Skip to content
CAI
Software that uses CAICheck a score

rtimush/sbt-updates

62.2

Adequate · 28 September 2026

959

lines of production code

Scala

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an sbt plugin designed to detect and report available updates for project dependencies and plugins. It supports cross-building across multiple SBT and Scala versions, with robust metadata loading from Maven and Ivy repositories. The tool provides configurable reporting in text or CSV formats, allows build failures on detected updates, and handles complex authentication and version parsing scenarios.

How it got here

2012 — SBT 1.x migration and feature expansion

9 changes.

The project migrated its build infrastructure from SBT 0.12 to 1.13, replacing legacy cross-building plugins with sbt-projectmatrix and dropping support for SBT 0.11. This period introduced significant new features, including CSV report generation, build failure options, and a custom version parser to replace external dependencies, all supported by comprehensive test coverage.

2015–2017 — Metadata engine and Scala 3 support

7 changes.

The project enhanced its metadata loading capabilities by introducing caching, Ivy repository support, and HTML-based version extraction, accompanied by comprehensive unit and scripted tests. Concurrently, a compatibility layer was added to enable cross-compilation with Scala 3 alongside the existing Scala 2.12 support.

2018–2021 — Test coverage and authentication enhancements

7 changes.

This period focused on expanding test coverage for the sbt-updates plugin, adding scripted tests for plugin interactions, dependency overrides, and Maven Central detection. It also introduced support for authentication headers and repository-scoped credentials to improve handling of private repositories and custom authentication mechanisms.

Features

Add HTML-based version extraction capability

The metadata extractor now supports extracting version numbers from HTML content. A new \HtmlVersionExtractor\ class uses a regular expression to identify version strings within anchor tags, and a \VersionExtractor\ type alias is introduced in the package object to define the extraction interface.

src/main/scala/com/timushev/sbt/updates/metadata/extractor · high confidence

Dependency update reporting now supports CSV output and configurable build failure

The plugin now allows users to write dependency update reports to a file in either standard text or CSV format via the new \dependencyUpdatesReport\ and \dependencyUpdatesCsvReport\ tasks. Additionally, a new \dependencyUpdatesFailBuild\ setting enables builds to fail automatically when updates are detected, and the \dependencyUpdatesFilter\ setting provides a unified way to include or exclude specific dependencies from reporting, replacing the deprecated \dependencyUpdatesExclusions\.

src/main/scala/com/timushev/sbt/updates · high confidence

Initial project setup and configuration

This change establishes the foundational configuration for the sbt-updates project. It introduces \.scalafmt.conf\ to enforce code formatting with scalafmt version 3.11.5 and specific style rules, and \.scala-steward.conf\ to configure automated dependency updates by pinning the sbt version to the 1.x series and ignoring the scripted-plugin. Additionally, it adds standard repository files including \CONTRIBUTING.md\, \LICENSE\ (BSD 3-Clause), and updates \.gitignore\ to exclude build artifacts and BSP directories, while \README.md\ documents the plugin's installation, tasks, and settings for sbt 0.13, 1.x, and 2.x.

(repo-wide) · high confidence

Removals

Removed SBT 0.11 plugin implementation files

The source files for the SBT 0.11 version of the plugin (CrossVersion.scala, UpdatesPlugin.scala, and UpdatesPluginTasks.scala) have been deleted from the project. This change removes the specific implementation code for the SBT 0.11.x series, aligning with the decision to disable cross-building for that version.

src/main/scala-sbt-0.11 · high confidence

Behavioural changes

Introduce Scala 3 compatibility layer

Added a new \Compat.scala\ file for Scala 3 (\src/main/scala-3\) to support cross-compilation alongside the existing Scala 2.12 version. This file implements the \Compat\ object with methods for setting settings, converting credentials, and handling uncached tasks, using Scala 3-specific syntax and imports (such as \Def.Settings\ and \Uncached\) to ensure the plugin functions correctly on both Scala 2.12 and Scala 3.

src/main/scala-2.12 · high confidence

Refactored metadata loading with caching and Ivy support

The metadata loading logic in the \metadata\ package has been restructured to improve performance and repository compatibility. A new \CachingMetadataLoader\ wraps loaders to cache version lookups, preventing redundant network requests for the same module. The system now supports Ivy-style repository patterns via a new \IvyMetadataLoader\, which extracts versions from HTML listings, in addition to the existing Maven XML metadata support. A \CompoundMetadataLoader\ allows combining multiple loaders for a single resolver, and a factory pattern with synchronized access ensures thread-safe creation and caching of these loaders.

src/main/scala/com/timushev/sbt/updates/metadata · high confidence

Replaced external semver library with custom version parser and ordering

The plugin now uses a custom-built version parser and ordering logic instead of the external semverfi library. This change introduces support for parsing versions prefixed with 'v', allows hyphens in pre-release identifiers, treats the '+' character as a patch version component, and recognizes 'Final' and 'Release' as release qualifiers. It also implements natural string ordering for version parts and ensures numeric version parts use long integers to prevent overflow, resulting in more robust version comparison and parsing behavior for users.

src/main/scala/com/timushev/sbt/updates/versions · high confidence

Support authentication headers and repository-scoped credentials

The authentication module now supports custom HTTP headers in addition to standard username/password credentials. It introduces a new configuration path via \csrConfiguration\ (Coursier settings) to load repository-specific authentication, allowing users to define credentials scoped to a specific repository ID rather than just a host. The system prioritizes repository-scoped credentials over host-based ones and correctly parses both sbt \Credentials\ and Coursier authentication structures.

src/main/scala/com/timushev/sbt/updates/authentication · high confidence

Test coverage

Added scripted test for sbt-updates with sbt-scalafmt; Added scripted tests for cross-Scala version support; Added scripted tests for dependency update filtering and cross-build scenarios; Added scripted tests for the auto-updates plugin; Added scripted tests for the includes feature; Added test case for sbt-updates dependency checking; Added test coverage for sbt plugin dependency updates; Added test coverage for update detection, dependency overrides, and CSV reporting; Added test for missing credentials handling; Added test for sbt-updates plugin detection on Maven Central; Added tests for cross-version and standard dependency overrides; Added tests for version parsing and ordering logic; Added unit tests for metadata loading and repository pattern logic; Updated scripted test for sbt-updates plugin.

Dependencies

Upgrade to SBT 1.13 and modernize build infrastructure

The build system has been upgraded from SBT 0.12 to 1.13, replacing the legacy sbt-cross-building plugin with sbt-projectmatrix to enable cross-building against multiple SBT versions. This change introduces a new SbtAxis configuration that automatically maps SBT versions to appropriate Scala versions (2.12 for SBT 1.x, 3.8.4 for SBT 2.x) and updates core plugins including sbt-scalafmt, sbt-git, sbt-git-versioning, and sbt-pgp to their latest versions.

project · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 62 → 62 (-0.1)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 57 → 57 (+0.0)
  • Readiness 56 → 56 (+0.0)
  • Security 62 → 62 (+0.0)

New (2)

  • Documentation: no project overview (README.md)
  • RepositoryPattern.substitute (cognitive 27) (src/main/scala/com/timushev/sbt/updates/metadata/RepositoryPattern.scala)

Changes since last survey

  • 3 commits — 3 feature/other, 0 fixes

By area

  • (repo) — 2 commits
  • .github/workflows — 1 commit

Notable commits

  • change: Bump sbt/setup-sbt from 1.5.8 to 1.5.9
  • change: Merge pull request #501 from anatoliykmetyuk/br/ivy-independent-updates
  • change: Merge pull request #503 from rtimush/dependabot/github_actions/sbt/setup-sbt-1.5.9

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rtimush/sbt-updates was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e3c52e03941694607f811d65e8a22203bd03d809 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.