What POM metadata is required for a Maven Central release, and why?
answer
- name + description + url
- license name+url
- scm connection/devConnection/url
- at least one developer
- validated before release
basics
~10 sYou need name, description, url, at least one license, an scm block (source control URLs), and at least one developer. These let consumers identify, license-check, and trace the artifact.
solid answer
~40 sCentral enforces a metadata baseline so every public artifact is identifiable and legally usable. Required POM elements: `<name>` and `<description>` (human-readable identity), `<url>` (project home), at least one `<license>` with name and URL (so consumers can do license compliance), an `<scm>` block (`connection`, `developerConnection`, `url`) pointing at source control for provenance, and at least one `<developer>` (a contact/owner). The coordinates `<groupId>`, `<artifactId>`, `<version>`, and `<packaging>` must also be present and the groupId must match your verified namespace. If any of these are missing the validation step rejects the deployment before it can be released. This metadata also feeds search.maven.org and downstream tooling like license scanners and SBOM generators.
code
xml · 14 lines<licenses>
<license>
<name>Apache-2.0</name>
<url>https://www.apache.org/licenses/LICENSE-2.0.txt</url>
</license>
</licenses>
<scm>
<connection>scm:git:https://github.com/acme/widget-core.git</connection>
<developerConnection>scm:git:[email protected]:acme/widget-core.git</developerConnection>
<url>https://github.com/acme/widget-core</url>
</scm>
<developers>
<developer><id>jdoe</id><name>Jane Doe</name></developer>
</developers>go deeper
Recalls that name, license, and developer info are required.
Can enumerate all required elements and write a correct license/scm/developers block.
Knows how inheritance affects the effective POM and how metadata feeds compliance tooling.
Standardizes metadata via a shared parent/BOM and enforces it in CI before release.
## Why metadata is mandatory Maven Central is a *public, permanent* corpus consumed by millions of builds. Sonatype enforces a metadata floor so artifacts are **identifiable**, **legally usable**, and **traceable**. Missing fields cause the publish validation to fail. ## The required fields - **`<name>`** — human-readable project name. - **`<description>`** — one-line summary; shown in search. - **`<url>`** — project homepage. - **`<licenses>` / `<license>`** — at least one, with a `<name>` and `<url>`. Enables automated license-compliance scanning. - **`<scm>`** — source control: `<connection>` (read-only, e.g. `scm:git:https://...`), `<developerConnection>` (read-write), and `<url>`. Provides provenance. - **`<developers>` / `<developer>`** — at least one with `<name>` and/or `<id>`. A point of contact and a sign of stewardship. Plus the usual coordinates: `<groupId>` (must equal your verified namespace), `<artifactId>`, `<version>`, `<packaging>`. ## Example POM fragment ```xml <project> <groupId>io.github.acme</groupId> <artifactId>widget-core</artifactId> <version>1.2.0</version> <packaging>jar</packaging> <name>Widget Core</name> <description>Reusable widget primitives for the JVM.</description> <url>https://github.com/acme/widget-core</url> <licenses> <license> <name>Apache-2.0</name> <url>https://www.apache.org/licenses/LICENSE-2.0.txt</url> </license> </licenses> <scm> <connection>scm:git:https://github.com/acme/widget-core.git</connection> <developerConnection>scm:git:[email protected]:acme/widget-core.git</developerConnection> <url>https://github.com/acme/widget-core</url> </scm> <developers> <developer> <id>jdoe</id> <name>Jane Doe</name> <email>[email protected]</email> </developer> </developers> </project> ``` ## Common pitfalls - Putting these only in a parent POM that isn't published — child needs effective metadata. - Empty/placeholder license or SCM blocks — validation checks they're present and well-formed.
- Where do these elements live if you use a parent POM?They must appear in the *effective* POM of the published artifact. They can be inherited from a published parent, but the deployed module must resolve to complete metadata.
- What does the scm block provide that url doesn't?Provenance and machine-readable source-control coordinates (connection strings) for release plugins and tooling, separate from the human-facing project homepage url.
saying these in an interview costs you the question
- Saying only groupId/artifactId/version are needed
- Omitting the license block
- Assuming an empty placeholder scm/developer passes validation