What is Maven Central, and how does Maven know to use it by default?
answer
- repo.maven.apache.org/maven2
- id = central
- comes from Super POM
- mirror via settings.xml
- read-only to public
basics
~20 sMaven Central is the big public default remote repository of open-source artifacts. Maven knows about it because it's defined in the built-in Super POM that every project inherits, so you don't have to configure anything.
solid answer
~40 sMaven Central (`https://repo.maven.apache.org/maven2`) is the default public remote repository hosting the vast majority of open-source Java artifacts. Every project transitively inherits the **Super POM** — the built-in base POM shipped with Maven — which declares Central as a `<repository>` (and `<pluginRepository>`) with id `central`. That's why a fresh project resolves dependencies with zero repository configuration. You can override Central's URL (e.g. point it at an internal mirror) using a `<mirror>` in `settings.xml` whose `<mirrorOf>central</mirrorOf>` or `*` intercepts requests. Many teams front Central with a repository manager (Nexus/Artifactory) for caching, availability, and policy control. Note Central is read-only to the public; you publish there through a separate, audited process — you can't just `mvn deploy` to it without credentials and staging.
code
xml · 9 lines<settings>
<mirrors>
<mirror>
<id>company-nexus</id>
<url>https://nexus.example.com/repository/maven-public/</url>
<mirrorOf>central</mirrorOf>
</mirror>
</mirrors>
</settings>go deeper
Central is the default public repo and works with no config.
Trace it to the Super POM and know how to mirror it in settings.xml.
Weigh proxying Central through Nexus/Artifactory for resilience and policy.
Define org-wide repository governance: mirroring, allowlists, supply-chain/CVE gating, publish workflows.
## What Maven Central is Maven Central is the canonical public **remote repository** for Java/JVM open-source libraries, served at `https://repo.maven.apache.org/maven2`. It holds millions of artifacts published by the community. ## How Maven knows about it without config Every POM has an implicit parent chain ending at the **Super POM**, a base POM bundled inside Maven itself. The Super POM declares default settings including a repository: - `<repository>` with id `central` -> for dependencies. - `<pluginRepository>` with id `central` -> for plugins. Because your project inherits the Super POM, Central is available out of the box. Run `mvn help:effective-pom` and you'll see the `central` repository even if your own `pom.xml` mentions no repositories. ## Pointing elsewhere with a mirror In `~/.m2/settings.xml` you can redirect Central — usually to a corporate repository manager: ```xml <settings> <mirrors> <mirror> <id>company-nexus</id> <name>Internal mirror of Central</name> <url>https://nexus.example.com/repository/maven-public/</url> <mirrorOf>central</mirrorOf> </mirror> </mirrors> </settings> ``` `<mirrorOf>central</mirrorOf>` means "whenever a build wants the repo with id `central`, fetch from this URL instead." Use `*` to mirror everything, or `external:*` to mirror all but localhost. ## Publishing Central is read-only for the public. Publishing requires a namespace claim, signed artifacts (GPG), and a staging/release workflow via the Central Publisher Portal — it is not a plain `mvn deploy` against the public URL. ## Why teams add a repository manager - Caching/proxying improves speed and survives Central outages. - A single approval point for allowed/blocked artifacts (license, CVE policy). - A place to host private internal artifacts alongside proxied public ones.
- How can you confirm Central is configured without editing any file?Run `mvn help:effective-pom`; the inherited Super POM contributes a `<repository>` and `<pluginRepository>` with id `central`.
- How do you make all builds go through an internal mirror?Add a `<mirror>` in settings.xml with `<mirrorOf>*</mirrorOf>` (or `central`) pointing at the repository manager URL.
saying these in an interview costs you the question
- Claiming you configure Central in every pom.xml manually.
- Thinking you can `mvn deploy` straight to public Central with no staging/signing.
- Confusing a mirror (redirect) with an additional repository (extra source).