Inside pluginManagement, how do you configure plugin repositories, and what is the default if you don't?
answer
- repositories {} inside pluginManagement
- gradlePluginPortal() / mavenCentral()
- default = portal only
- declaring own list replaces the default
- searched in declared order
basics
~10 sAdd a repositories {} block inside pluginManagement {} and call helpers like gradlePluginPortal() and mavenCentral(). If you declare none, Gradle defaults to the Gradle Plugin Portal only.
solid answer
~40 sInside `pluginManagement {}` you put a `repositories {}` block listing where plugins are fetched from. Common entries: `gradlePluginPortal()`, `mavenCentral()`, and `maven { url = uri("https://my-corp/repo") }` for an internal repository. Repositories are tried **in declared order**. If you omit the `repositories {}` block entirely, Gradle uses an implicit default of the **Gradle Plugin Portal**. The moment you declare your own `repositories {}`, that implicit default is **replaced**, not appended — so if you need the portal you must include `gradlePluginPortal()` yourself. This matters when companies want plugins resolved only from a vetted internal mirror: declaring just the internal `maven {}` entry removes the public portal entirely, which is usually the intent.
code
kotlin · 7 linespluginManagement {
repositories {
gradlePluginPortal() // public portal — implicit default, restate it explicitly
mavenCentral() // some plugins live only here
maven { url = uri("https://nexus.example.com/repo/") }
}
}go deeper
Know you add a repositories {} block with gradlePluginPortal() and mavenCentral().
Explain that declaring your own list replaces the implicit portal default and that order matters.
Discuss pointing builds at an internal mirror and deliberately omitting the public portal for supply-chain control.
Treat plugin-repository configuration as a governance lever — a single audited source of plugins enforced across all repos.
## Declaring plugin repositories Plugin repositories are declared with a `repositories {}` block nested inside `pluginManagement {}`: ```kotlin pluginManagement { repositories { gradlePluginPortal() mavenCentral() maven { url = uri("https://nexus.example.com/repository/gradle-plugins/") credentials { username = providers.gradleProperty("nexusUser").get() password = providers.gradleProperty("nexusPassword").get() } } } } ``` ## The repository helpers - **`gradlePluginPortal()`** — the public Gradle Plugin Portal at `https://plugins.gradle.org`. This is where most community plugins are published and is the implicit default. - **`mavenCentral()`** — Maven Central; needed because some plugins (especially those published as plain Maven artifacts, like certain Android or Spring tooling) are only on Central. - **`maven { url = ... }`** — any custom Maven repository, e.g. an internal Nexus/Artifactory mirror, optionally with `credentials {}`. ## The implicit-default replacement rule This is the subtlety interviewers probe: if you do **not** declare a `repositories {}` block at all, Gradle falls back to the Gradle Plugin Portal automatically. But as soon as you declare your **own** `repositories {}`, you are giving an *explicit, exhaustive* list — the implicit portal default is **no longer added for you**. So: ```kotlin pluginManagement { repositories { maven { url = uri("https://nexus.example.com/repo/") } // gradlePluginPortal() is NOT implicitly present here } } ``` If a build then references a plugin only available on the portal, resolution fails. Add `gradlePluginPortal()` explicitly if you still want it. For locked-down corporate builds, *omitting* the portal is the goal — every plugin must come from the audited mirror. ## Resolution order Repositories are searched **in the order declared**. Putting the fast internal mirror first can speed up resolution and reduce reliance on public infrastructure. ## Relation to dependency repositories These plugin repositories are completely separate from the repositories that resolve *library dependencies* (configured in `dependencyResolutionManagement {}` or in build scripts). A repository declared for plugins is not automatically used for dependencies, and vice versa.
- If you declare only an internal maven {} repo inside pluginManagement, can you still use a plugin that's only on the Gradle Plugin Portal?No. Declaring your own repositories replaces the implicit portal default. You must add gradlePluginPortal() explicitly to keep access to portal-only plugins.
- In what order are plugin repositories searched?In the order they are declared. The first repository that has the plugin wins, so ordering affects both correctness and resolution speed.
- Why might mavenCentral() be needed in addition to gradlePluginPortal()?Some plugins are published only as Maven artifacts on Central (not mirrored to the portal), so without mavenCentral() their resolution fails.
saying these in an interview costs you the question
- Saying declaring your own repositories appends to the portal default instead of replacing it.
- Assuming every plugin is on the Gradle Plugin Portal.
- Reusing dependency-repository assumptions for plugin resolution.