Skip to content
CAI
Software that uses CAICheck a score

scala-steward-org/scala-steward

57.3

Adequate · 27 September 2026

13.5k

lines of production code

Scala

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Scala Steward, an automated dependency update bot for Scala projects. It detects dependencies across multiple build tools—including SBT, Maven, Gradle, Mill, and Scala CLI—and generates pull requests to upgrade them. The tool handles complex migration tasks by applying Scalafix rules and executing post-update hooks like code formatting, while supporting various Git forges such as GitHub, GitLab, and Azure Repos.

How it got here

2018–2019 — architecture modernization and stability

35 changes.

This period focused on a comprehensive architectural overhaul, migrating the build system to sbt-typelevel, upgrading to Scala 3, and replacing legacy modules with robust, typed implementations for Git, I/O, and dependency resolution. The work significantly enhanced reliability and security by introducing sandboxed command execution, refined update filtering algorithms, and a structured data model for dependency tracking. Extensive test coverage was added to validate these core components, ensuring stable operation and improved maintainability.

2020–2021 — build tool expansion and reliability

20 changes.

This period focused on expanding build tool support by unifying the abstraction layer, adding initial integration for Mill, and enhancing SBT and Maven capabilities. Concurrently, the system introduced configurable post-update hooks and refined artifact migration logic to improve automated repository maintenance. Significant effort was also dedicated to testing coverage and stabilizing HTTP client behavior with improved retry mechanisms.

2022–2026 — forge abstraction and build tool expansion

23 changes.

This period focused on unifying the version control integration layer through a new forge abstraction, adding native support for Gitea, Azure Repos, and Bitbucket variants while refactoring existing GitHub and GitLab implementations. Concurrently, the project expanded its build tool detection capabilities to include Scala CLI, Gradle Version Catalogs, and Giter8 template rendering, ensuring comprehensive dependency extraction across diverse Scala ecosystems.

Features

Add Bitbucket Cloud support

Users can now use Scala Steward with Bitbucket Cloud repositories. This change introduces a new Bitbucket API implementation that handles forking, creating and listing pull requests, commenting, and closing PRs. It also supports fetching repository metadata and branch information. Note that updating existing pull requests is not yet supported for Bitbucket, and features like labels, assignees, and reviewers will log warnings if used, as they are not implemented for this forge.

modules/core/src/main/scala/org/scalasteward/core/forge/bitbucket · high confidence

Add Bitbucket Server forge support

Users can now connect Scala Steward to Bitbucket Server instances. This change introduces a new Bitbucket Server API client that handles repository metadata, branch listing, and pull request operations (creation, commenting, closing, and retrieval). The implementation includes authentication via Basic Auth with an XSRF bypass header and JSON serialization for Bitbucket Server's API structures. Note that updating pull requests is not yet supported and will log a warning, and features like assignees, reviewers, and labels are currently unsupported or only partially implemented with corresponding warnings.

modules/core/src/main/scala/org/scalasteward/core/forge/bitbucketserver · high confidence

Add Scala CLI build tool support

Scala Steward now detects and manages Scala CLI projects (identified by .sc and .scala files containing specific directives). Dependencies are extracted by invoking \scala-cli export --sbt\ and parsing the resulting SBT structure via the existing SBT algorithm. Scalafix migrations are supported for Scala CLI builds, executed via \scala-cli fix\ with built-in rules disabled to ensure only the specified migration rules are applied.

modules/core/src/main/scala/org/scalasteward/core/buildtool/scalacli · high confidence

Add initial Azure Repos integration

Users can now connect Scala Steward to Azure Repos. This change introduces the AzureReposApiAlg implementation, including JSON codecs for mapping Azure DevOps API responses to internal data structures and URL builders for constructing API endpoints. The integration supports creating pull requests, retrieving pull request and branch details, listing open pull requests, closing pull requests, and commenting on pull requests. Note that updating pull requests and assigning reviewers or assignees are not yet supported for Azure Repos.

modules/core/src/main/scala/org/scalasteward/core/forge/azurerepos · high confidence

Automated release tagging script added

A new shell script at scripts/release.sh has been introduced to streamline the release process. When executed with a version number as an argument, it automatically creates an annotated and signed Git tag for that version and pushes it to the remote repository, replacing the previous manual or alternative tooling approach.

scripts · high confidence

CLI now supports a dedicated validate-repo-config subcommand

Users can now validate their repository configuration files directly from the command line. The Main entry point has been updated to detect a new usage pattern, Cli.Usage.ValidateRepoConfig, which triggers the ValidateRepoConfigContext to validate and report on the specified config file, separate from the standard Steward run flow.

modules/core/src/main/scala/org/scalasteward/core · high confidence

Giter8 template rendering before dependency extraction

The core build-tool module now includes a new Giter8Alg that detects Giter8 templates (src/main/g8) and renders them to a target directory before attempting to extract dependencies. This ensures that generated build files (like build.sbt) are available for analysis, allowing the tool to recognize and update dependencies in projects that use Giter8 scaffolding.

modules/core/src/main/scala/org/scalasteward/core/buildtool/giter8 · high confidence

Initial Gitea forge integration

Added support for Gitea as a new forge backend, enabling users to manage repositories and pull requests on Gitea instances. The implementation includes creating and listing pull requests, handling labels (including automatic creation and attachment), and managing forks. Note that updating existing pull requests is currently not supported and will log a warning instead of failing.

modules/core/src/main/scala/org/scalasteward/core/forge/gitea · high confidence

Initial project scaffolding and configuration

The repository is initialized with core configuration files including a \.scala-steward.conf\ to enable automatic pull request updates, a \.mergify.yml\ to automatically label and merge Scala Steward's dependency update PRs, and a \.scalafmt.conf\ updated to version 3.11.5 with Scala 2.13 source 3 dialect and new syntax conversion enabled. The project also establishes a Code of Conduct, a \.git-blame-ignore-revs\ file to ignore formatting commits, and a \repos.md\ listing the repositories managed by this instance, while removing the legacy Travis CI configuration.

(repo-wide) · high confidence

Initial support for Mill build tool

Scala Steward can now detect and update dependencies in projects using the Mill build tool. The new \MillAlg\ implementation discovers builds by looking for \build.sc\, \build.mill\, or \build.mill.scala\ files, and it also supports reading the Mill version from \.mill-version\ or \.config/mill-version\ files. It extracts project dependencies by running the Mill CLI with the Scala Steward plugin, handling version-specific CLI flags (such as \--disable-ticker\ for Mill 0.11+ and \--ticker=false\ for 0.12+) and automatically including the Mill main library and detected Mill plugins in the update scope.

modules/core/src/main/scala/org/scalasteward/core/buildtool/mill · high confidence

Introduce ScalafmtAlg for version detection and reformatting

A new ScalafmtAlg component has been added to handle Scalafmt-specific operations. It detects the configured Scalafmt version by parsing the .scalafmt.conf file using the circe HOCON parser, constructs the appropriate dependency (handling the groupId change from com.geirsson to org.scalameta for versions \>= 2.0.0-RC2), and provides functionality to reformat changed files using the scalafmt CLI with --mode changed and --non-interactive flags.

modules/core/src/main/scala/org/scalasteward/core/scalafmt · high confidence

Introduce UpdateState model for dependency tracking

A new \UpdateState\ data model has been added to represent the status of dependency updates, replacing previous ad-hoc representations. This model distinguishes between dependencies that are up-to-date, outdated, or associated with pull requests (which can be open, outdated, or closed). It also includes a human-readable \show\ method to display the current state of a dependency, such as version transitions or PR links, aiding in clearer reporting and state management for update operations.

modules/core/src/main/scala/org/scalasteward/core/update/data · high confidence

Introduce configurable post-update hooks for automated repository maintenance

Scala Steward now supports post-update hooks that automatically run commands after applying dependency updates. This includes built-in hooks for reformatting code with scalafmt and regenerating GitHub Actions workflows when specific sbt plugins (such as sbt-github-actions, sbt-typelevel, and sbt-spiewak) are updated. These hooks can be enabled or disabled per repository via configuration, and their commits are optionally added to .git-blame-ignore-revs to keep blame statistics clean.

modules/core/src/main/scala/org/scalasteward/core/edit/hooks · high confidence

Introduces typed Git data models and a file-based Git implementation

The \modules/core/src/main/scala/org/scalasteward/core/git\ package now defines strict case classes for Git entities—\Author\ (with optional signing keys), \Branch\, \Commit\ (wrapping a \Sha1\), and \CommitMsg\ (supporting templated titles, body paragraphs, and trailers)—replacing previous raw string usage. It also introduces \FileGitAlg\, a concrete implementation of the \GenGitAlg\ interface that executes Git commands via the local file system, enabling features like bypassing Git hooks, configurable commit sign-offs, and structured commit message generation.

modules/core/src/main/scala/org/scalasteward/core/git · high confidence

New JSON-based key-value store with optional caching

The persistence layer now uses a new \KeyValueStore\ abstraction backed by JSON files, where each key is stored as a separate file in a versioned directory structure. This implementation includes a \CachingKeyValueStore\ wrapper that caches the most recently accessed key-value pair in memory to reduce disk I/O for repeated lookups. Users will benefit from improved performance on frequent reads and cleaner, file-based storage for configuration and state data.

modules/core/src/main/scala/org/scalasteward/core/persistence · high confidence

New utility components for HTTP, time, and string handling

The \util\ package now includes several new modules: \HttpJsonClient\ provides a unified HTTP client with JSON encoding/decoding and pagination support; \DateTimeAlg\ and \Timestamp\ offer time-related utilities; \UrlChecker\ checks URL existence with caching; \Details\ generates HTML details elements; and \string.scala\ adds string manipulation helpers like \extractWords\ and \splitBetweenLowerAndUpperChars\. These changes introduce new capabilities for handling HTTP requests, time, and string processing within the core utility layer.

modules/core/src/main/scala/org/scalasteward/core/util · high confidence

Support for Gradle Version Catalogs

Scala Steward now reads dependencies and plugins defined in Gradle Version Catalogs (libs.versions.toml). It parses the libraries and plugins tables to extract dependency coordinates and versions, and applies a default resolver for Gradle plugins from the official Gradle Plugin Portal.

modules/core/src/main/scala/org/scalasteward/core/buildtool/gradle · high confidence

Removals

Removal of experimental core modules

The \DependencyUpdate\, \Main\, \io\, and \sbt\ source files have been deleted from the core module. This removes the previously existing functionality for parsing dependency update strings, executing shell commands (such as \git clone\ and \sbt dependencyUpdates\), and managing repository cloning workflows, effectively stripping out these experimental or work-in-progress capabilities from the library.

modules/core/src/main/scala/eu · high confidence

Behavioural changes

Artifact migrations now require at least one 'before' identifier and are loaded from a remote config

The artifact migration system has been refactored to improve reliability and flexibility. The \ArtifactChange\ model now enforces that at least one of \groupIdBefore\ or \artifactIdBefore\ must be set, preventing ambiguous or incomplete migration rules. Additionally, migrations are no longer hardcoded; they are now loaded dynamically from a remote configuration file (defaulting to the project's GitHub user content) via \ArtifactMigrationsLoader\, allowing users to disable defaults or provide custom migration sources through the \ArtifactCfg\ configuration.

modules/core/src/main/scala/org/scalasteward/core/update/artifact · high confidence

GitHub integration refactored to support GitHub Apps and PR metadata

The GitHub forge implementation has been rewritten to support GitHub Apps authentication, allowing the tool to automatically discover accessible repositories and manage installation access tokens. Pull request creation and updates now support assigning users and teams as reviewers or assignees, and the system correctly handles GitHub Enterprise by accepting a configurable API host. The refactoring also introduces dedicated models for API payloads and responses, improving how labels, comments, and PR states are managed.

modules/core/src/main/scala/org/scalasteward/core/forge/github · high confidence

GitLab integration refactored to support assignees, reviewers, and source branch removal

The GitLab forge implementation has been updated to support assigning assignees and reviewers to merge requests, as well as removing the source branch after merging. This is achieved by introducing a new \GitLabAuthAlg\ for Private-Token authentication, a \Url\ helper for constructing API endpoints, and a refactored \GitLabApiAlg\ that maps user names to IDs and includes optional \assignee\_ids\, \reviewer\_ids\, and \remove\_source\_branch\ fields in the merge request payload.

modules/core/src/main/scala/org/scalasteward/core/forge/gitlab · high confidence

HTTP client configuration and retry behavior

The HTTP client setup now uses the JDK HTTP client via http4s-jdk-http-client instead of the deprecated okhttp client. Users will see that URL checking no longer follows redirects, and HTTP requests now include an X-Attempt header for tracking. Additionally, the client implements retry logic that respects the Retry-After response header for 403, 429, and 503 status codes, ensuring requests are retried with appropriate delays rather than failing immediately.

modules/core/src/main/scala/org/scalasteward/core/client · high confidence

Introduce configurable exit code policy for run results

The application now allows users to configure how the process exit code is determined based on the outcome of repository updates. A new \ExitCodePolicy\ mechanism supports two modes: \SuccessIfAnyRepoSucceeds\ (exit 0 if at least one repository is processed successfully) and \SuccessOnlyIfAllReposSucceed\ (exit 0 only if all repositories are processed successfully). This is exposed via a new CLI option and configuration field, allowing users to tailor the exit behavior to their CI/CD requirements.

modules/core/src/main/scala/org/scalasteward/core/application · high confidence

Introduce sandboxed command execution with configurable timeouts and buffer limits

The \modules/core/src/main/scala/org/scalasteward/core/io\ package now provides a new \ProcessAlg\ that supports executing commands within a Firejail sandbox. When the sandbox is enabled, commands are wrapped with \firejail --quiet\ and restricted by whitelisted and read-only directories, while environment variables are explicitly passed. The underlying process execution logic has been updated to enforce a configurable \processTimeout\ and a \maxBufferSize\ for output lines, raising specific exceptions for timeouts, buffer overflows, or non-zero exit codes. Additionally, the \FileAlg\ has been refactored to use \Resource\ for temporary file creation and deletion, ensuring files are cleaned up even if writes fail.

modules/core/src/main/scala/org/scalasteward/core/io · high confidence

Introduce typed wrappers for SBT and Scala versions

The system now uses distinct \SbtVersion\ and \ScalaVersion\ data types instead of plain strings to represent version identifiers. This change improves type safety by ensuring that SBT and Scala versions are handled separately throughout the build tool logic, reducing the risk of mixing them up, while maintaining the same JSON serialization and ordering behavior as before.

modules/core/src/main/scala/org/scalasteward/core/buildtool/sbt/data · high confidence

Introduces refresh backoff to skip failing repositories

The repository cache refresh process now includes a backoff mechanism that prevents repeated attempts to refresh repositories that have recently failed. A new \RefreshErrorAlg\ tracks errors in the key-value store and, if a repository failed within a configured backoff period, the system skips the refresh and logs the reason. This change improves stability by avoiding unnecessary work and potential resource exhaustion on unstable repositories.

modules/core/src/main/scala/org/scalasteward/core/repocache · high confidence

Major refactor of repository configuration model and loading

The repository configuration system has been completely rewritten to support a more granular and flexible setup. The configuration model is now split into dedicated case classes for commits, pull requests (including frequency, allowed hours, and grouping), updates (with allow/ignore/pin patterns and cooldowns), and post-update hooks. Configuration loading now searches for \.scala-steward.conf\ in multiple locations (root, \.github\, \.config\) and supports merging a global default configuration with repository-specific overrides. A new \ValidateRepoConfigAlg\ subcommand allows users to validate their configuration files before running updates.

modules/core/src/main/scala/org/scalasteward/core/repoconfig · high confidence

Maven dependency resolution now excludes transitive dependencies

When Scala Steward retrieves dependencies for Maven projects, it now runs the \dependency:list\ command with the \-DexcludeTransitive=true\ flag. This change ensures that only direct dependencies are reported, preventing transitive dependencies from cluttering the update suggestions and potentially causing unnecessary or incorrect update proposals.

modules/core/src/main/scala/org/scalasteward/core/buildtool/maven · high confidence

New Coursier-based dependency resolution and metadata extraction

The core module now uses the Coursier library to fetch dependency versions and metadata, replacing the previous SbtAlg-based approach. This change introduces a new CoursierAlg interface that retrieves versions and dependency metadata (including homepage, SCM URL, release notes, and version scheme) by fetching POM and Ivy files, supporting both Maven and Ivy repositories with authentication. A new VersionsCache component manages version caching with configurable TTL and error handling, while DependencyMetadata structures the extracted information for use in pull requests.

modules/core/src/main/scala/org/scalasteward/core/coursier · high confidence

New forge-agnostic data models for pull requests and repository metadata

The \modules/core/src/main/scala/org/scalasteward/core/forge/data\ package now includes a set of new case classes (\AuthenticatedUser\, \BranchOut\, \Comment\, \CommitOut\, \NewPullRequestData\, \PullRequestNumber\, \PullRequestOut\, \PullRequestState\, \RepoOut\, \UpdateState\, \UserOut\) that define the data structures used to represent forge interactions. \NewPullRequestData\ specifically introduces a configurable \maximumPullRequestLength\ to truncate PR bodies and adds JSON metadata comments to PRs, while \PullRequestState\ normalizes state strings (e.g., 'merged' to 'closed') across different forges. These models replace previous forge-specific implementations, providing a unified interface for creating and managing pull requests and repository data regardless of the underlying forge (GitHub, GitLab, etc.).

modules/core/src/main/scala/org/scalasteward/core/forge/data · high confidence

Pull request state is now persisted and refreshed before closing obsolete PRs

The nurture module now tracks the state of pull requests in a local repository (PullRequestRepository) and refreshes their status from the forge before deciding to close them as obsolete. This ensures that only truly closed PRs are removed, and it prevents the tool from accidentally closing PRs that were manually updated or closed by project maintainers.

modules/core/src/main/scala/org/scalasteward/core/nurture · high confidence

Refactored dependency scanning into dedicated scanner components

The dependency update logic in the core module has been restructured to separate concerns: \ScannerAlg\ now orchestrates file discovery using \GitAlg.findFilesContaining\, while \ModulePositionScanner\ and \VersionPositionScanner\ handle the specific regex-based parsing for SBT, Mill, Maven, and Scala \val\ definitions. This change improves the maintainability and precision of how Scala Steward identifies and locates dependency versions and module coordinates across different build tool formats.

modules/core/src/main/scala/org/scalasteward/core/edit/update · high confidence

Refactored update application into a structured EditAlg with explicit EditAttempt tracking

The core logic for applying dependency updates has been consolidated into the new \EditAlg\ class within the \edit\ package. This change introduces the \EditAttempt\ sealed trait to explicitly track the outcome of three distinct operations: version bumping (\UpdateEdit\), Scalafix migrations (\ScalafixEdit\), and post-update hooks (\HookEdit\). For users, this means the update process now clearly separates and reports on migration results and hook executions, allowing for better visibility into whether Scalafix rules were applied or failed, and ensuring that post-update hooks are executed as part of the standard update flow.

modules/core/src/main/scala/org/scalasteward/core/edit · high confidence

Refactored update filtering and pruning into dedicated algorithms

The update processing logic has been reorganized into three new components: FilterAlg, PruningAlg, and UpdateAlg. FilterAlg now centralizes the decision to ignore or accept an update, handling configuration-based rejections (such as pinned versions, ignored configurations, and cooldowns), Scala LTS/Next version constraints, and version ordering checks. PruningAlg manages the state of dependencies (up-to-date, outdated, closed PR, etc.) and determines which updates need attention based on pull request history and frequency settings. UpdateAlg orchestrates the discovery of newer versions and artifact migrations, delegating filtering to FilterAlg. This refactoring separates concerns, making the update pipeline more modular and easier to maintain.

modules/core/src/main/scala/org/scalasteward/core/update · high confidence

Refactored version update logic into modular data structures

The internal logic for detecting and applying version updates has been restructured into new, dedicated data classes (\ModulePosition\, \VersionPosition\, and \Substring\). This change introduces specific support for identifying versions defined in Scala \val\ declarations, alongside existing support for SBT, Mill, and Maven dependency definitions. It also adds robust handling for file replacements, including logic to unwrap version strings from variables and prevent errors when applying duplicate replacements.

modules/core/src/main/scala/org/scalasteward/core/edit/update/data · high confidence

Reworked core data model for dependencies and updates

The core data structures in the \data\ package have been restructured to better represent dependency information and update logic. New types such as \ArtifactId\, \GroupId\, \Dependency\, \CrossDependency\, and \Resolver\ (supporting Maven and Ivy repositories with credentials) provide a more granular and robust foundation for dependency resolution. The \Update\ hierarchy has been refined with \ArtifactForUpdate\, \ArtifactUpdateCandidates\, and specific update types like \ForArtifactId\ and \ForGroupId\ to distinguish between candidate versions and final update decisions. Additionally, \SemVer\ parsing and change detection have been implemented using \cats-parse\, and \Version\ selection logic now more accurately handles pre-releases, snapshots, and hash-based versions, improving the reliability of update suggestions.

modules/core/src/main/scala/org/scalasteward/core/data · high confidence

SbtAlg implementation with dynamic scalafix versioning and sbt 2 support

The SBT build-tool integration now dynamically retrieves the latest sbt-scalafix plugin version from the configured repository cache instead of using a hardcoded version, ensuring compatibility with newer Scalafix releases. The implementation adds explicit support for sbt 2.x by selecting version-specific steward plugins based on the detected sbt version (e.g., 2\_0\_0, 2\_1\0) and configures the sbt process to run in server mode with colors and supershell disabled for stable output. Additionally, it introduces support for running Scalafix migrations on build files (project/\.sbt and project/\*.scala) alongside source files, and temporarily injects the steward plugin into nested project directories to handle multi-level meta-builds.

modules/core/src/main/scala/org/scalasteward/core/buildtool/sbt · high confidence

Scalafix migration execution now supports post-update timing and build-file targets

The Scalafix migration system has been refactored to allow migrations to be configured with an execution order (pre-update or post-update) and a target scope (sources or build files). Users can now define migrations that run after a version bump or apply to build files, in addition to the previous default behavior of running before the update on source files. The migration configuration model now includes explicit fields for these options, and the finder logic partitions migrations accordingly to control when they are applied relative to the dependency update.

modules/core/src/main/scala/org/scalasteward/core/edit/scalafix · high confidence

Unified build-tool abstraction with multi-tool support

The build-tool detection and dependency extraction logic has been refactored to support multiple build tools per project root. A new \BuildRoot\ case class identifies a repository and relative path, while \BuildToolAlg\ provides a unified interface for tools like SBT, Maven, Gradle, Mill, Scala CLI, and Giter8. The \BuildToolDispatcher\ now iterates over all configured build roots, detects which tools are present in each, and aggregates dependencies from all of them, ensuring that projects using multiple build systems are handled correctly.

modules/core/src/main/scala/org/scalasteward/core/buildtool · high confidence

Unified forge abstraction with Gitea support and configurable PR limits

The core forge integration has been refactored to use a unified \ForgeApiAlg\ and \ForgeAuthAlg\ interface, replacing the previous VCS-specific implementations. This change introduces support for Gitea as a new forge type, alongside existing support for GitHub, GitLab, Bitbucket, Bitbucket Server, and Azure Repos. The new architecture allows forge-specific behaviors to be configured via \ForgeType\, including per-forge maximum pull request description lengths (e.g., 4000 for Azure Repos, 32768 for Bitbucket Server, 65536 for GitHub/GitLab) and URL patterns for diffs and file views. Authentication is now handled centrally, with \BasicAuthAlg\ supporting GitHub, Gitea, and Azure Repos, while specific forges like Bitbucket and GitLab use their own auth implementations. The \ForgeRepo\ class encapsulates forge-specific URL construction for diffs and file links, and \ForgeSelection\ routes API calls to the correct implementation based on the configured forge type.

modules/core/src/main/scala/org/scalasteward/core/forge · high confidence

Updated default artifact migrations, Scalafix rules, and Scala Steward configuration

Scala Steward now loads updated default configuration files on startup to improve dependency update reliability. The \artifact-migrations.conf\ and \artifact-migrations.v2.conf\ files have been refreshed with new and corrected mappings for groupId changes (e.g., sbt plugins moving to \com.github.sbt\, Monocle to \dev.optics\, log4cats to \org.typelevel\) and artifact renames. The \scalafix-migrations.conf\ has been updated with new rewrite rules for libraries such as Cats 2.2.0, Cats Effect 3.0.0, http4s 0.22.0, and sbt 1.5.0, ensuring code is automatically adjusted during upgrades. Additionally, \default.scala-steward.conf\ now includes post-update hooks for \organize-imports\, \sbt-java-formatter\, and \sbt-header\, and the \updates.ignore\ list has been reorganized to block specific broken or unannounced versions of Scala, Scala.js, and sbt.

modules/core/src/main/resources · high confidence

Test coverage

Added JMH benchmarks for UpdatesConfig, Version parsing, and VersionPositionScanner; Added MUnit-based tests for SBT build tool integration; Added test coverage for GitHub Forge integration; Added test fixtures for GitHub API responses and job summaries; Added test infrastructure and validation for built-in configuration files; Added tests for Azure Repos and Bitbucket Server forge integrations; Added tests for Bitbucket Forge integration; Added tests for BuildToolDispatcher and Giter8Alg; Added tests for CLI argument parsing, repos file loading, and run result reporting; Added tests for GitLab API interactions and merge request payload serialization; Added tests for Gradle Version Catalog parsing; Added tests for HTTP client configuration behavior; Added tests for JsonKeyValueStore operations and caching; Added tests for Mill build-tool integration; Added tests for ModulePositionScanner and VersionPositionScanner; Added tests for RepoCacheAlg and RefreshErrorAlg; Added tests for Scala CLI build tool integration; Added tests for Scalafix migration configuration and loading; Added tests for artifact migration loading and application; Added tests for core IO operations and process execution; Added tests for data model grouping, versioning, and serialization; Added tests for forge data models and PR body generation; Added tests for post-update hook execution; Added tests for repoconfig module; Added tests for scalafmt configuration parsing; Added tests for the EditAlg and Rewrite logic; Added tests for the new Forge abstraction layer; Added tests for update filtering, pruning, and display logic; Added unit tests for Coursier integration and metadata handling; Added unit tests for Git commit message generation and file-based Git operations; Added unit tests for Maven build tool integration; Added unit tests for core utility functions; Added unit tests for the Gitea Forge API integration; New mock infrastructure for tests; Removed tests for DependencyUpdate parsing.

Dependencies

Major dependency and build toolchain upgrade

The project has significantly upgraded its build infrastructure and runtime dependencies. The build tool was updated from sbt 1.2.1 to 1.13.0, and the plugin suite was modernized, introducing sbt-assembly, sbt-buildinfo, sbt-git, sbt-explicit-dependencies, sbt-doctest, sbt-native-packager, sbt-jmh, sbt-mdoc, and sbt-typelevel-mergify while removing older plugins like sbt-travisci and tut-plugin. Runtime libraries were bumped to their latest versions, including Cats Effect 3.7.1, Cats Core 2.13.0, http4s 1.0.0-M48, fs2 3.14.0, circe 0.14.16, and MUnit 1.3.6, alongside the addition of new dependencies such as commons-lang3, tomlj, and the JJWT 0.13.0 suite. Additionally, eviction errors are now logged as info rather than errors.

project · high confidence

Scala Steward major release: Scala 3 support, sbt-typelevel build, and Temurin 21 CI

This update delivers a major version of Scala Steward, introducing support for Scala 3 (specifically 3.9.0) alongside Scala 2.13.18. The build system has been completely refactored to use sbt-typelevel, replacing the previous custom cross-project setup with a modern, standardized structure. Consequently, the project group ID has changed from \eu.timepit\ to \org.scala-steward\, and the GitHub organization is now \scala-steward-org\. The CI pipeline now uses Temurin JDKs (versions 17, 21, and 25) and integrates Mergify for automatic PR labeling and merging. The Docker image base has been updated to Eclipse Temurin 17 Alpine, and several dependencies have been refreshed or replaced, including the switch from \http4s-async-http-client\ to \http4s-jdk-http-client\ and the adoption of \cats-parse\ for version parsing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 40 → 57 (+17.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 97 (-3.1)
  • Architecture 91 (new)
  • Maturity 49 → 53 (+4.8)
  • Readiness 30 → 49 (+19.3)
  • Security 35 → 62 (+26.4)

Resolved (23)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No artifact signing
  • No automated tests
  • …and 3 more

New (37)

  • Context.step0 (cognitive 28) (modules/core/src/main/scala/org/scalasteward/core/application/Context.scala)
  • Context.step1 (cognitive 45) (modules/core/src/main/scala/org/scalasteward/core/application/Context.scala)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (5 lines × 3) (modules/core/src/main/scala/org/scalasteward/core/edit/update/ModulePositionScanner.scala)
  • EditAlg.applyUpdate (cognitive 34) (modules/core/src/main/scala/org/scalasteward/core/edit/EditAlg.scala)
  • FileGitAlg.syncFork (cognitive 21) (modules/core/src/main/scala/org/scalasteward/core/git/FileGitAlg.scala)
  • Further sole-owners (lower concentration)
  • GitLabApiAlg.createPullRequest (cognitive 26) (modules/core/src/main/scala/org/scalasteward/core/forge/gitlab/GitLabApiAlg.scala)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 17 more

Changes since last survey

  • 104 commits — 103 feature/other, 1 fixes

By area

  • (repo) — 50 commits
  • modules/core — 24 commits
  • project/Dependencies.scala — 18 commits
  • project/plugins.sbt — 7 commits
  • (root) — 4 commits
  • project/build.properties — 1 commit

Notable commits

  • fix: revert some version updates in tests
  • change: Add artifact migration for launchdarkly-client
  • change: Add artifact migrations for the Prometheus simpleclient modules
  • change: Add artifact migrations for the openhtmltopdf move to io.github.openhtmltopdf
  • change: Add the labels a repository names, whatever the instance does
  • change: Block upgrades for Scala 3.10; add directives-parser rule
  • change: Do not update from Scala 2.13 to Scala 3
  • change: Fixup the patch
  • change: Handle Scala 3.9.x as LTS
  • change: Merge PR #3938: Update doctest-runtime and sbt-doctest to 0.13.2
  • change: Merge PR #3942: Update sbt-scalafmt to 2.6.2
  • change: Merge branch 'scala-steward-org:main' into feature/Gitter8
  • change: Merge pull request #3824 from monksy/feature/Gitter8
  • change: Merge pull request #3954 from scala-steward/update/mill-runner-launcher_3-1.1.8
  • change: Merge pull request #3955 from scala-steward/update/bcprov-jdk15to18-1.85.2
  • change: Merge pull request #3958 from scala-steward/update/munit-1.3.5
  • change: Merge pull request #3959 from scala-steward/update/logback-classic-1.6.2
  • change: Merge pull request #3960 from scala-steward-org/combine/sbt-scalafmt-doctest-2.6.2-0.13.2
  • change: Merge pull request #3961 from scala-steward/update/logback-classic-1.6.3
  • change: Merge pull request #3962 from xuwei-k/update-scalafmt-version
  • …and 84 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

scala-steward-org/scala-steward was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6bad96dbcdf22d1c2cd2c5e9b97959cc001d3edd — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.