skip to content

What is Maven Central, and how does Maven know to use it by default?

level: juniorimportance: should knowfreq 55%

answer

  1. repo.maven.apache.org/maven2
  2. id = central
  3. comes from Super POM
  4. mirror via settings.xml
  5. read-only to public

basics

~20 s

Maven Central is the big public default remote repository of open-source artifacts. Maven knows about it because it's defined in the built-in Super POM that every project inherits, so you don't have to configure anything.

solid answer

~40 s

Maven Central (`https://repo.maven.apache.org/maven2`) is the default public remote repository hosting the vast majority of open-source Java artifacts. Every project transitively inherits the **Super POM** — the built-in base POM shipped with Maven — which declares Central as a `<repository>` (and `<pluginRepository>`) with id `central`. That's why a fresh project resolves dependencies with zero repository configuration. You can override Central's URL (e.g. point it at an internal mirror) using a `<mirror>` in `settings.xml` whose `<mirrorOf>central</mirrorOf>` or `*` intercepts requests. Many teams front Central with a repository manager (Nexus/Artifactory) for caching, availability, and policy control. Note Central is read-only to the public; you publish there through a separate, audited process — you can't just `mvn deploy` to it without credentials and staging.

code

xml · 9 lines
xml
<settings>
  <mirrors>
    <mirror>
      <id>company-nexus</id>
      <url>https://nexus.example.com/repository/maven-public/</url>
      <mirrorOf>central</mirrorOf>
    </mirror>
  </mirrors>
</settings>

go deeper

for a junior

Central is the default public repo and works with no config.

for a middle

Trace it to the Super POM and know how to mirror it in settings.xml.

for a senior

Weigh proxying Central through Nexus/Artifactory for resilience and policy.

for a principal

Define org-wide repository governance: mirroring, allowlists, supply-chain/CVE gating, publish workflows.

## What Maven Central is Maven Central is the canonical public **remote repository** for Java/JVM open-source libraries, served at `https://repo.maven.apache.org/maven2`. It holds millions of artifacts published by the community. ## How Maven knows about it without config Every POM has an implicit parent chain ending at the **Super POM**, a base POM bundled inside Maven itself. The Super POM declares default settings including a repository: - `<repository>` with id `central` -> for dependencies. - `<pluginRepository>` with id `central` -> for plugins. Because your project inherits the Super POM, Central is available out of the box. Run `mvn help:effective-pom` and you'll see the `central` repository even if your own `pom.xml` mentions no repositories. ## Pointing elsewhere with a mirror In `~/.m2/settings.xml` you can redirect Central — usually to a corporate repository manager: ```xml <settings> <mirrors> <mirror> <id>company-nexus</id> <name>Internal mirror of Central</name> <url>https://nexus.example.com/repository/maven-public/</url> <mirrorOf>central</mirrorOf> </mirror> </mirrors> </settings> ``` `<mirrorOf>central</mirrorOf>` means "whenever a build wants the repo with id `central`, fetch from this URL instead." Use `*` to mirror everything, or `external:*` to mirror all but localhost. ## Publishing Central is read-only for the public. Publishing requires a namespace claim, signed artifacts (GPG), and a staging/release workflow via the Central Publisher Portal — it is not a plain `mvn deploy` against the public URL. ## Why teams add a repository manager - Caching/proxying improves speed and survives Central outages. - A single approval point for allowed/blocked artifacts (license, CVE policy). - A place to host private internal artifacts alongside proxied public ones.

  • How can you confirm Central is configured without editing any file?
    Run `mvn help:effective-pom`; the inherited Super POM contributes a `<repository>` and `<pluginRepository>` with id `central`.
  • How do you make all builds go through an internal mirror?
    Add a `<mirror>` in settings.xml with `<mirrorOf>*</mirrorOf>` (or `central`) pointing at the repository manager URL.

saying these in an interview costs you the question

  • Claiming you configure Central in every pom.xml manually.
  • Thinking you can `mvn deploy` straight to public Central with no staging/signing.
  • Confusing a mirror (redirect) with an additional repository (extra source).

context