What does mvn artifact:check-buildplan do, and how does it fit into verifying a reproducible build?
answer
- maven-artifact-plugin goal
- static lint of build plan
- flags missing outputTimestamp
- compare = dynamic byte diff
- buildinfo = published fingerprint
basics
~10 sartifact:check-buildplan (from the maven-artifact-plugin) inspects your effective build plan and warns or fails if plugins are configured in a way that breaks reproducibility — for example if project.build.outputTimestamp is missing.
solid answer
~40 s`mvn artifact:check-buildplan` is a goal of the `maven-artifact-plugin`. It analyzes the *effective build plan* — the configured plugins and their parameters — and reports configuration that is known to harm reproducibility, most notably a missing `project.build.outputTimestamp` or plugins/versions known not to be reproducible-friendly. It is a *static* pre-check: it doesn't rebuild and diff bytes; it tells you whether your setup *should* be reproducible. You complement it with the dynamic check `artifact:compare`, which rebuilds and compares the produced artifacts (often against a reference deploy at `https://.../.buildinfo`). A typical CI gate runs `check-buildplan` to fail fast on misconfiguration, then `compare` to prove byte-identity. There is also `artifact:describe-build-output` / `.buildinfo` generation to publish a fingerprint of outputs for third-party verification.
code
bash · 4 lines# static check (fail fast in CI)
mvn artifact:check-buildplan
# dynamic proof against a reference
mvn clean verify artifact:comparego deeper
Knows there is a Maven goal that checks if your build is set up for reproducibility.
Knows check-buildplan is static and that compare/byte-diff is the dynamic counterpart.
Can wire both into CI as fail-fast plus proof, and explain the maven-artifact-plugin goal set.
Establishes org-wide verification: published .buildinfo, third-party rebuild policy, and gates that distinguish 'configured' from 'proven' reproducibility.
## The maven-artifact-plugin Apache ships a dedicated plugin — `maven-artifact-plugin` — for reproducibility tooling. Its key goals: - **`artifact:check-buildplan`** — a *static* lint of your build plan. - **`artifact:compare`** — a *dynamic* rebuild-and-diff against a reference. - **`artifact:buildinfo`** (a.k.a. `describe-build-output`) — generates a `.buildinfo` fingerprint file listing each artifact and its checksum, for independent verifiers. ## What check-buildplan checks It walks the **effective build plan** (all plugin executions and their resolved parameters) and flags things known to break byte-stability, for example: - `project.build.outputTimestamp` is **not set**. - A plugin version is on a list known to be non-reproducible (older versions before fixes landed). - Configuration that injects volatile data. It is fast and needs no network or reference artifact, so it is ideal as a **fail-fast CI gate**. ```bash mvn artifact:check-buildplan ``` To make it fail the build instead of just warning, you bind it with the appropriate configuration / run it as a verification step. ## Static vs dynamic verification `check-buildplan` answers 'is my build *configured* to be reproducible?' It does **not** prove the bytes match. For proof you run: ```bash mvn clean verify artifact:compare ``` `compare` rebuilds and compares the resulting artifacts to a reference (e.g. a previously published `.buildinfo`), reporting any files that differ. ## Where it fits in a pipeline 1. Set `project.build.outputTimestamp` (often from the commit). 2. CI runs `artifact:check-buildplan` -> fail fast if misconfigured. 3. CI builds and publishes a `.buildinfo` with `artifact:buildinfo`. 4. Independent rebuilders run `artifact:compare` to confirm identical bytes. Together these make the build *verifiably* reproducible rather than merely *intended* to be.
- Does check-buildplan prove the artifact bytes are identical?No. It is a static check of configuration. To prove byte-identity you rebuild and run artifact:compare (or compare published checksums/.buildinfo).
- What is a .buildinfo file?A fingerprint file generated by artifact:buildinfo listing each produced artifact and its checksum, so independent parties can verify a rebuild matches the published outputs.
saying these in an interview costs you the question
- Claiming check-buildplan rebuilds and diffs the artifact bytes.
- Confusing it with running the build twice manually as the only verification.
- Thinking it requires network/reference artifacts to run.