Skip to content

Guardrails / scala

Scala version is declared ​

scala/version-declared@v1

The build declares the Scala version it compiles against, and that version is no older than the configured floor.

Idscala/version-declared
Versionv1
Categoryscala
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsscala

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
scalaThe sbt build in the project directory: the Scala and sbt versions it pins, every subproject the reader saw, the library dependencies each build file names with their configurations, and the plugins the build itself runs. build.sbt is Scala rather than a declaration, so what it declares indirectly is not seen and scanned says so.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "scala/version-declared@v1",
              "severity": "warning",
              "with": {
                  "projectDir": ".",
                  "minVersion": "2.13"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
minVersionOldest Scala version accepted. A declared version below this is a violation.2.13GUARDRAIL_INPUT_MINVERSION

How to fix ​

Declare the compiler version once in build.sbt, so every subproject inherits it:

scala
ThisBuild / scalaVersion := "3.4.1"

Without it, sbt compiles against the Scala version its own launcher was built with. The compiler that produced the artifact then depends on the machine that ran the build, not on the checkout, and it changes whenever the launcher does.

More in scala ​

  • scala/dependencies-pinned. Every library dependency found in the build names a literal revision. build.sbt is Scala code read by pattern, so a dependency built by a function, added inside a condition or held in a variable isn't detected, and the list may be incomplete.
  • scala/no-snapshot-dependencies. No library dependency found in the build is a -SNAPSHOT. build.sbt is Scala code read by pattern, so dependencies it declares indirectly aren't detected, and the list may be incomplete.
  • scala/sbt-version-pinned. project/build.properties pins the sbt version the build runs with, instead of leaving it to whichever launcher the machine has.

All 4 scala guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412