What is the spring-boot-dependencies BOM and what problem does it solve?
answer
- packaging=pom, only dependencyManagement
- curated, tested-together versions
- declare starters with no version
- version == Boot version
- manages versions, adds nothing
basics
~10 sspring-boot-dependencies is a BOM (Bill of Materials): a special POM listing tested, compatible versions of Spring and third-party libraries. Import it so you declare dependencies without versions and get a consistent, curated version set.
solid answer
~40 sThe spring-boot-dependencies BOM is a Maven POM of packaging type 'pom' that contains a large <dependencyManagement> section pinning versions for hundreds of libraries Spring Boot tests together (Spring modules, Jackson, Hibernate, Tomcat, Kotlin, etc.). By importing it, your build inherits those managed versions, so you declare dependencies like spring-boot-starter-web with no <version> element. The BOM only manages versions, it doesn't add any dependencies to your build. The benefit is a single curated, mutually-compatible dependency set that eliminates version guesswork and reduces conflicts. Its version equals the Spring Boot version you target. It is the same version data the spring-boot-starter-parent uses under the hood, but importing the BOM directly lets you use it without inheriting the Boot parent POM.
code
kotlin · 17 lines// Excerpt of what spring-boot-dependencies conceptually contains (Maven POM view):
// <dependencyManagement>
// <dependencies>
// <dependency>
// <groupId>com.fasterxml.jackson.core</groupId>
// <artifactId>jackson-databind</artifactId>
// <version>2.17.2</version>
// </dependency>
// ... hundreds more ...
// </dependencies>
// </dependencyManagement>
//
// Result in your build.gradle.kts (versions omitted, resolved from BOM):
dependencies {
implementation("org.springframework.boot:spring-boot-starter-web")
implementation("com.fasterxml.jackson.module:jackson-module-kotlin")
}go deeper
Know it's a curated list of compatible versions letting you omit versions on starters.
Explain packaging=pom, dependencyManagement-only, and that it adds nothing.
Contrast parent-inheritance vs direct import and note version-override precedence.
Frame it as the reproducible, tested dependency contract and its role in supply-chain/version governance.
## What a BOM is A **BOM (Bill of Materials)** is a normal Maven POM whose `<packaging>` is `pom` and whose main purpose is a large `<dependencyManagement>` block. `<dependencyManagement>` does **not** add dependencies to a project — it only declares *what version to use* if and when a given dependency is requested. Think of it as a lookup table: 'if anyone asks for `com.fasterxml.jackson.core:jackson-databind`, use version X'. ## spring-boot-dependencies specifically `org.springframework.boot:spring-boot-dependencies` is the BOM Spring Boot publishes. Its version string equals the Spring Boot release you target (e.g. `3.3.4`). Inside it are managed versions for: - Every Spring Boot and Spring Framework module (spring-core, spring-web, spring-context, all the `spring-boot-starter-*` artifacts). - Hundreds of third-party libraries Spring Boot integrates with and **tests together**: Jackson, Hibernate/JPA, Tomcat/Jetty/Undertow, Netty, Micrometer, Logback/SLF4J, Kotlin, JUnit, Mockito, Testcontainers, and so on. Because Spring engineers run integration tests against this exact combination, the versions are known to be mutually compatible. That is the core value: you don't hand-pick versions and risk `NoSuchMethodError` from a Jackson/Hibernate mismatch. ## How you consume it When the BOM's managed versions are in effect, you write dependencies **without a version**: ```xml <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> <!-- no <version> --> </dependency> ``` Maven resolves the version from dependency management. There are two ways to bring the BOM in: 1. **Inherit `spring-boot-starter-parent`** — the parent POM itself imports spring-boot-dependencies, plus adds plugin config, resource filtering, Java version, etc. 2. **Import the BOM directly** with `<scope>import</scope>` — gives you only the version management, no parent inheritance. Useful when your project already has another parent (a corporate parent POM) since Maven allows only one parent. ## Key gotchas - Importing the BOM adds **zero** dependencies — you still declare each starter you want; it only supplies versions. - The BOM version must match the Spring Boot version you actually use; mixing a `3.3.x` BOM with `3.4.x` starters is unsupported. - A `<dependency>` version you write explicitly always wins over the BOM's managed version (nearest/explicit wins), which is how you override. ## When to use Always, for any Spring Boot project. Use the parent for greenfield apps; use the import scope when you can't inherit the Boot parent.
- Does importing the BOM add spring-boot-starter-web to your classpath?No. A BOM only supplies managed versions via dependencyManagement. You still declare each dependency yourself; the BOM just fills in the version.
- What version should the spring-boot-dependencies BOM be?The same as the Spring Boot version you target — the BOM is versioned in lockstep with each Boot release, e.g. 3.3.4.
saying these in an interview costs you the question
- Saying the BOM downloads/adds dependencies by itself.
- Thinking you must still specify versions on starters after importing it.
- Believing you need the Boot parent POM to get managed versions.