From 6ff2f925f86c07be63fa1cb675db6ea6a2c9d0db Mon Sep 17 00:00:00 2001 From: Nicolas Stucki Date: Thu, 16 Dec 2021 09:51:06 +0100 Subject: [PATCH] Upgrade SBT to 1.5.7 Updates log4j 2 to 2.16.0, which disables JNDI lookup and fixes a denial of service vulnerability (CVE-2021-45046) See https://github.com/sbt/sbt/releases/tag/v1.5.7 --- community-build/src/scala/dotty/communitybuild/projects.scala | 2 +- project/build.properties | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/community-build/src/scala/dotty/communitybuild/projects.scala b/community-build/src/scala/dotty/communitybuild/projects.scala index 0c865afa2a1a..23b37c042388 100644 --- a/community-build/src/scala/dotty/communitybuild/projects.scala +++ b/community-build/src/scala/dotty/communitybuild/projects.scala @@ -140,7 +140,7 @@ final case class SbtCommunityProject( case Some(ivyHome) => List(s"-Dsbt.ivy.home=$ivyHome") case _ => Nil extraSbtArgs ++ sbtProps ++ List( - "-sbt-version", "1.5.6", + "-sbt-version", "1.5.7", "-Dsbt.supershell=false", s"-Ddotty.communitybuild.dir=$communitybuildDir", s"--addPluginSbtFile=$sbtPluginFilePath" diff --git a/project/build.properties b/project/build.properties index bb3a9b7dc6d2..baf5ff3ec78b 100644 --- a/project/build.properties +++ b/project/build.properties @@ -1 +1 @@ -sbt.version=1.5.6 +sbt.version=1.5.7