sbt/sbt-native-packager
61.2
Adequate · 27 September 2026
8.9k
lines of production code
Scala
primary language
3
measurements over time
What this system is
This system is the sbt-native-packager, an sbt plugin that automates the creation of deployment artifacts for Java applications. It generates native packages for Linux (Debian, RPM), Windows (MSI), and macOS, as well as Docker images, Universal distributions, and custom Java runtime images via jlink. The tool also supports building GraalVM native executables and provides extensive configuration for service lifecycle management, file permissions, and packaging validation.
How it got here
2011–2014 — Native packager architecture and testing
81 changes.
This period established the sbt-native-packager project by migrating legacy packaging logic into a modular AutoPlugin architecture supporting Debian, RPM, Windows, Docker, and Universal formats. It introduced core infrastructure for staging, file permissions, and reproducible builds, while expanding capabilities with native zip support, launcher JARs, and explicit daemon user configuration. The work was heavily supported by the creation of a comprehensive suite of scripted integration tests to verify packaging correctness across all target platforms.
2015–2017 — System loader refactoring and JDK packager
43 changes.
This period focused on refactoring system loader plugins into modular AutoPlugins and introducing a new JDK Packager plugin for native installers. Extensive scripted tests were added to validate these new features alongside improvements to start script generation and cross-platform compatibility.
2018–2026 — New packaging plugins and validation
26 changes.
This period introduced new packaging capabilities for JLink and GraalVM Native Images, alongside a comprehensive package validation framework to catch configuration errors early. Extensive scripted tests were added to verify these new features, as well as improvements to Docker layer grouping, file permission strategies, and SBT 2.x compatibility.
Features
Add Classpath and Launcher JAR packaging plugins
Two new SBT plugins are introduced to support Java application packaging: ClasspathJarPlugin and LauncherJarPlugin. ClasspathJarPlugin adds a new artifact (classifier 'classpath') that generates a JAR with a manifest specifying the runtime classpath, while LauncherJarPlugin adds a 'launcher' classifier JAR that embeds both the main class and classpath in its manifest. Both plugins integrate with the existing JavaAppPackaging to ensure these JARs are included in the Universal distribution and that the generated bash and batch scripts are configured to use them correctly.
src/main/scala/com/typesafe/sbt/packager/jar · high confidence
Add JDK Packager plugin for native installers via Ant tasks
Introduces the JDKPackagerPlugin, which enables generating native installer packages (such as .exe, .dmg, .pkg, .deb, and .rpm) by leveraging Oracle's javapackager Ant tasks bundled with JDK 8. The plugin adds a dedicated JDKPackager configuration scope with keys to control the package type, JVM arguments, application arguments, system properties, file associations, and application icons. It automatically locates the ant-javafx.jar library and generates the necessary Ant build definitions to produce the final packages.
src/main/scala/com/typesafe/sbt/packager/jdkpackager · high confidence
Add Play Framework RPM integration test project
A new test project has been added to the integration tests to validate packaging a Play Framework application as an RPM package. This includes a Vagrant environment provisioned via Ansible to set up the JDK, sbt, and build tools, along with a Play application configured with sbt-native-packager to generate an RPM (including epoch support). The entry also includes the Ansible test playbook that builds the RPM, installs it, verifies the service health, and cleans up.
integration-tests-ansible · high confidence
Add Windows test project with SBT build configuration
A new test project for Windows environments has been introduced, establishing the build infrastructure with SBT version 1.2.6 and configuring the sbt-native-packager plugin. The project includes the sbt-scalafmt plugin (version 1.10) to handle code formatting on compile, and provides a sample Scala application (ExampleApp) that demonstrates concurrent execution using a fixed thread pool.
test-project-windows · high confidence
Add simple test project for sbt-native-packager
A new test project named 'test-project-simple' has been added to the repository. It is configured with sbt version 1.2.6 and includes the sbt-scalafmt plugin for code formatting. The project defines a simple Scala application (ExampleApp) that prints memory usage and arguments, and includes a template file for default configuration, serving as a basic example or test case for the sbt-native-packager plugin.
test-project-simple · high confidence
Added Docker test project scaffold
A new test project for Docker functionality has been introduced, providing a concrete example for building and testing Docker images. This includes a docker-compose configuration defining a 'fooservice' using the 'docker-test:latest' image, an SBT build setup (version 1.5.4) that references the sbt-native-packager and includes the Spotify Docker Client library (version 3.5.13), and a basic Scala application entry point.
test-project-docker · high confidence
Initial Sphinx-based documentation structure
The project documentation has been migrated to Sphinx, introducing a new configuration file (conf.py) that utilizes the Read the Docs theme and sets the version to 1.0a1. This change establishes a structured documentation site with an introduction, a getting started guide, and sections for formats and archetypes, replacing the previous documentation format.
src/sphinx · high confidence
Introduce GraalVM Native Image packaging plugin
Adds a new plugin that enables building ahead-of-time native executables using GraalVM. Users can now generate native binaries locally or within a Docker container by enabling the plugin and configuring the GraalVM version. The plugin supports custom native-image options, handles resource directories under src/graal, and automatically selects the correct executable command for Windows or Unix environments.
src/main/scala/com/typesafe/sbt/packager/graalvmnativeimage · high confidence
Introduce JlinkPlugin for creating custom Java runtime images
Adds the JlinkPlugin, which enables users to package their application as a minimal, custom Java runtime image using the jlink utility. The plugin automatically detects required modules via jdeps, excludes removed Java platform modules, and provides hooks (jlinkIgnoreMissingDependency) to handle missing package dependencies, resulting in smaller and more secure deployment artifacts.
src/main/scala/com/typesafe/sbt/packager/archetypes/jlink · high confidence
Introduce Linux packaging plugin with daemon user and symlink support
The Linux packaging module now provides a dedicated plugin that manages file ownership, daemon user configuration, and symlink generation for Debian and RPM packages. Users can configure specific daemon users, groups, UIDs, GIDs, shells, and home directories, which are applied to installed files and service scripts. The plugin also automatically generates symlinks for binaries and configuration directories, and exposes settings for script replacements, log locations, and file descriptor limits to tailor the installed service behavior.
src/main/scala/com/typesafe/sbt/packager/linux · high confidence
Introduce native Debian packaging implementation alongside JDeb
The Debian plugin now includes a native packaging implementation (DebianNativePackaging) that uses the system's dpkg toolchain (dpkg-deb, dpkg-genchanges, dpkg-sig) to build .deb packages, in addition to the existing Java-based JDeb implementation. This new path generates native Debian control files and changelogs, supports package signing via dpkg-sig, and allows lintian validation. Users can enable this via the DebianNativePackaging plugin to leverage native tools instead of the JVM-based jdeb library.
src/main/scala/com/typesafe/sbt/packager/debian · high confidence
Introduction of the SbtNativePackager AutoPlugin
The sbt-native-packager is now available as an AutoPlugin (\SbtNativePackager\), allowing users to enable packaging capabilities simply by adding \enablePlugins(SbtNativePackager)\ to their build configuration. This top-level plugin aggregates settings and tasks from various packaging archetypes (Universal, Linux, Debian, Rpm, Windows, Docker) and provides a unified \autoImport\ namespace for all native packager keys. It establishes default values for common settings like \maintainer\, \packageDescription\, and \executableScriptName\, and includes deprecated helper methods (\java\_application\, \java\_server\) to guide users toward the new plugin-based enabling style.
src/main/scala/com/typesafe/sbt · high confidence
Native packager core utilities and staging infrastructure
This change introduces the foundational infrastructure for the native packager plugin, including file permission handling, hashing, and staging logic. It adds FileUtil to manage POSIX file permissions (with Windows fallback) and support for SOURCE\_DATE\_EPOCH to enable reproducible builds by normalizing file timestamps. Hashing utilities for SHA-1, SHA-512, and MD5 are added for artifact integrity checks. The Stager component now handles file synchronization with caching and ensures executable permissions are correctly set on staged scripts. Additionally, a comprehensive set of keys (Keys.scala) and settings helpers (SettingsHelper.scala) are defined to configure package metadata, script names, maintainer scripts, and publishing behaviors for various target platforms.
src/main/scala/com/typesafe/sbt/packager · high confidence
New /etc/default configuration templates for SystemV and Systemd packaging
The packaging archetypes now include new template files (application.ini-template, etc-default-template, and etc-default-systemd-template) that allow users to easily configure environment variables, JVM options, and PID file paths via /etc/default files. This change enables more flexible configuration of application settings at deployment time, particularly for SystemV and Systemd service managers, without requiring modifications to the startup scripts themselves.
src/main/resources/com/typesafe/sbt/packager/archetypes · high confidence
New SystemV init script templates for Debian and RPM packages
The SystemV packaging archetype now includes dedicated init script templates for both Debian and RPM distributions. The new Debian template utilizes standard LSB headers and start-stop-daemon for service management, while the RPM template integrates with Red Hat's init.d functions library. These templates provide users with robust, standardized service control (start, stop, restart, status) and support for configuration via environment files, ensuring consistent service behavior across different Linux package formats.
src/main/resources/com/typesafe/sbt/packager/archetypes/systemloader/systemv · high confidence
New package validation framework with standard checks
A new validation system has been introduced for package formats (such as Universal and Debian), allowing users to verify their package configuration before distribution. This includes a \validatePackage\ task and a set of standard validators that check for common issues: ensuring the package is not empty, verifying that all mapped files actually exist on disk, confirming that a maintainer is specified, and validating that RPM epoch values are non-negative. Users can now catch configuration errors early, with clear error messages and instructions on how to fix them.
src/main/scala/com/typesafe/sbt/packager/validation · high confidence
New test project for JDK packager integration
Added a new test project (\test-project-jdkpackager\) that demonstrates packaging Scala applications using the JDK's \javapackager\ tool. The project includes a JavaFX-based example application (\ExampleApp\) that displays system properties, and configures JVM options via a \jvmopts\ file to verify argument processing during the packaging process.
test-project-jdkpackager · high confidence
Project initialization and repository structure setup
The repository has been initialized with the core project structure, including the Apache 2.0 license, a code of conduct, and contribution guidelines. The build system is configured with a \.scalafmt.conf\ file (version 3.8.3) to enforce code formatting standards, and a \.gitignore\ file is provided to exclude IDE metadata and build artifacts. Documentation is established via a \README.md\ and \CHANGELOG.md\, and CI integration is set up with an \appveyor.yml\ configuration for Windows builds.
(repo-wide) · high confidence
Support for multiple main classes in application packaging
The packaging plugin now generates separate launch scripts for each main class defined in the project (e.g., \main-app\ and \second-app\) when no single main class is explicitly configured. If a main class is explicitly set via \Compile / mainClass\, the default script retains the project name while additional scripts for other main classes are still generated. This behavior is verified for both Bash and Windows environments.
src/sbt-test/bash/multiple-apps, src/sbt-test/windows/multiple-apps · high confidence
Support for overriding RPM scriptlets in packaging
Users can now provide custom RPM installation scriptlets (pre, post, preun, postun) to override the default packaging behavior. This change introduces the ability to define specific shell scripts for these lifecycle stages, allowing for more granular control over the installation and removal processes of RPM packages generated by the tool.
src/sbt-test/rpm/scriptlets-override-rpm/src · high confidence
Systemd service template and loader functions added
The systemd packaging archetype now includes a new service unit template (start-template) and a shell script for loader functions (loader-functions). The service template defines the unit structure, including support for configurable retry timeouts, success exit statuses, stop timeouts, and file descriptor limits. The loader functions provide scripts to add, start, stop, and restart the systemd service, handling configuration prefixing and enabling the service on the system.
src/main/resources/com/typesafe/sbt/packager/archetypes/systemloader/systemd · high confidence
Windows MSI packaging plugin initialization
The Windows packaging plugin has been initialized in this location, introducing the core infrastructure for generating Windows MSI installers via the WiX Toolset. This includes the \WindowsPlugin\ which wires up the build process to compile WiX source files and link them into an MSI, \WindowsKeys\ defining the configuration settings (such as product IDs, license files, and WiX options), and \WixHelper\ which manages the generation of the WiX XML structure, including directory trees, file components, environment variable updates, and shortcuts. Users can now enable this plugin to produce Windows installers for their projects.
src/main/scala/com/typesafe/sbt/packager/windows · high confidence
Removals
Removal of legacy Debian packaging plugin
The legacy Debian packaging plugin (DebianPlugin, Keys, and metadata.scala) has been removed from the codebase. This eliminates the ability to generate .deb packages, create control files, and run lintian checks via the previous implementation, effectively removing Debian-specific packaging capabilities from this module.
src/main/scala/com/typesafe/packager/debian · high confidence
Removal of legacy Linux packaging keys and mapping classes
The \Keys.scala\ file, which defined the \maintainer\ and \linuxPackageMappings\ settings, and the \LinuxPackageMapping.scala\ file, which contained the \LinuxFileMetaData\ and \LinuxPackageMapping\ case classes, have been deleted from the \src/main/scala/com/typesafe/packager/linux\ directory. This change removes the specific Scala definitions for Linux package file mappings and metadata configuration from this location, likely as part of a cleanup or consolidation into a common plugin structure.
src/main/scala/com/typesafe/packager/linux · high confidence
Behavioural changes
Debian packaging scripts now support custom daemon user and group IDs
The Debian package maintainer scripts (postinst, postrm, preinst, prerm) have been refactored to support explicit configuration of the daemon user and group. The postinst script now creates the daemon user and group using specific UID and GID values provided via template variables, and ensures the home directory is created. The postrm script handles cleanup by deleting the user and group only during a purge operation, while preinst and prerm remain minimal. This allows users to packagers to control the identity of the service account more precisely.
src/main/resources/com/typesafe/sbt/packager/debian · high confidence
Disable Jekyll processing for site content
A .nojekyll file has been added to the site root to prevent Jekyll from processing the site's content. This ensures that static assets and files starting with an underscore are preserved as-is rather than being treated as Jekyll-specific templates or data files.
src/site · high confidence
Docker layer grouping behavior changes with new test coverage
The Docker plugin's layer grouping logic has been updated, specifically ensuring that 'None' is treated as the last layer group and separating dependencies from application jars. This change is validated by new scripted tests in the 'test-layer-groups' directory, which verify that custom layer configurations (such as grouping Spark files under a specific layer ID) are correctly applied to the Docker image structure, and that disabling layer grouping results in a flat directory layout without numbered layer subdirectories.
src/sbt-test/docker/test-layer-groups · high confidence
Docker plugin refactored with new permission strategies and layer grouping
The Docker plugin has been restructured to introduce configurable file permission strategies (None, Run, MultiStage, CopyChown) and granular chmod types, allowing users to control how file modes are handled in the resulting image. It also implements a new layer grouping mechanism that separates dependencies, libraries, and configuration into distinct layers to improve Docker cache efficiency. Additionally, the plugin now supports multi-stage builds, BuildKit detection, and exposes UDP ports alongside TCP, while updating the default base image to eclipse-temurin:25.
src/main/scala/com/typesafe/sbt/packager/docker · high confidence
RPM packaging plugin refactored and migrated to sbt 1.x/2.x slash syntax
The RPM packaging plugin has been restructured to support modern sbt versions (1.x/2.x) by migrating to the slash syntax for settings and tasks, and by introducing a new \Rpm\ configuration scope. This change consolidates RPM-specific keys (such as metadata, dependencies, scriptlets, and build options) into a dedicated \RpmKeys\ trait and updates the plugin's internal helpers (\RpmHelper\, \RpmSpec\, \RpmMetadata\) to align with the new architecture. Users will see improved scoping for RPM settings, better integration with the Linux plugin's maintainer scripts, and updated default behaviors for RPM build processes, including support for relocatable packages and configurable daemon log files.
src/main/scala/com/typesafe/sbt/packager/rpm · high confidence
Refactor start script generation into modular plugins and add Ash shell support
The script generation logic in this package has been restructured into distinct, modular plugins: BashStartScriptPlugin, BatStartScriptPlugin, and a new AshScriptPlugin for generating scripts compatible with the lightweight ash shell (e.g., BusyBox). A shared CommonStartScriptGenerator trait and ScriptUtils handle the core logic for creating start scripts and forwarders, while ApplicationIniGenerator manages the generation of application.ini configuration files. This change introduces new sbt keys (e.g., bashScriptTemplateLocation, batScriptConfigLocation) and improves support for multiple main classes by generating specific scripts or forwarders for each discovered entry point.
src/main/scala/com/typesafe/sbt/packager/archetypes/scripts · high confidence
Refactor system loader plugins into AutoPlugins with new configuration keys
The system loader plugins (Systemd, SystemV, Upstart) have been extracted into their own AutoPlugins, introducing a new \ServerLoader\ enumeration and a set of shared configuration keys in \SystemloaderKeys\. This change adds \serviceAutostart\ to control whether the service starts after installation, \systemdSuccessExitStatus\ for Systemd, and \systemdIsServiceFileConfig\ to mark the Systemd unit file as a configuration file rather than a regular script. It also standardizes the start script location for Systemd to \/lib/systemd/system\ on Debian and \/usr/lib/systemd/system\ on RPM, and updates the Systemd plugin to use \TimeoutStopSec\ for the kill timeout.
src/main/scala/com/typesafe/sbt/packager/archetypes/systemloader · high confidence
Refactored Java application packaging into modular archetypes
The Java application packaging logic has been reorganized into distinct, modular components to improve maintainability and separation of concerns. The core settings and tasks for general Java applications are now defined in \JavaAppKeys\ and \JavaAppKeys2\, while the \JavaAppPackaging\ plugin handles the universal distribution structure, including classpath ordering and dependency artifact resolution. A new \JavaServerAppPackaging\ archetype specifically targets server applications, introducing settings for daemon user/group ownership, configurable log file locations (\daemonStdoutLogFile\), and integration with the \/etc/default\ configuration file. Supporting infrastructure includes \JavaServerBashScript\ for loading loader-specific init scripts (SystemD, SystemV, Upstart), \MaintainerScriptHelper\ for easier customization of Debian/RPM maintainer scripts, and \TemplateWriter\ for consistent script generation from templates.
src/main/scala/com/typesafe/sbt/packager/archetypes · high confidence
Refactored RPM packaging scripts with dedicated pre/post-install templates
The RPM packaging templates for the Java server archetype have been refactored to use dedicated \pre-template\ and \postun-template\ scriptlets. The new \pre-template\ handles user and group creation during initial installation and manages the \PACKAGE\_PREFIX\ configuration in \/etc/sysconfig/\, while the \postun-template\ ensures system users and groups are cleaned up only during a full uninstall (not during upgrades). This change centralizes control logic via \control-functions\ and improves the reliability of package lifecycle operations.
_src/main/resources/com/typesafe/sbt/packager/archetypes/java\server · high confidence
Simplified syntax for file mappings in build definitions
The packager plugin now allows users to specify source directories and content using simple strings (e.g., \directory("extra")\) instead of requiring explicit \file()\ conversions. This change, implemented via new \MappingsHelper\ and \PluginCompat\ modules, streamlines the configuration of file mappings in Universal and other packaging tasks, reducing boilerplate in build definitions.
src/main/scala-2.12 · high confidence
Support for explicit UID/GID and home directory creation in Linux packaging
The Linux packaging scripts now support specifying explicit user and group IDs (UID/GID) when creating system users and groups, allowing for more deterministic container or system environments. Additionally, the user creation process now automatically creates the user's home directory (defaulting to /var/lib/$user), ensuring that applications running as these users have a valid home directory available.
src/main/resources/com/typesafe/sbt/packager/linux · high confidence
Universal packaging plugin introduces native zip support and configurable archive options
The universal packaging plugin now supports creating zip archives using the system's native \zip\ command via the \makeNativeZip\ method and \useNativeZip\ setting, which better preserves executable permissions compared to the Java-based implementation. Additionally, the plugin exposes a new \universalArchiveOptions\ setting key, allowing users to customize command-line arguments passed to tar and zip utilities for tgz and txz packages. The plugin also defines \stage\ and \dist\ tasks for the universal configuration and includes validation to ensure mapped files exist before packaging.
src/main/scala/com/typesafe/sbt/packager/universal · high confidence
Updated backward compatibility filters for sbt 1.3.15
This release adds a new set of MiMa (Migration Manager) backward-compatibility excludes for version 1.3.15. These filters suppress warnings for API changes in the sbt-packager project, including new settings for Docker build environment variables, GraalVM native image configuration, and forwarder script templates for start scripts, as well as structural changes to Windows, Debian, and RPM packaging plugins.
src/main/mima-filters · high confidence
Updated shell and batch start scripts with improved argument handling and Cygwin support
The generated start scripts for Linux/macOS (bash and ash) and Windows (bat) have been updated to improve reliability and compatibility. Key changes include using \exec\ in forwarder scripts to ensure correct process signaling, adding support for the \JAVA\_OPTS\ environment variable in ash templates, and fixing argument parsing to correctly handle spaces and special characters. The bash and ash templates now include robust \realpath\ implementations to resolve symlinks correctly on macOS and handle Cygwin path conversions, while the Windows batch scripts have been enhanced to support the \-jvm-debug\ flag and better configuration file loading.
src/main/resources/com/typesafe/sbt/packager/archetypes/scripts · high confidence
Updated spotify-client test to use docker-client 3.5.13
The spotify-client sbt-test has been updated to depend on version 3.5.13 of the docker-client library, addressing a previous NullPointerException. The test script now verifies the Docker image by running the container and checking for the expected output.
src/sbt-test/docker/spotify-client · high confidence
Upstart service configuration now supports advanced lifecycle and resource settings
The Upstart system loader has been updated to allow users to configure service restart behavior, file descriptor limits, and environment variable handling. The generated Upstart job now includes a configurable kill timeout, a respawn policy with retry limits and intervals, and a setting for the maximum number of open file descriptors. Additionally, the service startup script now automatically loads an external environment configuration file and exports its variables to the daemon process.
src/main/resources/com/typesafe/sbt/packager/archetypes/systemloader/upstart · high confidence
Fixes
Disable jar repacking in RPM builds
The RPM packaging process now includes a configuration that disables the automatic repacking of JAR files (by setting \_\_jar\_repack to nil). This change addresses issues where repacking was incorrectly negated or causing build problems, resulting in faster and more reliable RPM builds for users.
src/main/resources/com/typesafe/sbt/packager/rpm · high confidence
Test coverage
Add minimal jlink integration test; Add sbt test for Java Home variable expansion; Add sbt-test for app settings and native packaging; Add scripted test for Docker image removal via clean task; Add scripted test for Docker image user creation; Add scripted test for RPM setarch packaging; Add scripted test for basic Docker image building; Add scripted tests for JDK 8, 11, 17, 21, and 25 support; Add test for command-line settings in AshScriptPlugin; Added JDK packager test scenarios for image, mappings, and minimal packaging; Added SBT 2.x compatibility tests for universal mapping helpers; Added Windows memory-settings sbt test; Added Windows-specific sbt-test cases for app home and dynamic environment names; Added Windows-specific test for custom main class packaging; Added automated test for RPM changelog and brpJavaRepackJars configuration; Added integration tests for Ash, Bash, Debian, and RPM packaging plugins; Added integration tests for Docker build command override; Added regression test for RPM scriptlet override functionality; Added regression test for rpm scriptlet overrides; Added regression tests for RPM scriptlet configuration and version checking; Added sbt test cases for JVM memory settings and simple application packaging; Added sbt test for launcher JAR packaging; Added sbt test for memory settings in native packaging; Added sbt-test cases for custom ASH script templates; Added sbt-test fixtures for script debug and help flags; Added scripted test for Docker latest tag updates; Added scripted test for Docker multiple tags support; Added scripted test for Docker plugin with multiple main classes; Added scripted test for JDKPackager package mappings; Added scripted test for RPM artifact path generation; Added scripted test for RPM snapshot override behavior; Added scripted test for custom WiX source support; Added scripted test for debian genChanges task; Added scripted test for debian package generation; Added scripted test for debian package mapping and control script; Added scripted test for debian packageName configuration; Added scripted test for executableScriptName setting; Added scripted test for jdeb directory mappings; Added scripted test for universal package naming; Added scripted tests for Debian package Conflicts and Provides metadata; Added scripted tests for Debian package generation; Added scripted tests for Debian package structure and autostart configuration; Added scripted tests for Docker alias and build options; Added scripted tests for Docker entrypoint plugin; Added scripted tests for Docker environment variable handling; Added scripted tests for Docker file permission strategies; Added scripted tests for Docker image generation and execution; Added scripted tests for Docker label handling; Added scripted tests for Docker staging functionality; Added scripted tests for Docker volume export behavior; Added scripted tests for JDKPackager image generation; Added scripted tests for RPM and universal zip packaging; Added scripted tests for RPM packaging with and without Java repackaging; Added scripted tests for RPM start script template overrides; Added scripted tests for debian packaging template and directory mappings; Added scripted tests for executableScriptName setting; Added scripted tests for systemd Debian packaging and autostart configuration; Added scripted tests for systemd loader function template override; Added scripted tests for sysvinit stop timeout packaging; Added scripted tests for universal packaging formats; Added scripted tests for universal publish and Maven publishing; Added scripted tests for zip packaging without top-level directory; Added test case for classpath-jar functionality; Added test case for launching JARs from paths containing spaces; Added test case for overriding /etc/default in Debian packaging; Added test case for overriding bash and bat templates; Added test cases for Scala 3 top-level main methods; Added test coverage for JLinkPlugin scenarios; Added test coverage for RPM path override behavior; Added test coverage for RPM path override scenarios; Added test coverage for packaging utilities and plugins; Added test coverage for universal distribution packaging; Added test fixtures for Debian package mapping helpers; Added test fixtures for docker and universal plugin packageName support; Added test fixtures for executableScriptName setting; Added test fixtures for overriding Debian control scripts; Added test fixtures for systemd integration on Debian and RPM; Added test fixtures for sysvinit RPM generation; Added test for Cygwin Java app archetype; Added test for Debian daemon package with custom group ID; Added test for Debian package file permissions; Added test for Debian package user shell configuration; Added test for Docker command override and label behavior; Added test for JVM options in application.ini; Added test for RPM symlink handling in spec files; Added test for UDP port exposure in Docker builds; Added test for UDP-only port exposure; Added test for Windows batch script generation; Added test for classifier support in multiproject builds; Added test for classpath-jar plugin; Added test for custom main class in staged distribution; Added test for daemon user control script generation; Added test for daemon user home directory creation in Debian packaging; Added test for executableScriptName setting; Added test for handling missing dependencies in JLinkPlugin; Added test for jdeb dependency packaging; Added test for overriding Debian control files; Added test resources for jdeb directory mapping validation; Added test suite for java-app-archetype; Added test utility for validating Windows batch exit codes; Added tests for Debian package user/group ID configuration; Added tests for absolute paths in classpath; Added tests for executableScriptName setting; Added tests for systemd RPM packaging and service autostart configuration; Added tests to verify correct start script template selection for systemd, SystemV, and Upstart; Added validation test for empty distribution prevention; Test for multi-stage intermediate image removal; Test verifies staging directory cleanup of removed configuration files; Updated staging-custom-main test sources.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 43 → 61 (+18.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 91 (-8.9)
- Architecture 69 → 100 (+30.9)
- Maturity 55 → 54 (-1.0)
- Readiness 26 → 55 (+29.4)
- Security 50 → 67 (+16.4)
Resolved (25)
- Dimension evaluation failed
- High IaC: DS-0002 (src/sbt-test/docker/build-command/src/main/resources/docker-test/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: DS-0026 (src/sbt-test/docker/build-command/src/main/resources/docker-test/Dockerfile)
- Medium IaC: DS-0001 (src/sbt-test/docker/build-command/src/main/resources/docker-test/Dockerfile)
- …and 5 more
New (99)
- Concentrated knowledge decay
- Duplicated block (11 lines × 2) (src/main/scala/com/typesafe/sbt/packager/docker/DockerPlugin.scala)
- Duplicated block (5 lines × 2) (src/main/scala-2.12/com/typesafe/sbt/packager/MappingsHelper.scala)
- Duplicated block (6 lines × 2) (src/main/scala-2.12/com/typesafe/sbt/packager/MappingsHelper.scala)
- Duplicated block (6 lines × 2) (src/main/scala-2.12/com/typesafe/sbt/packager/MappingsHelper.scala)
- Duplicated block (6–9 lines × 2) (src/main/scala/com/typesafe/sbt/packager/docker/DockerPlugin.scala)
- Duplicated block (7 lines × 2) (src/main/scala/com/typesafe/sbt/packager/archetypes/scripts/AshScriptPlugin.scala)
- Duplicated block (8 lines × 2) (src/main/scala/com/typesafe/sbt/packager/debian/DebianMetadata.scala)
- Duplicated block (8 lines × 2) (src/main/scala/com/typesafe/sbt/packager/debian/DebianPlugin.scala)
- Duplicated block (8–9 lines × 3) (src/main/scala/com/typesafe/sbt/packager/SettingsHelper.scala)
- FileTooLong: docker/DockerPlugin.scala (src/main/scala/com/typesafe/sbt/packager/docker/DockerPlugin.scala)
- FixmeComment (src/main/scala/com/typesafe/sbt/packager/debian/JDebPackaging.scala)
- FixmeComment (src/main/scala/com/typesafe/sbt/packager/debian/JDebPackaging.scala)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 79 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- src/sbt-test — 1 commit
Notable commits
- change: Support simpler syntax without need for implicit conversion in SBT 2.x (#1776)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sbt/sbt-native-packager was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9c046d48878c4af0e2bf0f575dadf593a0eb3f19 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.