Skip to content

chore(deps): bump org.scala-sbt:sbt from 1.12.9 to 2.0.9 - #28

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/sbt/master/org.scala-sbt-sbt-2.0.9
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/sbt/master/org.scala-sbt-sbt-2.0.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps org.scala-sbt:sbt from 1.12.9 to 2.0.9.

Release notes

Sourced from org.scala-sbt:sbt's releases.

2.0.9

🐛 bug fixes

Full Changelog: sbt/sbt@v2.0.8...v2.0.9

2.0.8

🐛 bug fixes

Full Changelog: sbt/sbt@v2.0.7...v2.0.8

2.0.7

⚠️ Remote code execution vulnerability fix

sbt team received a security report GHSA-943m-f264-54p4 from @​stasimus that when the serverConnectionType is set to Tcp, an attacker is able to execute arbitrary code remotely via BSP, similar to a recent bug that was found in JSON-RPC. sbt 1.13.0 and 2.0.7 fix this bug.

Builds with the default serverConnectionType are not affected. In affected builds, we recommend removing the serverConnectionType setting, or upgrading to a patched version or later. In an affected build, the setting might look like this:

Global / serverConnectionType := ConnectionType.Tcp

The remediation was implemented by @​stasimus.

🚀 updates

🐛 bug fixes

... (truncated)

Commits
  • 6165811 Merge pull request #9759 from eed3si9n/bport2/bport
  • 82560d3 [2.0.x] Update sbtn to 2.1.0-M1 (#9755)
  • 56b20c2 [2.0.x] IO 1.13.2
  • cee3208 [2.0.x] fix: Fix sbt runner script not starting on openSUSE (#9753)
  • 1bde2c0 [2.0.x] fix: keep macro subprojects off the pipelined classpath (#9719)
  • 621df16 [2.x] fix: virtualize semanticdbTargetRoot in the compile cache key (#9711)
  • fb1183e [2.0.x] Cache pipelined Java compilation
  • 2500707 [2.0.x] Fix Java output when export pipelining is disabled
  • 3127e8d sbt 2.0.8
  • 039b3db Merge pull request #9673 from eed3si9n/bport2/bport
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.scala-sbt:sbt](https://github.com/sbt/sbt) from 1.12.9 to 2.0.9.
- [Release notes](https://github.com/sbt/sbt/releases)
- [Commits](sbt/sbt@v1.12.9...v2.0.9)

---
updated-dependencies:
- dependency-name: org.scala-sbt:sbt
  dependency-version: 2.0.9
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added auto update Automated changed (created by bot or AI) no RN No release notes required labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from benedeki as a code owner September 21, 2026 21:06
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added no RN No release notes required auto update Automated changed (created by bot or AI) labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: benedeki/PGUtils/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: a4bdd8a1-8cf0-4c2e-8c83-0e4df564a950

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto update Automated changed (created by bot or AI) no RN No release notes required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants