natively supported the `sbt` package ecosystem since May 2026 + # (github.blog changelog 2026-05-26) — before that, sbt updates were Scala + # Steward's job, which is why Steward is retired in favor of Dependabot. - package-ecosystem: "github-actions" directory: "/" schedule: @@ -10,3 +12,10 @@ updates: labels: - "dependencies" - "github-actions" + - package-ecosystem: "sbt" + directory: "/" + schedule: + interval: "weekly" + labels: + - "dependencies" + - "sbt" diff --git a/.github/release.yml b/.github/release.yml index 99945202..e80c5c1d 100644 --- a/.github/release.yml +++ b/.github/release.yml @@ -3,7 +3,9 @@ changelog: exclude: authors: - - scala-steward + # Scala Steward is retired (dependabot.yml now covers sbt); keep bot + # PRs out of the auto-generated release notes. + - dependabot[bot] categories: - title: "⚠️ Breaking changes" labels: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6978522b..708d447b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -366,31 +366,6 @@ jobs: modules-ignore: cats-eo-docs_3 configs-ignore: test scala-tool scala-doc-tool test-internal - validate-steward: - name: Validate Steward Config - strategy: - matrix: - os: [ubuntu-22.04] - java: [temurin@17] - runs-on: ${{ matrix.os }} - steps: - - name: Checkout current branch (fast) - uses: actions/checkout@v7 - - - name: Setup Java (temurin@17) - id: setup-java-temurin-17 - if: matrix.java == 'temurin@17' - uses: actions/setup-java@v6 - with: - distribution: temurin - java-version: 17 - - - uses: coursier/setup-action@v3 - with: - apps: scala-steward - - - run: scala-steward validate-repo-config .scala-steward.conf - site: name: Generate Site strategy: diff --git a/.github/workflows/scala-steward.yml b/.github/workflows/scala-steward.yml deleted file mode 100644 index f4f1f158..00000000 --- a/.github/workflows/scala-steward.yml +++ /dev/null @@ -1,27 +0,0 @@ -# Scala Steward — opens PRs for sbt library / plugin / Scala version upgrades. -# Dependabot (see .github/dependabot.yml) doesn't understand sbt, so it only -# covers GitHub Actions; Steward covers everything under build.sbt / project/. -# -# Uses the default GITHUB_TOKEN (the repo already grants Actions write + -# create-PR permission). ponytail: GITHUB_TOKEN-opened PRs do NOT trigger the -# CI workflow — add a PAT as the SCALA_STEWARD_TOKEN secret and swap it into -# `github-token` below if you want CI to run on Steward PRs automatically. -name: Scala Steward - -on: - schedule: - - cron: "0 6 * * 1" # Mondays 06:00 UTC - workflow_dispatch: # allow manual runs from the Actions tab - -permissions: - contents: write - pull-requests: write - -jobs: - scala-steward: - name: Launch Scala Steward - runs-on: ubuntu-22.04 - steps: - - uses: scala-steward-org/scala-steward-action@v2.96.0 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.scala-steward.conf b/.scala-steward.conf deleted file mode 100644 index 47edb678..00000000 --- a/.scala-steward.conf +++ /dev/null @@ -1,19 +0,0 @@ -# jackson 2.22.0 regressed the @JsonIgnoreProperties case-insensitive fix -# (CVE-2026-54515, dependabot alert #7). 2.22.1 carries the re-fix and is what -# apache-avro 1.12.2's parent BOM resolves, so the build is already past it. -# -# There is deliberately NO `updates.pin` here. A pin like `version = "2.22."` -# is a SERIES LOCK, not a floor: it would block Steward from ever proposing -# 2.23.x, and it matches 2.22.0 anyway so it does not even express "never -# 2.22.0". The previous `"2.21."` pin is the proof of that failure mode — -# 2.22.1 shipped OSV-clean and required by avro 1.12.2, yet the build sat on -# 2.21.5 until a human edited the pin by hand. Steward never proposes a -# version below the current one, so 2.22.0 is already unreachable from 2.22.1 -# and a pin buys nothing but the stranding. -# -# `updates.ignore` below is the belt-and-braces form: it names the single bad -# version instead of locking a series, so 2.23.x and beyond still flow. -updates.ignore = [ - { groupId = "com.fasterxml.jackson.core", artifactId = "jackson-core", version = "2.22.0" }, - { groupId = "com.fasterxml.jackson.core", artifactId = "jackson-databind", version = "2.22.0" } -] diff --git a/build.sbt b/build.sbt index f3c8e3c7..4e104af5 100644 --- a/build.sbt +++ b/build.sbt @@ -1,4 +1,4 @@ -val scala3Version = "3.8.4" +val scala3Version = "3.9.0" // ---- Publishing metadata ------------------------------------------- // @@ -95,7 +95,7 @@ ThisBuild / githubWorkflowBuildPreamble ++= Seq( ThisBuild / semanticdbEnabled := true ThisBuild / semanticdbVersion := scalafixSemanticdb.revision ThisBuild / scalafixDependencies += - "org.typelevel" %% "typelevel-scalafix" % "0.5.0" + "org.typelevel" %% "typelevel-scalafix" % "0.6.0" ThisBuild / scalacOptions += "-Wunused:all" // Raise kindlings' per-derivation macro-expansion budget from its 5s default (which a loaded // machine intermittently trips: `derived timed out after 5000ms`) to 30s. One namespace per @@ -352,7 +352,7 @@ lazy val cats = Typelevel %% "cats-core" % "2.13.0" lazy val catsLaws = Typelevel %% "cats-laws" % "2.13.0" lazy val disciplineCore = Typelevel %% "discipline-core" % "1.7.0" lazy val discipline = Typelevel %% "discipline-specs2" % "2.0.0" -lazy val scalacheck = ScalaCheckOrg %% "scalacheck" % "1.19.0" +lazy val scalacheck = ScalaCheckOrg %% "scalacheck" % "1.20.0" lazy val monocle = Optics %% "monocle-core" % "3.3.0" // droste — the recursion-scheme baseline for the schemes benchmarks (pattern // functor + Fix encoding). Benchmark-only; never a published dependency. @@ -388,7 +388,7 @@ lazy val circe = Circe %% "circe-core" % "0.14.16" // vulcan pins apache-avro 1.11.x transitively; our explicit avro 1.12.2 pin // below wins on the compile classpath, and as an Optional dep vulcan forces // nothing downstream anyway. -lazy val vulcan = "com.github.fd4s" %% "vulcan" % "1.13.0" +lazy val vulcan = "com.github.fd4s" %% "vulcan" % "1.14.0" lazy val circeParser = Circe %% "circe-parser" % "0.14.16" // Pin apache-avro 1.12.2 explicitly even though kindlings-avro-derivation // brings it transitively — keeps the reachable runtime jar visible in @@ -443,7 +443,7 @@ lazy val avro = ApacheAvro % "avro" % "1.12.2" // zio — runtime + ZEnvironment/ZLayer/Ref, the DI surface `cats-eo-zio` // integrates with. Compile-scope there: the module's whole API names // ZIO types. -lazy val zioCore = Ziverge %% "zio" % "2.1.24" +lazy val zioCore = Ziverge %% "zio" % "2.1.26" // zio-schema / zio-json / zio-prelude — Optional in `cats-eo-zio`: only // the `eo.zio.schema` / `eo.zio.json` / `eo.zio.prelude` sub-packages name // their types, callers who want a seam add its artifact themselves (the @@ -456,7 +456,7 @@ lazy val zioSchema = Ziverge %% "zio-schema" % ZioSchemaVersion lazy val zioSchemaDerivation = Ziverge %% "zio-schema-derivation" % ZioSchemaVersion lazy val zioSchemaJson = Ziverge %% "zio-schema-json" % ZioSchemaVersion lazy val zioJson = Ziverge %% "zio-json" % "0.7.44" -lazy val zioPrelude = Ziverge %% "zio-prelude" % "1.0.0-RC41" +lazy val zioPrelude = Ziverge %% "zio-prelude" % "1.0.0-RC48" // kyo-prelude — Kyo's dependency-light pure layer: Env / Var / Layer / // TypeMap all live here (kyo-data + kyo-kernel come transitively; no // kyo-core IO runtime). `cats-eo-kyo` deliberately depends on nothing @@ -465,7 +465,7 @@ lazy val zioPrelude = Ziverge %% "zio-prelude" % "1.0.0-RC41" // kyo's macro classes can only LOAD in a JDK 25+ compiler JVM. The kyo // module therefore builds on a 25 toolchain (`tlJdkRelease := 25` there) // and drops out of the root aggregate on older JVMs — see `kyoBuildActive`. -val KyoVersion = "1.0.0-RC6" +val KyoVersion = "1.0.0-RC7" lazy val kyoPrelude = GetKyo %% "kyo-prelude" % KyoVersion // kyo-schema — schema-driven codecs/foci (kyo-data only; no kyo-core). // Optional in `cats-eo-kyo`: only the `eo.kyo.schema` sub-package names @@ -485,8 +485,8 @@ val kyoBuildActive: Boolean = .get("java.specification.version") .exists(v => scala.util.Try(v.toInt).getOrElse(0) >= 25) -lazy val jsoniterCore = Plokhotnyuk %% "jsoniter-scala-core" % "2.38.17" -lazy val jsoniterMacros = Plokhotnyuk %% "jsoniter-scala-macros" % "2.38.17" +lazy val jsoniterCore = Plokhotnyuk %% "jsoniter-scala-core" % "2.41.2" +lazy val jsoniterMacros = Plokhotnyuk %% "jsoniter-scala-macros" % "2.41.2" lazy val commonSettings = Seq( // `version` is NOT set here — sbt-typelevel-ci-release derives it diff --git a/project/build.properties b/project/build.properties index 7c95fc19..e0a1aa02 100644 --- a/project/build.properties +++ b/project/build.properties @@ -1 +1 @@ -sbt.version=1.12.13 +sbt.version=1.13.0 diff --git a/project/plugins.sbt b/project/plugins.sbt index bae375b7..ae078589 100644 --- a/project/plugins.sbt +++ b/project/plugins.sbt @@ -15,12 +15,13 @@ addSbtPlugin("pl.project13.scala" % "sbt-jmh" % "0.4.8") // test deps), so every mutant comes back NoCoverage; switching the // current project first makes specs2 visible. 0.20.x auto-derives the // Scala 3 dialect from scalaVersion. -addSbtPlugin("io.stryker-mutator" % "sbt-stryker4s" % "0.20.3") +// 0.20.4 fixed multi-module invocation; the `project ; stryker` workaround still works. +addSbtPlugin("io.stryker-mutator" % "sbt-stryker4s" % "0.20.4") // Format check gate for CI (`sbt scalafmtCheckAll scalafmtSbtCheck` // in the workflow). The project ships a `.scalafmt.conf` pinned to // 3.x; sbt-scalafmt honours that pin automatically. -addSbtPlugin("org.scalameta" % "sbt-scalafmt" % "2.5.6") +addSbtPlugin("org.scalameta" % "sbt-scalafmt" % "2.6.2") // `sbt-typelevel-ci-release` wires the Sonatype Central Portal flow // (post-June-2025 OSSRH sunset): derives the version from git tags, @@ -29,7 +30,7 @@ addSbtPlugin("org.scalameta" % "sbt-scalafmt" % "2.5.6") // `sbt-typelevel-mima` dependency so binary-compat checks run on // every CI build from 0.1.1 onward (0.1.0 has no previous version // to compare against; see `mima.sbt`). -addSbtPlugin("org.typelevel" % "sbt-typelevel-ci-release" % "0.8.6") +addSbtPlugin("org.typelevel" % "sbt-typelevel-ci-release" % "0.8.7") // `sbt-typelevel-settings` contributes the curated scalac flag set // (`-deprecation -feature -unchecked -Wunused:... -Wvalue-discard`, @@ -37,7 +38,7 @@ addSbtPlugin("org.typelevel" % "sbt-typelevel-ci-release" % "0.8.6") // in CI via `tlFatalWarnings`. Not transitively brought in by // `-ci-release`, so we add it explicitly — without it each module is // responsible for its own scalacOptions. -addSbtPlugin("org.typelevel" % "sbt-typelevel-settings" % "0.8.6") +addSbtPlugin("org.typelevel" % "sbt-typelevel-settings" % "0.8.7") // `sbt-scalafix` wires Scalafix into the build (`sbt scalafixAll`, // `sbt scalafixAll --check`). Pinned to the same minor as the @@ -50,13 +51,13 @@ addSbtPlugin("org.typelevel" % "sbt-typelevel-settings" % "0.8.6") // trailing comma. scalafix fully owns imports (sorting, grouping, and now // trailing commas), so scalafmt is set to `trailingCommas = keep` // (.scalafmt.conf) to stay out of import formatting — the two no longer fight. -addSbtPlugin("ch.epfl.scala" % "sbt-scalafix" % "0.14.7") +addSbtPlugin("ch.epfl.scala" % "sbt-scalafix" % "0.14.9") // `sbt-typelevel-site` drives the Laika-based docs site. Pairs the // mdoc-compiled markdown under `site/docs/` with the Helium theme // configured from build.sbt. Pinned to the same 0.8.5 family as // ci-release so they share plugin transitive versions. -addSbtPlugin("org.typelevel" % "sbt-typelevel-site" % "0.8.6") +addSbtPlugin("org.typelevel" % "sbt-typelevel-site" % "0.8.7") // `unused-code-plugin` from xuwei-k contributes the `WarnUnusedCode` / // `ErrorUnusedCode` / `RemoveUnusedCode` Scalafix `SyntacticRule`s,