{"id":16573874,"url":"https://github.com/leobenkel/soteria","last_synced_at":"2025-07-22T08:31:53.530Z","repository":{"id":40304587,"uuid":"189290976","full_name":"leobenkel/Soteria","owner":"leobenkel","description":"Plugin to block compilation when unapproved dependencies are used or code styling does not comply.","archived":false,"fork":false,"pushed_at":"2024-08-19T16:28:48.000Z","size":1989,"stargazers_count":47,"open_issues_count":19,"forks_count":10,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-04-21T15:40:07.261Z","etag":null,"topics":["sbt","sbt-plugin","scala","security","security-automation","security-tools","security-vulnerability"],"latest_commit_sha":null,"homepage":"https://github.com/leobenkel/Soteria","language":"Scala","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/leobenkel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"github":"leobenkel","patreon":"leobenkel","open_collective":null,"ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":null,"issuehunt":null,"otechie":null,"custom":null}},"created_at":"2019-05-29T20:08:42.000Z","updated_at":"2023-10-23T11:46:22.000Z","dependencies_parsed_at":"2023-02-19T10:16:05.708Z","dependency_job_id":"58522cc1-785e-40ff-a97a-183153f1eb22","html_url":"https://github.com/leobenkel/Soteria","commit_stats":null,"previous_names":[],"tags_count":29,"template":false,"template_full_name":null,"purl":"pkg:github/leobenkel/Soteria","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/leobenkel%2FSoteria","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/leobenkel%2FSoteria/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/leobenkel%2FSoteria/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/leobenkel%2FSoteria/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/leobenkel","download_url":"https://codeload.github.com/leobenkel/Soteria/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/leobenkel%2FSoteria/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":266456245,"owners_count":23931383,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-07-22T02:00:09.085Z","response_time":66,"last_error":null,"robots_txt_status":null,"robots_txt_updated_at":null,"robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["sbt","sbt-plugin","scala","security","security-automation","security-tools","security-vulnerability"],"created_at":"2024-10-11T21:43:17.052Z","updated_at":"2025-07-22T08:31:53.500Z","avatar_url":"https://github.com/leobenkel.png","language":"Scala","funding_links":["https://github.com/sponsors/leobenkel","https://patreon.com/leobenkel","https://www.patreon.com/leobenkel"],"categories":[],"sub_categories":[],"readme":"![Soteria_animated](https://raw.githubusercontent.com/leobenkel/Soteria/main/assets/Soteria_animated.gif)\n\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![release-badge][]][release]\n[![maven-central-badge][]][maven-central-link]\n[![BCH compliance](https://bettercodehub.com/edge/badge/leobenkel/Soteria?branch=main)](https://bettercodehub.com/)\n[![Coverage Status](https://coveralls.io/repos/github/leobenkel/Soteria/badge.svg?branch=main)](https://coveralls.io/github/leobenkel/Soteria?branch=main)\n[![Mutation testing badge](https://badge.stryker-mutator.io/github.com/leobenkel/Soteria/main)](https://stryker-mutator.github.io)\n\n\n[release]:              https://github.com/leobenkel/soteria/releases\n[release-badge]:        https://img.shields.io/github/tag/leobenkel/soteria.svg?label=version\u0026color=blue\n[maven-search]:         https://search.maven.org/search?q=g:com.leobenkel%20a:soteria\n[leobenkel-github-badge]:     https://img.shields.io/badge/-Github-yellowgreen.svg?style=social\u0026logo=GitHub\u0026logoColor=black\n[leobenkel-github-link]:      https://github.com/leobenkel\n[leobenkel-linkedin-badge]:     https://img.shields.io/badge/-Linkedin-yellowgreen.svg?style=social\u0026logo=LinkedIn\u0026logoColor=black\n[leobenkel-linkedin-link]:      https://linkedin.com/in/leobenkel\n[leobenkel-personal-badge]:     https://img.shields.io/badge/-Website-yellowgreen.svg?style=social\u0026logo=data:image/svg+xml;base64,PHN2ZyBoZWlnaHQ9JzMwMHB4JyB3aWR0aD0nMzAwcHgnICBmaWxsPSIjMDAwMDAwIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2ZXJzaW9uPSIxLjEiIHg9IjBweCIgeT0iMHB4IiB2aWV3Qm94PSIwIDAgNjQgNjQiIGVuYWJsZS1iYWNrZ3JvdW5kPSJuZXcgMCAwIDY0IDY0IiB4bWw6c3BhY2U9InByZXNlcnZlIj48Zz48Zz48cGF0aCBkPSJNNDEuNiwyNy4yYy04LjMsMC0xNSw2LjctMTUsMTVzNi43LDE1LDE1LDE1YzguMywwLDE1LTYuNywxNS0xNVM0OS45LDI3LjIsNDEuNiwyNy4yeiBNNTEuNSwzNmgtMy4zICAgIGMtMC42LTEuNy0xLjQtMy4zLTIuNC00LjZDNDguMiwzMi4yLDUwLjIsMzMuOSw1MS41LDM2eiBNNDEuNiwzMS41YzEuMywxLjIsMi4zLDIuNywzLDQuNGgtNkMzOS4zLDM0LjIsNDAuNCwzMi43LDQxLjYsMzEuNXogICAgIE0zNy40LDMxLjNjLTEsMS40LTEuOCwyLjktMi40LDQuNmgtMy4zQzMzLjEsMzMuOSwzNS4xLDMyLjIsMzcuNCwzMS4zeiBNMzAuMyw0NWMtMC4yLTAuOS0wLjQtMS44LTAuNC0yLjhjMC0xLDAuMS0yLDAuNC0yLjkgICAgaDMuOWMtMC4xLDEtMC4yLDEuOS0wLjIsMi45YzAsMC45LDAuMSwxLjksMC4yLDIuOEgzMC4zeiBNMzEuNyw0OC4zSDM1YzAuNiwxLjcsMS40LDMuNCwyLjQsNC44QzM1LDUyLjIsMzMsNTAuNSwzMS43LDQ4LjN6ICAgICBNNDEuNiw1Mi45Yy0xLjMtMS4yLTIuMy0yLjgtMy4xLTQuNWg2LjFDNDQsNTAuMSw0Mi45LDUxLjcsNDEuNiw1Mi45eiBNMzcuNiw0NWMtMC4yLTAuOS0wLjItMS44LTAuMi0yLjhjMC0xLDAuMS0yLDAuMy0yLjloOCAgICBjMC4yLDAuOSwwLjMsMS45LDAuMywyLjljMCwxLTAuMSwxLjktMC4yLDIuOEgzNy42eiBNNDUuOCw1My4xYzEtMS40LDEuOC0zLDIuNC00LjhoMy4zQzUwLjIsNTAuNSw0OC4yLDUyLjIsNDUuOCw1My4xeiBNNDksNDUgICAgYzAuMS0wLjksMC4yLTEuOCwwLjItMi44YzAtMS0wLjEtMi0wLjItMi45aDMuOWMwLjIsMC45LDAuNCwxLjksMC40LDIuOWMwLDEtMC4xLDEuOS0wLjQsMi44SDQ5eiI+PC9wYXRoPjxwYXRoIGQ9Ik0zNCwyNS45Yy0wLjktMC43LTEuOC0xLjMtMi45LTEuOGMyLTIuMSwzLjItNC45LDMuMi03LjljMC02LjMtNS4xLTExLjQtMTEuNC0xMS40UzExLjYsOS45LDExLjYsMTYuMiAgICBjMCwzLjEsMS4yLDUuOSwzLjIsNy45Yy00LjEsMi02LjgsNS40LTcuMSw5LjRsLTAuMywzLjhjMCwyLDcsMy42LDE1LjYsMy42YzAuMiwwLDAuNSwwLDAuNywwQzI0LjIsMzQuMywyOC4yLDI4LjYsMzQsMjUuOXogICAgIE0yMyw4LjhjNC4xLDAsNy40LDMuMyw3LjQsNy40cy0zLjMsNy40LTcuNCw3LjRzLTcuNC0zLjMtNy40LTcuNFMxOC45LDguOCwyMyw4Ljh6Ij48L3BhdGg+PC9nPjwvZz48L3N2Zz4=\u0026logoColor=black\n[leobenkel-personal-link]:      https://leobenkel.com\n[leobenkel-patreon-link]:            https://www.patreon.com/leobenkel\n[leobenkel-patreon-badge]: https://img.shields.io/badge/-Patreon-yellowgreen.svg?style=social\u0026logo=Patreon\u0026logoColor=black\n[maven-central-link]:                             https://maven-badges.herokuapp.com/maven-central/com.leobenkel/soteria\n[maven-central-badge]:          https://maven-badges.herokuapp.com/maven-central/com.leobenkel/soteria/badge.svg\n\n\n# Soteria\n\nInformation about [who was Soteria](https://www.wikiwand.com/en/Soteria_(mythology)).\n\nIf you have any question [submit an issue](https://github.com/leobenkel/soteria/issues/new).\n\n## Table of Contents\n\n  * [Presentations](#presentations)\n  * [Setup steps](#setup-steps)\n  * [soteria.json](#soteriajson)\n     * [Root level](#root-level)\n     * [Modules](#modules)\n        * [How to make sure library A is always version x.y and Provided ?](#how-to-make-sure-library-a-is-always-version-xy-and-provided-)\n        * [How to remove a dependency D completely from a library A ?](#how-to-remove-a-dependency-d-completely-from-a-library-a-)\n        * [Is there an easy way to build the dependenciesToRemove tree ?](#is-there-an-easy-way-to-build-the-dependenciestoremove-tree-)\n  * [Features](#features)\n     * [Scala Style](#scala-style)\n     * [Coveralls](#coveralls)\n     * [For fat-jar assembly build](#for-fat-jar-assembly-build)\n     * [!!!Dangerous!!! Allow compilation even with vulnerability](#dangerous-allow-compilation-even-with-vulnerability)\n        * [Vulnerability by-pass](#vulnerability-by-pass)\n        * [Compilation warning by pass](#compilation-warning-by-pass)\n     * [Debug](#debug)\n  * [Publishing](#publishing)\n  * [Authors](#authors)\n     * [Leo Benkel](#leo-benkel)\n\nCreated by [gh-md-toc](https://github.com/ekalinin/github-markdown-toc)\n\n## Presentations\n\nFeel free to watch the talk given at [Scala in the city (2020-05-28)](https://www.youtube.com/watch?v=NYSVF7uCJOA) with [the slide deck](https://docs.google.com/presentation/d/1aS1KCKItcaHYRJLuK_9eZ9ZN2oU_6FsOWQJxymUZm_0).\n\n## Setup steps\n\n1. Make sure you are using `SBT 1.2.x`.\n1. Add to `./project/soteria.sbt` in your project:\n    ```\n    addSbtPlugin(\"com.leobenkel\" % \"soteria\" % soteriaVersion)\n    ```\n    The latest release is [![release-badge][]][release] [![maven-central-badge][]][maven-central-link]\n1. Make sure to have a config file. Take a look at [soteria.json](https://github.com/leobenkel/soteria/blob/main/soteria.json) for examples\n1. If you need a **fat-jar**:\n     1. Add to your `build.sbt` the following lines:\n         ```\n         assemblyOption in assembly := soteriaAssemblySettings.value\n         enablePlugins(DockerPlugin)\n         ```\n1. Clean up your `build.sbt` by removing all pre-set settings:\n     1. `dependencyOverrides`\n     1. `scalacOptions`\n     1. All settings related to `sbt-assembly` and `sbt-docker`\n     1. All test options `in Test`:\n        1. `javaOptions in Test`\n        1. `testOptions in Test`\n        1. `parallelExecution in Test`\n        1. `fork in Test`\n1. Remove all plugins that are already included for you:\n     1. `sbt-scoverage`\n     1. `sbt-assembly`\n     1. `sbt-docker`\n     1. `sbt-dependency-graph`\n     1. `sbt-scalafix`\n     1. `sbt-scalafmt`\n     1. `scalastyle-sbt-plugin`\n1. You can run your project the same as before. There can be compilation issues due to vulnerable dependencies.\n1. *Dangerous!* If you are not able to fix compiler issues, add: `soteriaSoftOnCompilerWarning := true`\n1. *Dangerous!* If you are not able to fix dependencies issues, add: `soteriaSoft := true`\n1. You can now then fix scala style issues:\n    1. Run `sbt soteriaCheckScalaStyle`\n    1. Run `sbt soteriaCheckScalaFix`\n    1. Run `sbt soteriaCheckScalaFmt`\n        1. If you are ready to rewrite the broken files:\n            1. Create a clean branch\n            1. Run `sbt soteriaCheckScalaFmtRun`\n\n## soteria.json\n\n### Root level\n\nTo override where the config file is read from, update the setting `soteriaConfPath` in your `build.sbt`. This setting can be a URL starting by `http://` or `https://` or a local file path. \nBy default it will search for `./soteria.json`.\n\nRoot level:\n\n* `dockerImage`: To set in which image the fat-jar will be built.\n* `sbtVersion`: SBTVersion to enforce. If a project is trying to compile with a different version, it will break.\n* `scalaVersions`: Is an array of authorized scala Version. This is an array and not a value to allow Spark/Play project on different version.\n* `scalaCFlags`: The list of compile flag to add to the build process. If `soteriaSoftOnCompilerWarning` is **not** true, then `-Xfatal-warnings` will be added as well to trigger a compilation failure.\n* `modules`: This is where the bulk of the settings are living.\n  * The structure is `groupId|com.organization` -\u003e `artifactName` -\u003e description of the constraints\n  \n### Modules\n\nThe modules are the constraint enforced by the plugin related to each dependencies.\n\nThe path to each module is `groupId|com.organization` -\u003e `artifactName` -\u003e description of the constraints.\n\nA module can accept those keys:\n* `version`: Either `None` or a version number. If the library is added with a different version number, the compilation will fail\n* `exactName`: Default is True if absent. If false, the `artifactName` can just be a start. It is used for instance where you want to enforce a version for a library and related ones. `circe` or `spark-` can be good examples.\n* `excludeName`: Default empty. It is used to exclude libraries that would be catch by the `name` + `exactName`:false. It is used for instance in Play project where you would enforce something for all libraries starting by `play-` except a few that are behind on version numbers.\n* `needDoublePercent`: By default is false. If true, the conversion to `sbt.ModuleID` will be with `%%` instead of `%`. The same way it would be in the `build.sbt`.\n* `shouldDownload`: Is true by default and is only used for `sbt soteriaGetAllDependencies`.\n* `overrideIsEnough`: Default is true. This is related to `dependenciesToRemove`. \n  * If `overrideIsEnough` is true, the library will be added to `dependencyOverrides`. \n  * If `overrideIsEnough` is false, the library will be converted to an exclusion rule.\n* `forbidden`: Default is null. If this is set, and the library is added, the message will be displayed as a build failure. For instance you can use it to forbid one MySQL library and advise to use a different one.\n* `shouldBeProvided`: Default is false. If true, the compilation will fail if the library is not set to `Provided` in `build.sbt`. It is used for Spark.\n* `dependenciesToRemove`: This is a list of `groupID | artifactName` libraries to remove from this library. This is when `overrideIsEnough` come into play.\n* `scalaVersionsFilter`: This field is a list of scala versions, following this format: `[+-][MajorVersion].[MinorVersion]\u003c.[SmallVersion]\u003e`.\n\n#### How to make sure library A is always version x.y and Provided ?\n\n```\n\"modules\": {\n    \"groupID.A\": {\n        \"artifactName-A\": {\n            \"version\": \"x.y\",\n            \"shouldBeProvided\": true\n        }\n    }\n}\n```\n\n#### How to remove a dependency D completely from a library A ?\n\n```\n\"modules\": {\n    \"groupID.D\": {\n        \"artifactName-D\": {\n            \"version\": \"None\",\n            \"overrideIsEnough\": false\n        }\n    },\n    \"groupID.A\": {\n        \"artifactName-A\": {\n            \"dependenciesToRemove\": [ \n                \"groupID.D | artifactName-D\"\n            ],\n            \"version\": \"vA.A\"\n        }\n    }\n}\n```\n\n\nThe `dependenciesToRemove` in A, will search for D. \nSince `overrideIsEnough` is false in D, the plugin will remove D from A using an ExclusionRule.\nThen, the plugin gather all the library which have been removed, and add them back with the appropriate version.\nIn this case the version of D is `None`, so it will **not** be added back. \n\n#### Is there an easy way to build the `dependenciesToRemove` tree ?\n\nYes there is !\n\nFirst assemble your json:\n \n ```\n\"modules\": {\n    \"groupID.D\": {\n        \"artifactName-D\": {\n            \"version\": \"None\",\n            \"overrideIsEnough\": false\n        }\n    },\n    \"groupID.A\": {\n        \"artifactName-A\": {\n            \"version\": \"vA.A\"\n        }\n    },\n    \"groupID.B\": {\n        \"artifactName-B\": {\n            \"version\": \"vB.B\"\n        }\n    }\n}\n```\n\nThen run `sbt soteriaDebugAllModules`.\n\nThis will:\n \n1. Remove all the dependencies from your `build.sbt`\n1. List all the known libraries from your config file\n1. Add one library at a time, compile and get the fetched dependencies\n1. Compare the fetch dependencies with the known dependencies from your config file\n1. When all the libraries have been reviewed, the plugin will display a new json payload that you can just copy paste with all the `dependenciesToRemove` set to the knowledge you have in your json.\n\n## Features\n\n### Scala Style\n\nThe sbt plugin includes [ScalaFix](https://github.com/scalacenter/scalafix), [ScalaStyle](http://www.scalastyle.org/) and [ScalaFmt](https://scalameta.org/scalafmt/).\n\n\n1. Check that you have [.scalafix.conf](https://github.com/leobenkel/soteria/blob/main/.scalafix.conf), [.scalafmt.conf](https://github.com/leobenkel/soteria/blob/main/.scalafmt.conf) and [scalastyle-config.xml](https://github.com/leobenkel/soteria/blob/main/scalastyle-config.xml) in your project\n   * Feel free to copy the one present in this repo to follow the same style guides\n2. Run `sbt soteriaCheckScalaCheckAll` to check that everything is correct.\n    * You can run each system independently with:\n        * `sbt soteriaCheckScalaStyle`\n        * `sbt soteriaCheckScalaFix`\n        * `sbt soteriaCheckScalaFmt`\n3. To apply the fix for [ScalaFmt](https://scalameta.org/scalafmt/), you can run `sbt soteriaCheckScalaFmtRun`\n\n### Coveralls\n\n#### Locally\n\nYou can run \n```\nsbt soteriaRunTestCoverage\n```\nto generate local reporting.\n\nJust open:\n```\n./target/scala-2.xx/sbt-1.0/scoverage-report/index.html\n```\n\n#### Submit to coveralls\n\nTo submit to coveralls\n```\nsbt soteriaRunSubmitCoverage\n```\n\nThis will generate the reports and submit it to coveralls using your COVERALLS token, set in the env var: `COVERALLS_REPO_TOKEN`. \n\n### For fat-jar assembly build\n\nYou need to add\n```\nassemblyOption in assembly := soteriaAssemblySettings.value\nenablePlugins(DockerPlugin)\n```\n\nto your `build.sbt` file.\n\nYou can now call `sbt docker` to create the fat-jar. It will be located at `./target/docker/0/*.jar`.\n\nTo change in which docker image the build is ran, you can change `dockerImage` in [soteria.json](https://github.com/leobenkel/soteria/blob/main/soteria.json).\n\n### !!!Dangerous!!! Allow compilation even with vulnerability\n\n#### Vulnerability by-pass\n\nBy default, you won't be able to compile if you have errors in your build.\n\nIf you need time to fix several issues, you can add:\n\n```\nsoteriaSoft := true\n```\n\nto your `build.sbt` file while you are fixing them.\n\n#### Compilation warning by pass\n\nIf you also want to allow compiler warning, you will need to add:\n\n```\nsoteriaSoftOnCompilerWarning := true\n```\n\nto your `build.sbt` file while you are fixing them\n\n### Debug\n\nTo print more or less logs for this plugin, you can set `soteriaLogLevel`.\n\nFor `Debug`:\n\n```\nsoteriaLogLevel := Level.Debug\n```\n\nFor `Error` only:\n\n```\nsoteriaLogLevel := Level.Error\n```\n\n## Publishing\n\n* Update version number in `VERSION` file.\n* Deploy the updated plugin locally: `make publishLocal`\n* Update version number in `./project/soteria.sbt`.\n* Run the plugin on itself with `make publishLocal`\n* Publish: `make publish`\n\n## Authors\n\n### Leo Benkel\n\n* [![leobenkel-github-badge][]][leobenkel-github-link]\n* [![leobenkel-linkedin-badge][]][leobenkel-linkedin-link]\n* [![leobenkel-personal-badge][]][leobenkel-personal-link]\n* [![leobenkel-patreon-badge][]][leobenkel-patreon-link]\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fleobenkel%2Fsoteria","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fleobenkel%2Fsoteria","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fleobenkel%2Fsoteria/lists"}