Skip to content
CAI
Software that uses CAICheck a score

xerial/sbt-sonatype

61.8

Adequate · 20 September 2026

1.5k

lines of production code

Scala

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is an sbt plugin designed to automate the publishing of Scala artifacts to Sonatype repositories. It manages the workflow for creating and uploading staging bundles, supporting both legacy Nexus OSS hosts and the modern Sonatype Central API. The plugin handles resolver configuration, JSON parsing for staging profiles, and error reporting to streamline the release process for sbt-based projects.

Features

Repository initialization and tooling configuration

The repository has been initialized with standard project configuration files, including an Apache 2.0 license, a comprehensive README documenting the sbt-sonatype plugin usage and deprecation notice, and release notes. Automated maintenance is configured via .scala-steward.conf for dependency updates and .mergify.yml for automatic merging of Scala Steward pull requests. Code formatting is standardized using scalafmt 3.8.4, and the sbt launcher script has been updated to version 1.10.2.

(repo-wide) · high confidence

Support for Sonatype Central API

The plugin now supports publishing to Sonatype Central (central.sonatype.com) in addition to the legacy Nexus OSS hosts. This introduces new commands (sonatypeCentralRelease, sonatypeCentralUpload) and settings (sonatypeCentralDeploymentName, sonatypePublishToBundle) to handle bundle uploads and deployments to the new API, while maintaining backward compatibility with existing staging repository workflows.

src/main · high confidence

Behavioural changes

Migration to sbt 1.10.7 and modernized build infrastructure

The build system has been upgraded from sbt 0.13.1 to sbt 1.10.7, requiring users to update their sbt installation to support this version. The legacy \project/Build.scala\ file has been removed in favor of the modern sbt 1.x auto-plugin structure defined in \project/plugins.sbt\. Several build plugins have been updated or replaced: \sbt-sonatype\ is now configurable via the \SONATYPE\_VERSION\ environment variable (defaulting to 3.12.2), \sbt-pgp\ is set to 2.3.0, \sbt-scalafmt\ to 2.5.2, \sbt-dynver\ to 5.1.0, and \sbt-buildinfo\ to 0.13.1. The \sbt-release\ plugin has been removed, and the \scripted-plugin\ is now explicitly added as a library dependency. Additionally, snapshot repository access has been enabled via a resolver configuration.

project · high confidence

Test coverage

Added scripted test for Sonatype Central resolver configuration; Added scripted tests for sbt-sonatype operations plugin; Added tests for Sonatype client JSON parsing and missing profile error handling; Simplified sbt-sonatype example test suite.

Dependencies

Update build dependencies and add sbt 2.0 support

The build configuration has been updated to support sbt 2.0 (specifically 2.0.0-M4) for Scala 3 builds, while maintaining sbt 1.x for Scala 2.12. Dependencies have been upgraded to Airframe 24.12.2 and Airspec 24.12.2, with the Sonatype Central client library switched to use upickle instead of zio-json. The example test project has also been modernized to explicitly define publishing metadata rather than relying on imported settings.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 62.

Lenses

  • Code Health 100
  • Architecture 100
  • Maturity 50
  • Readiness 64
  • Security 65

Changes since last survey

  • 300 commits — 287 feature/other, 13 fixes

By area

  • (root) — 206 commits
  • project/plugins.sbt — 43 commits
  • src/main — 23 commits
  • project/build.properties — 10 commits
  • .github/workflows — 8 commits
  • (repo) — 4 commits
  • .github/release-drafter.yml — 2 commits
  • src/sbt-test — 2 commits
  • .github/ISSUE_TEMPLATE — 1 commit
  • .github/dependabot.yml — 1 commit

Notable commits

  • fix: Fix build
  • fix: Fix build.sbt (#445)
  • fix: Fix computation of sonatypeDefaultResolver for Sonatype Central (#501)
  • fix: Fix release notes
  • fix: Fixes #214: Support s01.oss.sonatype.org value in sonatypePublishToBundle (#220)
  • fix: Fixes #223: Handle SSL Timeout during bundleUplaod (#329)
  • fix: Fixes #303: Retry on 502 during bundle upload (#326)
  • fix: Fixes #309: Handle 404 upon repository drop (#327)
  • fix: Revert "#276: Always use ThisBuild / sonatypeCredentialHost settings (#285)" (#294)
  • fix: fix #507: Add tests on JDK 8, 11, and 17 to fix missing method (java.nio.file.Path.of) error (#508)
  • fix: fix scripted build.sbt format (#524)
  • fix: fix: Exclude logback-core for JDK8 compatibility (#531)
  • fix: fixes #530: Disable logback-core in Java 8 and show warning messages (#533)
  • change: #276: Always use ThisBuild / sonatypeCredentialHost settings (#285)
  • change: 3.9.11 release notes
  • change: 3.9.12 release note
  • change: 3.9.14 release notes
  • change: 3.9.14 release notes
  • change: 3.9.5 release notes
  • change: 3.9.6 release notes
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

xerial/sbt-sonatype was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit af00344d21f9af28d03a833b64b0f49a057b0565 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.