Skip to content

build(deps): bump org.scala-sbt:sbt from 1.13.0 to 2.0.9 - #125

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/sbt/org.scala-sbt-sbt-2.0.9
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/sbt/org.scala-sbt-sbt-2.0.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps org.scala-sbt:sbt from 1.13.0 to 2.0.9.

Release notes

Sourced from org.scala-sbt:sbt's releases.

2.0.9

🐛 bug fixes

Full Changelog: sbt/sbt@v2.0.8...v2.0.9

2.0.8

🐛 bug fixes

Full Changelog: sbt/sbt@v2.0.7...v2.0.8

2.0.7

⚠️ Remote code execution vulnerability fix

sbt team received a security report GHSA-943m-f264-54p4 from @​stasimus that when the serverConnectionType is set to Tcp, an attacker is able to execute arbitrary code remotely via BSP, similar to a recent bug that was found in JSON-RPC. sbt 1.13.0 and 2.0.7 fix this bug.

Builds with the default serverConnectionType are not affected. In affected builds, we recommend removing the serverConnectionType setting, or upgrading to a patched version or later. In an affected build, the setting might look like this:

Global / serverConnectionType := ConnectionType.Tcp

The remediation was implemented by @​stasimus.

🚀 updates

🐛 bug fixes

... (truncated)

Commits
  • 6165811 Merge pull request #9759 from eed3si9n/bport2/bport
  • 82560d3 [2.0.x] Update sbtn to 2.1.0-M1 (#9755)
  • 56b20c2 [2.0.x] IO 1.13.2
  • cee3208 [2.0.x] fix: Fix sbt runner script not starting on openSUSE (#9753)
  • 1bde2c0 [2.0.x] fix: keep macro subprojects off the pipelined classpath (#9719)
  • 621df16 [2.x] fix: virtualize semanticdbTargetRoot in the compile cache key (#9711)
  • fb1183e [2.0.x] Cache pipelined Java compilation
  • 2500707 [2.0.x] Fix Java output when export pipelining is disabled
  • 3127e8d sbt 2.0.8
  • 039b3db Merge pull request #9673 from eed3si9n/bport2/bport
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.scala-sbt:sbt](https://github.com/sbt/sbt) from 1.13.0 to 2.0.9.
- [Release notes](https://github.com/sbt/sbt/releases)
- [Commits](sbt/sbt@v1.13.0...v2.0.9)

---
updated-dependencies:
- dependency-name: org.scala-sbt:sbt
  dependency-version: 2.0.9
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, sbt. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Benchmark A/B

❌ benchmark job failed

base: success, head: failure — sbt Jmh/run failed (compile error on that side? see the run logs)

No comparison available — this is an explicit failure state, not a pass.

@kryptt

kryptt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Declining for now — this is hard-blocked upstream, not by our build: sbt-typelevel (ci-release / settings / site 0.8.7) has no sbt-2 cross-build at any version (typelevel/sbt-typelevel#899, itself waiting on Laika#774 and an sbt-gpg sbt-2 build), so plugin resolution fails before the build definition compiles. Everything else already cross-publishes _sbt2_3 at the pinned versions, and a stripped probe showed the codebase itself is sbt-2-clean (full sbt compile + root sbt test 786 examples, 0 failures, on JDK 25). Worth re-opening when sbt-typelevel#899 ships a release; the only known mechanical fallout then is two url(...) → uri(...) deprecations in build.sbt and rewriting the typelevel-coupled workflow steps.

@kryptt kryptt closed this Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/sbt/org.scala-sbt-sbt-2.0.9 branch October 2, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant