skip to content

What is Maven Central, and at a high level what does it take to publish an artifact there?

level: juniorimportance: should knowfreq 45%

answer

  1. default repo for resolution
  2. Sonatype operates it
  3. verified groupId namespace
  4. sources+javadoc+gpg sign
  5. immutable releases

basics

~10 s

Maven Central is the default public repository where Maven downloads dependencies. To publish, you need a registered namespace (groupId), full POM metadata, GPG-signed artifacts, and you upload through Sonatype's Central Portal.

solid answer

~40 s

Maven Central is the canonical public repository that Maven (and Gradle, sbt, etc.) reads from by default — when you declare a dependency, it's resolved from `repo.maven.apache.org/maven2` unless you configure another repo. Publishing TO it is a separate flow run by Sonatype. You must: (1) claim a `groupId` namespace and prove ownership (DNS TXT record or a verified GitHub org like `io.github.<user>`); (2) produce the artifact plus `-sources.jar`, `-javadoc.jar`, and `.pom`; (3) sign everything with GPG so each file has a `.asc`; (4) include required POM metadata — name, description, url, license, scm, developers; (5) upload a deployment bundle via the Central Portal (or historically OSSRH staging), which validates and releases it. Once released to Central, a version is immutable.

code

bash · 5 lines
bash
# Resolve from Central (automatic):
mvn dependency:get -Dartifact=org.apache.commons:commons-lang3:3.14.0

# Publish to Central (after full setup):
mvn clean deploy -P release

go deeper

for a junior

Knows Central is the default download repo and that publishing needs an account and signing.

for a middle

Can list the concrete requirements: verified groupId, sources/javadoc jars, GPG signatures, POM metadata.

for a senior

Understands immutability, namespace verification options (DNS vs GitHub), and why validation is strict.

for a principal

Sets org-wide publishing policy, namespace governance, and reproducible release pipelines.

## What Maven Central is **Maven Central** is the largest public repository of Java/JVM artifacts. It is the *default* remote repository for Maven: out of the box, declaring a `<dependency>` makes Maven fetch it from `https://repo.maven.apache.org/maven2`. Gradle, sbt, Leiningen and others use it too. It is operated by **Sonatype**. There are two sides: - **Consuming** (resolving dependencies) — automatic, no account needed. - **Publishing** (deploying your own library) — gated, requires identity verification and strict metadata/signing rules so that public artifacts are trustworthy and reproducible. ## Core requirements to publish 1. **A verified namespace (groupId).** You must own the coordinate. Options: a reversed domain you control (`com.example`, verified via a DNS TXT record) or `io.github.<username>` (verified through GitHub). 2. **Complete artifacts.** A release must include the main JAR, a **`-sources.jar`**, a **`-javadoc.jar`**, and the **`.pom`**. (For non-JAR types like `pom` packaging the rules differ slightly.) 3. **GPG signatures.** Every uploaded file needs a detached `.asc` signature, and the public key must be published to a keyserver so Sonatype can verify it. 4. **Required POM metadata.** `<name>`, `<description>`, `<url>`, at least one `<license>`, an `<scm>` block, and at least one `<developer>`. 5. **Upload + release.** Via the modern **Central Portal** (`central.sonatype.com`) using the `central-publishing-maven-plugin`, or historically via **OSSRH** Nexus staging with `nexus-staging-maven-plugin`. ## Immutability Once a non-SNAPSHOT version is released to Central it can **never** be changed or removed — you publish a new version instead. This is why validation is strict. ```bash # A normal release deploy once everything is configured mvn clean deploy -P release ``` The `release` profile typically activates the GPG signing plugin and the publishing plugin so they don't run on every local build.

  • Do you need an account to download from Maven Central?
    No. Resolution is anonymous and is the default repository. An account/namespace is only needed to publish.
  • Can you delete a released version from Central?
    No. Released (non-SNAPSHOT) versions are immutable and permanent; you fix mistakes by releasing a new version.

Maven Central is like a public app store for libraries: anyone can download, but to publish you must verify your identity, sign your package, and meet listing requirements.

saying these in an interview costs you the question

  • Thinking you must add Central as a repository to download from it (it's the default)
  • Believing you can overwrite or delete a released version
  • Forgetting that sources and javadoc jars are mandatory

context