Walk me through the contents of .mvn/wrapper/maven-wrapper.properties — what do distributionUrl and wrapperUrl control?
answer
- distributionUrl = which Maven zip
- wrapperUrl = the bootstrap jar
- distributionType: bin / only-script / source
- sha256Sum = integrity check
- edit URL → pin version
basics
~10 sdistributionUrl is the URL of the exact Maven version zip the wrapper downloads and runs. wrapperUrl is where the wrapper's own bootstrap jar is fetched from. Changing distributionUrl pins a different Maven version.
solid answer
~40 s`.mvn/wrapper/maven-wrapper.properties` is the source of truth for which Maven the wrapper uses. The key entry is **`distributionUrl`** — the full URL to a Maven binary distribution zip (e.g. `apache-maven-3.9.6-bin.zip`). The wrapper parses the version from that URL, caches the unpacked distribution under `~/.m2/wrapper/dists`, and runs it. **`wrapperUrl`** points to the wrapper's own bootstrap jar (`maven-wrapper.jar`) when using the jar-based distribution type, so the script can self-download it if missing. The newer wrapper also supports `distributionType` (`bin`, `only-script`, `source`) and optional `distributionSha256Sum` / `wrapperSha256Sum` for integrity verification. To upgrade Maven you change one line — the version in `distributionUrl` — ideally via `mvn wrapper:wrapper -Dmaven=<version>` so all files stay consistent.
code
properties · 4 lineswrapperVersion=3.3.2
distributionType=only-script
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.6/apache-maven-3.9.6-bin.zip
distributionSha256Sum=706f01b20dec0305a822ab614d51f32b07ee11d0218175e55450242e49d2156ago deeper
Recognizes distributionUrl as 'where the Maven version comes from'.
Can read all keys, knows bin vs only-script, and how to bump the version.
Adds sha256 verification, caches the dist dir in CI, regenerates via the plugin to stay consistent.
Mandates checksum pinning and internal-mirror distributionUrls across the org for supply-chain control.
## The properties file `.mvn/wrapper/maven-wrapper.properties` is a plain Java properties file. It is the single place that decides *which* Maven the wrapper provisions. ## Key properties - **`distributionUrl`** — the most important line. A full URL to a Maven *binary distribution* archive, e.g. `https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.6/apache-maven-3.9.6-bin.zip`. The wrapper derives the version from this URL, downloads the archive (once), unpacks it into a per-user cache (`~/.m2/wrapper/dists/...`), and executes that Maven. **To pin or change the Maven version, you edit this URL.** - **`wrapperUrl`** — where to fetch `maven-wrapper.jar` (the bootstrap that actually performs the download) when it is not committed. Used by the jar/`bin` distribution type. - **`distributionType`** — `bin` (download full Maven, default), `only-script` (no jar committed; pure-script bootstrap, newer 3.2.0+ wrapper), or `source`. - **`distributionSha256Sum`** / **`wrapperSha256Sum`** — optional checksums; the wrapper verifies the download against them, protecting against tampered or corrupted distributions (important for supply-chain hygiene). ## Caching behavior Downloads are cached per user, so the cost is paid once per Maven version per machine. CI caches `~/.m2/wrapper` to avoid re-downloading on every run. ## Example file ```properties wrapperVersion=3.3.2 distributionType=only-script distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.6/apache-maven-3.9.6-bin.zip distributionSha256Sum=706f01b20dec0305a822ab614d51f32b07ee11d0218175e55450242e49d2156a ``` ## Upgrading correctly Prefer regenerating with the plugin rather than hand-editing so the scripts, jar, and properties stay in sync: ```bash mvn wrapper:wrapper -Dmaven=3.9.6 -Dtype=only-script ```
- Where is the downloaded Maven distribution cached?Per user, under ~/.m2/wrapper/dists (keyed by version). CI typically caches this directory to avoid re-downloading.
- How do you make the wrapper verify the integrity of the downloaded Maven?Set distributionSha256Sum (and wrapperSha256Sum for the jar) in maven-wrapper.properties; the wrapper checks the download against the hash and fails if it doesn't match.
saying these in an interview costs you the question
- Confusing distributionUrl (the Maven version) with wrapperUrl (the bootstrap jar).
- Hand-editing the properties version but leaving stale wrapper scripts/jar, causing inconsistencies.
- Thinking the properties file controls dependency versions — it only controls the Maven engine version.