skip to content

Dependency Management

Configurations such as api and implementation, version catalogs, resolution and conflict rules, repositories, and dependency verification. Interviewers focus here because Gradle resolves differently from Maven and candidates often assume otherwise.

on this pageshow

explore

questions

179 · 6 sections

You try to resolve `implementation` and get an error that it cannot be resolved. Why, and what should you resolve instead?

level: juniorimportance: must knowfreq 50%
basics
~10 s

implementation is a declaration bucket — isCanBeResolved is false — so it has no resolution result. Resolve compileClasspath or runtimeClasspath, which extend from it.

open as a page

What is the `dependencies {}` block in a Gradle build script, and how do you add a dependency to a specific configuration inside it?

level: juniorimportance: must knowfreq 70%
basics
~10 s

The dependencies {} block is where you declare a module's dependencies. Inside it you call a configuration name like implementation(...) with the dependency coordinates (group:name:version) to attach a dependency to that configuration.

open as a page

How do `testImplementation` and `testRuntimeOnly` relate to the main source set's configurations, and when do you use each?

level: juniorimportance: must knowfreq 58%
basics
~20 s

testImplementation adds a dependency to the test compile + runtime classpath (e.g. JUnit, Mockito). testRuntimeOnly adds it only to the test runtime classpath (e.g. the JUnit Platform launcher engine). Test classpaths also extend the main ones.

open as a page

How do you exclude a single transitive dependency that is pulled in by one specific dependency in Gradle?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Attach an exclude block to that one dependency, naming the unwanted artifact by group and/or module. Only that dependency's transitive graph is affected.

open as a page

What does the string dependency notation 'group:name:version' mean in Gradle, and how do you declare such a dependency?

level: juniorimportance: must knowfreq 80%
basics
~10 s

It's the shorthand for a module's coordinates: group (org), name (artifact), version. You declare it inside a configuration, e.g. implementation("org.apache.commons:commons-lang3:3.14.0").

open as a page

What does 'dependency version alignment' mean in Gradle, and why might you need it for a dependency family like Jackson?

level: juniorimportance: must knowfreq 55%
basics
~10 s

Alignment forces all modules of one library family (e.g. all jackson-* artifacts) to resolve to the same version, instead of a mix, avoiding runtime incompatibilities between modules built to be released together.

open as a page

What is a Gradle version catalog and where does the default `libs` catalog come from?

level: juniorimportance: must knowfreq 68%
basics
~10 s

A version catalog is a central, typed list of dependency coordinates and versions shared across a build. Gradle auto-creates the libs catalog from gradle/libs.versions.toml if that file exists.

open as a page

What is the gradle/libs.versions.toml file, and what are the four tables it can contain?

level: juniorimportance: must knowfreq 70%
basics
~10 s

It's Gradle's version catalog: a TOML file at gradle/libs.versions.toml listing dependency coordinates and versions in one place. Its four tables are [versions], [libraries], [bundles], and [plugins].

open as a page

What is the difference between a dynamic version and a changing version in Gradle dependency management?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A dynamic version lets Gradle pick which version to resolve (e.g. '1.+', 'latest.release'). A changing version is one fixed coordinate whose artifacts can change over time (e.g. '-SNAPSHOT'), so the same version number may hold different content.

open as a page

What does the platform() dependency notation do in Gradle, and what is a typical use for it?

level: juniorimportance: must knowfreq 60%
basics
~10 s

platform() imports a Maven BOM so its version constraints apply to your dependencies, letting you declare those dependencies without versions and keep them aligned.

open as a page

When two transitive dependencies require different versions of the same module, what does Gradle do by default?

level: juniorimportance: must knowfreq 78%
basics
~10 s

By default Gradle picks the highest requested version of the module and uses that single version everywhere on the classpath. This is 'highest-version-wins' conflict resolution.

open as a page

What does `resolutionStrategy.force('com.google.guava:guava:32.1.3-jre')` do, and when would you reach for it?

level: juniorimportance: must knowfreq 58%
basics
~10 s

It pins Guava to exactly that version for the whole configuration, overriding whatever version conflict resolution would otherwise pick — even if another dependency wants a higher one.

open as a page

What is dependency locking in Gradle, and why would you enable it?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Dependency locking pins the exact versions a configuration resolves to, saving them in a lockfile. With dynamic versions or version ranges, builds can drift over time; locking makes resolution reproducible across machines and over time.

open as a page

What is dependency substitution in Gradle, and what problem does it solve?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Dependency substitution lets you swap one dependency for another during resolution — for example, replacing a published external module with a local project so you build and test against your own source instead of a release.

open as a page

What is a 'capability' in Gradle dependency management, and what problem does it solve compared to plain version conflict resolution?

level: middleimportance: must knowfreq 45%
basics
~20 s

A capability is a label (group:name:version) saying 'I provide this feature'. By default a module provides one capability matching its GAV. Two modules offering the same capability conflict, even if they are different modules — like log4j and log4j-over-slf4j both providing logging.

open as a page

Where does Gradle store downloaded dependencies, and what is the purpose of that cache?

level: juniorimportance: must knowfreq 60%
basics
~10 s

Gradle stores downloaded artifacts and metadata under GRADLE_USER_HOME/caches/modules-2 (default ~/.gradle). The cache avoids re-downloading the same dependency on every build, speeding things up and enabling offline reuse.

open as a page

What is centralized repository management in Gradle, and where do you configure it?

level: juniorimportance: must knowfreq 55%
basics
~10 s

It's declaring repositories once for the whole build inside settings.gradle.kts using dependencyResolutionManagement { repositories {} }, instead of repeating repositories {} in every project's build.gradle.kts.

open as a page

What is repository content filtering in Gradle, and why would you use it?

level: juniorimportance: must knowfreq 55%
basics
~10 s

It tells Gradle which repositories can or cannot supply which modules, using a content {} block with includeGroup/excludeGroup. This avoids pointless lookups and speeds up resolution.

open as a page

How do you configure a private Maven repository in Gradle that requires a username and password, and where should those secrets actually live?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Declare the repo with a url and a credentials { username; password } block. Don't hardcode the secrets — read them from gradle.properties or environment variables instead.

open as a page

What is a repository in Gradle, and how do you declare one so your dependencies can be resolved?

level: juniorimportance: must knowfreq 78%
basics
~10 s

A repository is a source Gradle downloads dependency artifacts and metadata from. You declare them in a repositories {} block, e.g. mavenCentral(), so Gradle knows where to look for the modules you depend on.

open as a page

How do you actually trigger a registered artifact transform during resolution using an artifactView?

level: middleimportance: must knowfreq 42%
basics
~10 s

Resolve the configuration with an artifactView that requests the transform's to attribute, e.g. configurations.runtimeClasspath.get().incoming.artifactView { attributes.attribute(artifactType, "classes") }.artifacts. Requesting that attribute makes Gradle insert the transform.

open as a page

What does it mean to register an artifact transform in Gradle, and what do `from` and `to` describe?

level: middleimportance: must knowfreq 45%
basics
~10 s

You call dependencies.registerTransform(MyTransform) { ... } and declare from.attribute(...) and to.attribute(...). Gradle uses those attributes to know which artifacts the transform can convert and what it produces.

open as a page

How do you correctly produce derived files inside a TransformAction using TransformOutputs, and what rule governs where those files may live?

level: middleimportance: must knowfreq 28%
basics
~20 s

Call outputs.file(name) or outputs.dir(name) to get a location, then write your derived content there. Outputs must be either the input artifact itself or a path under the directory Gradle gives you — never an arbitrary location.

open as a page

What is a TransformAction in Gradle, and what are the two essential pieces you must implement when writing one?

level: middleimportance: must knowfreq 35%
basics
~10 s

A TransformAction converts an input artifact into one or more derived output files. You implement the transform(outputs) method and mark the input file with @InputArtifact so Gradle injects it.

open as a page

Where can artifact transforms be registered, and how do they become available to a project or an entire build?

level: middleimportance: should knowfreq 22%
basics
~20 s

You register transforms inside a project's dependencies { registerTransform(...) } block, usually from a plugin's apply. The registration is scoped to that project; to share, apply the plugin (or a convention/settings plugin) to every project that needs it.

open as a page

What is checksum verification in Gradle's dependency verification, and what problem does it solve?

level: juniorimportance: must knowfreq 55%
basics
~10 s

Gradle records an expected hash (e.g. sha256) for each downloaded artifact in verification-metadata.xml. On every build it re-hashes the file and fails if it differs, proving the artifact wasn't tampered with or swapped.

open as a page

What is the verification-metadata.xml file in Gradle, where does it live, and what is its purpose?

level: juniorimportance: must knowfreq 55%
basics
~10 s

It's an XML file at gradle/verification-metadata.xml that lists trusted checksums and/or signatures for every dependency and plugin Gradle resolves. When present and enabled, Gradle verifies each artifact against it before use.

open as a page

What does PGP signature verification in Gradle's dependency verification feature actually verify, and how does it differ from a checksum?

level: juniorimportance: must knowfreq 45%
basics
~10 s

PGP verification checks that a dependency's .asc signature file was produced by a trusted publisher's private key, proving authenticity. A checksum only proves the bytes match a recorded hash, not who produced them.

open as a page

Walk through the practical workflow for keeping verification-metadata.xml current as your project adds and upgrades dependencies over time. What goes wrong if you do it carelessly?

level: middleimportance: must knowfreq 40%
basics
~20 s

When you change dependencies, re-run --write-verification-metadata to append new entries, review the diff in your PR, and commit it. If you skip this, the build fails with 'artifact not in verification metadata'. Regenerating blindly can silently trust tampered artifacts.

open as a page

How do you initially generate Gradle's verification-metadata.xml file, and what does the --write-verification-metadata flag actually do during the build?

level: middleimportance: must knowfreq 55%
basics
~10 s

Run the build with --write-verification-metadata <checksums>, e.g. ./gradlew build --write-verification-metadata sha256. Gradle resolves all dependencies and writes their computed checksums into gradle/verification-metadata.xml.

open as a page