skip to content

Maven

Apache Maven's whole model: a declarative POM, a fixed lifecycle, and plugins bound to its phases, plus dependency resolution and publishing. Interviewers start here because almost every JVM shop has a Maven build that someone has to explain or repair.

on this pageshow

explore

questions

250 · 11 sections

What are Maven coordinates (GAV), and what does each part identify?

level: juniorimportance: must knowfreq 80%
basics
~10 s

GAV stands for groupId, artifactId, version. Together they uniquely identify an artifact in a Maven repository. groupId is the owning org/namespace, artifactId is the project name, version is the release.

open as a page

What is the 'effective POM' in Maven, and how does it differ from the pom.xml you write by hand?

level: juniorimportance: must knowfreq 70%
basics
~10 s

The effective POM is the final, fully-merged project model Maven actually builds with. It combines your pom.xml with the built-in Super POM, parent POMs, and active profiles, filling in all defaults.

open as a page

What is POM inheritance in Maven, and how does a child POM declare its parent?

level: juniorimportance: must knowfreq 70%
basics
~10 s

A child POM points at a parent POM via the <parent> element (groupId, artifactId, version). The child then automatically gets the parent's configuration unless it overrides it.

open as a page

What are Maven properties, and how do you define and reference a custom property in a pom.xml?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Properties are named placeholders you set under <properties> in the pom and reference with ${name}. They let you avoid repeating values like version numbers in one central place.

open as a page

What does the <packaging> element do, and what are the common packaging types?

level: middleimportance: must knowfreq 70%
basics
~10 s

<packaging> tells Maven what kind of artifact to build and which lifecycle bindings to use. Common values: jar (default), war (web app), pom (aggregator/parent), and maven-plugin.

open as a page

On the mvn command line, what is the difference between passing a lifecycle phase (like `mvn package`) and a direct plugin goal (like `mvn compiler:compile`)?

level: juniorimportance: must knowfreq 80%
basics
~10 s

A phase (e.g. package) runs every step bound to it and all earlier phases in order. A goal (e.g. compiler:compile) runs just that one plugin task by itself.

open as a page

What does it mean for a Maven plugin goal to be 'bound' to a lifecycle phase, and why does running a phase execute plugin goals?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A lifecycle phase (like compile) is just a named step that does nothing by itself. Plugin goals are 'bound' to phases, so running 'mvn compile' actually runs the goals attached to that phase, like compiler:compile.

open as a page

Walk through the key phases of the default lifecycle in order and explain what typically happens at each.

level: juniorimportance: must knowfreq 75%
basics
~20 s

The main default phases run in order: validate, compile, test, package, verify, install, deploy. Validate checks the project, compile builds source, test runs unit tests, package makes the jar/war, verify runs checks, install copies to the local repo, deploy uploads to a remote repo.

open as a page

What are Maven's three built-in build lifecycles, and what is each one responsible for?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Maven has three built-in lifecycles: clean (deletes previous build output), default (builds, tests, packages and deploys the project), and site (generates project documentation/reports).

open as a page

What is the difference between `-DskipTests` and `-Dmaven.test.skip=true`, and how do `-D` properties work on the mvn command line in general?

level: middleimportance: must knowfreq 75%
basics
~10 s

-DskipTests compiles tests but skips running them. -Dmaven.test.skip=true skips both compiling AND running tests. -D sets a system/user property that plugins and the POM can read.

open as a page

How do you inspect the full dependency graph of a Maven project, and what does dependency:tree show you?

level: juniorimportance: must knowfreq 80%
basics
~10 s

Run mvn dependency:tree. It prints every dependency your project pulls in, including transitive ones, as an indented tree showing which dependency brought in which, plus the scope and version of each.

open as a page

What are the dependency scopes in Maven, and what is each one used for?

level: juniorimportance: must knowfreq 85%
basics
~20 s

Maven has six scopes: compile (default, everywhere), provided (compile/test only, supplied at runtime by the container), runtime (not for compiling, needed to run), test (only for tests), system (like provided but you give a local jar path), and import (only for BOMs in dependencyManagement).

open as a page

What are transitive dependencies in Maven, and where do they come from?

level: juniorimportance: must knowfreq 75%
basics
~10 s

Transitive dependencies are the dependencies of your dependencies. If you declare library A and A needs B, Maven automatically downloads B too, so you don't have to list it yourself.

open as a page

What does the <dependencyManagement> section in a pom.xml do, and how is it different from a plain <dependencies> section?

level: juniorimportance: must knowfreq 75%
basics
~20 s

<dependencyManagement> declares versions (and other settings) centrally but does NOT add the dependency to the build. Child modules that list the same dependency without a version inherit the managed version. Plain <dependencies> actually pulls the jar onto the classpath.

open as a page

What is the difference between the provided and runtime scopes, and when would you choose each?

level: middleimportance: must knowfreq 70%
basics
~20 s

provided is on the compile and test classpaths but NOT packaged or shipped, because something else (a container/JDK) supplies it at runtime. runtime is the opposite: NOT on the compile classpath but available (and packaged) for running and testing.

open as a page

Where in the build lifecycle does the maven-compiler-plugin run, and which goals does it execute by default?

level: juniorimportance: must knowfreq 60%
basics
~10 s

The compiler plugin's compiler:compile goal binds to the compile phase (main sources) and compiler:testCompile binds to test-compile (test sources). Maven binds these automatically for jar projects.

open as a page

What does the <configuration> block do inside a Maven plugin declaration, and how do you pass parameters to a plugin?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The <configuration> block sets a plugin's parameters in the pom.xml. Each child element name matches a plugin parameter (for example <source>17</source> for the compiler), and Maven injects those values into the plugin Mojo when it runs.

open as a page

What are Maven's core build plugins, and what is each one responsible for during a build?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Core build plugins handle the standard build steps: clean removes target/, resources copies non-code files, jar packages a JAR, install copies the artifact to the local repository, and deploy uploads it to a remote repository.

open as a page

What is a Maven plugin, and how does it relate to a 'goal' (mojo)?

level: juniorimportance: must knowfreq 80%
basics
~20 s

A Maven plugin is a bundle of related tasks. Each task is a 'goal', implemented by a class called a mojo. You run a goal like mvn compiler:compile, where compiler is the plugin and compile is the goal.

open as a page

What is a Mojo in Maven, and what are the minimum pieces you write to create a custom plugin goal?

level: middleimportance: must knowfreq 55%
basics
~10 s

A Mojo is the Java class behind one Maven goal. You extend AbstractMojo, annotate the class with @Mojo(name = "..."), implement execute(), and package it as a maven-plugin artifact so Maven can run it.

open as a page

What is a Maven profile, and why would you use one?

level: juniorimportance: must knowfreq 75%
basics
~20 s

A Maven profile is a named set of build settings (dependencies, plugins, properties) that can be turned on or off. You use it to vary the build for different environments like dev, test, and prod without changing the main configuration.

open as a page

Where does Maven store repository credentials, and what is the basic mechanism for keeping them out of plain text?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Credentials go in ~/.m2/settings.xml inside a <server> entry (id, username, password). Maven can encrypt the password so settings.xml holds an {encrypted} value instead of the real one, decrypted at build time using a master password.

open as a page

What is the difference between the global and user settings.xml files, and how does Maven combine them?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Maven reads two settings.xml files: a global one in the Maven install directory (${maven.home}/conf) and a user one in ~/.m2. The user file overrides the global file. Settings hold machine-level config like credentials and mirrors, not project info.

open as a page

What activation triggers can automatically enable a Maven profile, and how do they behave?

level: middleimportance: must knowfreq 70%
basics
~10 s

Besides activating with -P, a profile's <activation> can turn it on automatically: activeByDefault, a property being set, a JDK version range, the OS, or whether a file exists or is missing.

open as a page

Walk through the exact CLI steps to set up Maven password encryption from scratch.

level: middleimportance: must knowfreq 50%
basics
~10 s

First run mvn --encrypt-master-password to create the master, paste its output into ~/.m2/settings-security.xml. Then run mvn --encrypt-password for each server password and paste the {token} into the <server><password> in settings.xml.

open as a page

How do you set up JaCoCo to measure code coverage in a Maven build, and what does the prepare-agent goal actually do?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Add the jacoco-maven-plugin and bind its prepare-agent goal. prepare-agent sets a property (argLine) that adds the JaCoCo Java agent to the JVM running your tests, so it records which lines execute.

open as a page

How do you enforce a minimum Maven and Java version, and what does the version range syntax mean?

level: juniorimportance: must knowfreq 50%
basics
~10 s

Use the requireMavenVersion and requireJavaVersion rules with a version range. For example [3.9,) means '3.9 or higher'. The build fails if the running Maven or JDK is outside the range.

open as a page

What is the Maven Enforcer Plugin and what problem does it solve?

level: juniorimportance: must knowfreq 55%
basics
~10 s

The Enforcer Plugin lets you declare build rules (like a minimum Maven or Java version) and fails the build automatically when they are violated, so problems are caught early instead of at runtime.

open as a page

What is the Maven Failsafe plugin and how does it differ from the Surefire plugin?

level: juniorimportance: must knowfreq 70%
basics
~10 s

Failsafe runs integration tests; Surefire runs unit tests. Surefire fails the build immediately on a test failure, while Failsafe defers failure so teardown always runs.

open as a page

What are static analysis plugins in Maven, and how do you make one (e.g. Checkstyle) actually run during your build?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Static analysis plugins inspect source/bytecode for style and bug issues without running it. You add the plugin to your pom and bind its check goal to a build phase (often verify) inside an <execution> so mvn verify runs it automatically.

open as a page

What does the <packaging> element control in a Maven POM, and what is the difference between jar, war, and ear packaging?

level: juniorimportance: must knowfreq 70%
basics
~20 s

<packaging> tells Maven what artifact to build and which lifecycle to use. jar makes a plain Java archive, war makes a web app archive for a servlet container, and ear bundles multiple modules for a Java EE app server.

open as a page

What does the maven-assembly-plugin do, and when would you reach for it instead of the default jar packaging?

level: juniorimportance: must knowfreq 55%
basics
~20 s

The assembly plugin bundles your project output plus extra files (dependencies, scripts, docs) into a single distributable archive like a zip, tar.gz, or a fat jar. The default jar packaging only packs your own compiled classes.

open as a page

What is the MANIFEST.MF file inside a JAR, and how does Maven create it for you?

level: juniorimportance: must knowfreq 60%
basics
~10 s

MANIFEST.MF lives in META-INF/ inside a JAR and holds metadata as key: value lines (like the entry-point class). The maven-jar-plugin generates it automatically when you build with packaging jar.

open as a page

What is an uber-JAR (fat JAR) and how does the maven-shade-plugin build one?

level: juniorimportance: must knowfreq 70%
basics
~10 s

An uber-JAR is a single JAR that bundles your code plus all dependency classes, so it runs standalone with java -jar. maven-shade-plugin unpacks every dependency JAR and merges the classes into one output JAR.

open as a page

What does the spring-boot-maven-plugin's repackage goal do, and what is a layered jar?

level: middleimportance: must knowfreq 65%
basics
~20 s

The repackage goal takes the plain jar Maven built and rewrites it into an executable fat jar that embeds all dependencies and a launcher, so you can run it with java -jar. A layered jar splits it into layers ordered by change frequency to make Docker image builds cache better.

open as a page

Why does an aggregator/parent POM use <packaging>pom</packaging>, and what does it produce?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Because it isn't a real artifact like a jar — it only organizes other modules and/or shares config. packaging=pom makes Maven install just the POM file itself (no jar/war), and it is required for any POM with a <modules> section.

open as a page

What is the Maven reactor, and how do you build only a single module out of a large multi-module project from the command line?

level: juniorimportance: must knowfreq 70%
basics
~10 s

The reactor is Maven's engine that figures out which modules to build and in what order based on dependencies. To build one module, run from the root: mvn install -pl :artifactId (or -pl module-path).

open as a page

In a Maven multi-module build, what determines the order in which the reactor builds the modules?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Maven's reactor builds modules in dependency order, not in the order they are listed in <modules>. It looks at each module's <dependency> entries and builds a needed module before the one that depends on it.

open as a page

In a Maven multi-module project, what is the difference between aggregation and inheritance, and which POM elements express each?

level: middleimportance: must knowfreq 70%
basics
~20 s

Aggregation means a parent POM lists child <modules> so one build command builds them all. Inheritance means a child declares a <parent> and reuses its config (versions, plugins, dependencies). They are independent concerns that often live in the same POM.

open as a page

In a multi-module project, how do you keep dependency versions consistent across modules?

level: middleimportance: must knowfreq 65%
basics
~10 s

Put a <dependencyManagement> block (and version properties) in the shared parent POM. Child modules declare dependencies without versions, so every module uses the parent's pinned version.

open as a page

What is a mirror in Maven's settings.xml, and why would a team configure one?

level: juniorimportance: must knowfreq 70%
basics
~10 s

A mirror in settings.xml redirects requests for one or more repositories to a different URL. Teams use it to point all downloads at an internal repository manager instead of public servers.

open as a page

What is the difference between a SNAPSHOT version and a release version in Maven, and why does it matter for a release process?

level: juniorimportance: must knowfreq 75%
basics
~10 s

A SNAPSHOT (e.g. 1.0.0-SNAPSHOT) is a mutable in-development version that can change at any time; a release (e.g. 1.0.0) is immutable and published once. Releasing means dropping -SNAPSHOT and locking the artifact.

open as a page

What is the Maven local repository, where does it live, and what is it used for?

level: juniorimportance: must knowfreq 75%
basics
~10 s

The local repository is a folder on your machine (by default ~/.m2/repository) where Maven caches every downloaded dependency and plugin, plus artifacts you build and install yourself, so it doesn't re-download them.

open as a page

What does the maven-deploy-plugin's deploy goal do, and where does it sit in the build lifecycle relative to install?

level: juniorimportance: must knowfreq 65%
basics
~20 s

deploy is the last phase of the default lifecycle. The maven-deploy-plugin's deploy goal uploads the built artifact, its POM, and metadata to the remote repository. install (earlier) only copies it to your local ~/.m2 repo.

open as a page

What is the difference between a SNAPSHOT version and a release version in Maven, and how does Maven treat each one differently?

level: juniorimportance: must knowfreq 80%
basics
~10 s

A SNAPSHOT (e.g. 1.0.0-SNAPSHOT) is an in-development, mutable version Maven re-checks and may re-download; a release (e.g. 1.0.0) is final and immutable, downloaded once and cached forever.

open as a page

What is a Maven archetype, and how do you use archetype:generate to scaffold a new project?

level: juniorimportance: must knowfreq 55%
basics
~10 s

An archetype is a project template. You run mvn archetype:generate, pick a template, and answer prompts for groupId, artifactId and version; Maven creates a ready-to-build project skeleton from that template.

open as a page

What is the Maven Wrapper, and why would a project commit mvnw/mvnw.cmd into its repository?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The Maven Wrapper is a small script (mvnw on Unix, mvnw.cmd on Windows) checked into the repo. Running ./mvnw downloads and uses a fixed Maven version automatically, so everyone builds with the same Maven without installing it.

open as a page

How do you run a multi-module Maven build in parallel, and what does the -T option actually control?

level: middleimportance: must knowfreq 65%
basics
~10 s

Use the -T flag, e.g. mvn -T 4 install for 4 threads or mvn -T 1C install for one thread per CPU core. Maven builds independent modules of the reactor concurrently.

open as a page

Walk me through the contents of .mvn/wrapper/maven-wrapper.properties — what do distributionUrl and wrapperUrl control?

level: middleimportance: must knowfreq 55%
basics
~10 s

distributionUrl is the URL of the exact Maven version zip the wrapper downloads and runs. wrapperUrl is where the wrapper's own bootstrap jar is fetched from. Changing distributionUrl pins a different Maven version.

open as a page

What is the build-helper-maven-plugin, and what kinds of problems does it solve in a Maven build?

level: juniorimportance: should knowfreq 45%
basics
~10 s

It's a utility plugin that adds small 'glue' goals Maven core lacks: registering extra source/test folders, attaching extra build outputs as artifacts, parsing versions, extracting a property by regex, and reserving free network ports.

open as a page

What is an SBOM, and how do you generate one for a Maven project?

level: juniorimportance: must knowfreq 55%
basics
~10 s

An SBOM (Software Bill of Materials) is a machine-readable inventory of every dependency in your build. In Maven you generate one with the cyclonedx-maven-plugin, usually its makeBom goal, which writes bom.xml/bom.json.

open as a page

What is the OWASP dependency-check-maven plugin, and what problem does it solve in a Maven build?

level: juniorimportance: must knowfreq 65%
basics
~10 s

It is a Maven plugin that scans your project's dependencies for known security vulnerabilities (CVEs) by matching them against a public vulnerability database, and can fail the build if it finds risky libraries.

open as a page

What is a dependency confusion (substitution) attack in the context of Maven, and why is Maven susceptible to it?

level: middleimportance: must knowfreq 60%
basics
~20 s

An attacker publishes a package to a public repo with the same groupId/artifactId as your internal one. If your build can reach both repos, it may download the malicious public version instead of the private one.

open as a page

What is the difference between the makeBom and makeAggregateBom goals?

level: middleimportance: must knowfreq 45%
basics
~10 s

makeBom produces one SBOM per module from that module's dependencies. makeAggregateBom runs once for a multi-module (reactor) build and produces a single SBOM covering all modules together.

open as a page

How do you lock Maven to trusted sources using <mirrors> and <repositories> in settings.xml, and what does <mirrorOf> control?

level: seniorimportance: must knowfreq 50%
basics
~10 s

Add a <mirror> in settings.xml with <mirrorOf>*</mirrorOf> pointing at your trusted virtual repo. That redirects every repository request through it, so builds never hit untrusted public repos directly.

open as a page