⚠️ Security advisory: sbt server (1.x/2.x) had an RCE vulnerability (GHSA-m2pw-22cj-jq4v). Only builds with a non-default `serverConnectionType` setting of TCP are affected. Upgrade to sbt 1.12.15+/2.0.6+ or alter the setting. Writeup: scala-lang.org/blog/2026/0...
scala-lang.org
Fixing a remote execution vulnerability in sbt