skip to content

Supply Chain & Security

Hardening the dependency supply chain: generating SBOMs, scanning for known CVEs, and defending against dependency confusion and tampered artifacts. Increasingly asked because compliance requirements now reach directly into the build file.

on this pageshow

explore

questions

16

What is an SBOM, and how do you generate one for a Maven project?

level: juniorimportance: must knowfreq 55%

answer

  1. SBOM = ingredient label
  2. cyclonedx-maven-plugin
  3. makeBom / makeAggregateBom
  4. PURL identifiers
  5. bom.xml / bom.json in target

basics

~10 s

An SBOM (Software Bill of Materials) is a machine-readable inventory of every dependency in your build. In Maven you generate one with the cyclonedx-maven-plugin, usually its makeBom goal, which writes bom.xml/bom.json.

solid answer

~40 s

An SBOM (Software Bill of Materials) is a formal, machine-readable list of every component your application ships — direct and transitive dependencies — with their group/artifact/version, licenses, and identifiers (PURLs). It lets security and compliance tools answer 'am I affected by CVE-X?' and 'what licenses am I shipping?'. For Maven the standard tool is the `org.cyclonedx:cyclonedx-maven-plugin`. Bind its `makeBom` goal (single module) or `makeAggregateBom` (multi-module reactor) to a phase like `package`, and it emits `target/bom.xml` and/or `bom.json` in CycloneDX format. By default it also attaches the BOM as a build artifact so it gets installed/deployed alongside the JAR. You typically run it in CI and feed the output to scanners like Dependency-Track, Grype, or Trivy.

code

bash · 2 lines
bash
mvn org.cyclonedx:cyclonedx-maven-plugin:makeAggregateBom
# emits target/bom.xml and target/bom.json (CycloneDX)

go deeper

for a junior

Knows SBOM = list of all dependencies and that cyclonedx-maven-plugin generates it.

for a middle

Can wire makeBom/makeAggregateBom to a phase and locate bom.xml/bom.json in target.

for a senior

Explains transitive coverage, PURLs, attaching as artifact, and feeding scanners in CI.

for a principal

Drives org-wide SBOM policy: format/schema standards, central collection (Dependency-Track), and release-gating.

## What an SBOM is A **Software Bill of Materials (SBOM)** is a structured, machine-readable inventory of all the software components that make up an application. Think of it like the ingredient label on food packaging: it lists every library you depend on — both the ones you declared directly and the **transitive** ones pulled in automatically — along with metadata such as version, license, and a unique identifier. Why it matters: - **Vulnerability response:** when a CVE (a publicly catalogued security flaw) drops, you can query your SBOMs to instantly find which apps include the affected component and version. - **License compliance:** legal/compliance teams need to know every license (Apache-2.0, GPL, MIT, etc.) you redistribute. - **Supply-chain transparency:** regulations and customer contracts increasingly require an SBOM per release. ## Generating one in Maven The de-facto plugin is **`org.cyclonedx:cyclonedx-maven-plugin`**. It walks Maven's resolved dependency graph and serializes it into the **CycloneDX** SBOM format. Key goals: - **`makeBom`** — produces an SBOM for the current module from its resolved dependencies. - **`makeAggregateBom`** — for multi-module (reactor) builds, produces a single SBOM covering all modules. Bind the goal to a lifecycle phase (commonly `package`) so it runs automatically: ```xml <plugin> <groupId>org.cyclonedx</groupId> <artifactId>cyclonedx-maven-plugin</artifactId> <version>2.8.0</version> <executions> <execution> <id>build-sbom</id> <phase>package</phase> <goals> <goal>makeAggregateBom</goal> </goals> </execution> </executions> <configuration> <outputFormat>all</outputFormat> <!-- xml + json --> <schemaVersion>1.5</schemaVersion> <includeLicenseText>false</includeLicenseText> </configuration> </plugin> ``` The output lands in `target/bom.xml` and `target/bom.json`. ## Identifiers and content Each component carries a **PURL (Package URL)** like `pkg:maven/org.springframework/[email protected]`, plus its hashes and license. PURLs are what scanners match against vulnerability databases. ## CLI run You can also invoke it ad hoc without editing the POM: ```bash mvn org.cyclonedx:cyclonedx-maven-plugin:makeAggregateBom ``` The result is consumed by SBOM-aware tools (Dependency-Track, Grype, Trivy, Syft) for continuous vulnerability monitoring.

  • Does the SBOM include transitive dependencies?
    Yes — it serializes Maven's fully resolved dependency graph, so direct and transitive components both appear, with the resolved versions after mediation.
  • Where does the generated BOM file go by default?
    Into target/ as bom.xml and/or bom.json, and it is attached as a build artifact so install/deploy publish it alongside the main JAR.

An SBOM is the ingredient list on a food package — it lets you check for an allergen (CVE) without re-cooking the meal.

saying these in an interview costs you the question

  • Saying an SBOM only lists your declared (direct) dependencies
  • Confusing an SBOM with a dependency:tree text dump — an SBOM is a standardized, tool-consumable format with identifiers and licenses
  • Thinking you must hand-write the inventory

context

open as a page

What is the OWASP dependency-check-maven plugin, and what problem does it solve in a Maven build?

level: juniorimportance: must knowfreq 65%

basics

~10 s

It is a Maven plugin that scans your project's dependencies for known security vulnerabilities (CVEs) by matching them against a public vulnerability database, and can fail the build if it finds risky libraries.

open as a page

What is a dependency confusion (substitution) attack in the context of Maven, and why is Maven susceptible to it?

level: middleimportance: must knowfreq 60%

basics

~20 s

An attacker publishes a package to a public repo with the same groupId/artifactId as your internal one. If your build can reach both repos, it may download the malicious public version instead of the private one.

open as a page

What is the difference between the makeBom and makeAggregateBom goals?

level: middleimportance: must knowfreq 45%

basics

~10 s

makeBom produces one SBOM per module from that module's dependencies. makeAggregateBom runs once for a multi-module (reactor) build and produces a single SBOM covering all modules together.

open as a page

How do you lock Maven to trusted sources using <mirrors> and <repositories> in settings.xml, and what does <mirrorOf> control?

level: seniorimportance: must knowfreq 50%

basics

~10 s

Add a <mirror> in settings.xml with <mirrorOf>*</mirrorOf> pointing at your trusted virtual repo. That redirects every repository request through it, so builds never hit untrusted public repos directly.

open as a page

How does failBuildOnCVSS work, and how would you tune it so it is useful rather than just noisy?

level: seniorimportance: must knowfreq 50%

basics

~20 s

failBuildOnCVSS is a number from 0 to 11. If any dependency has a CVE with a CVSS score at or above that value, the build fails. Lower the number to be stricter; raise it to be more lenient.

open as a page

How does Maven verify artifact integrity with checksums, and what does running with -C (strict checksum policy) change?

level: middleimportance: should knowfreq 35%

basics

~10 s

Every artifact has companion .sha1/.md5 checksum files. Maven downloads them and compares. By default a mismatch only warns; running mvn -C makes a mismatch a hard build failure.

open as a page

What is the difference between the dependency-check `check` and `aggregate` goals in a multi-module Maven build?

level: middleimportance: should knowfreq 40%

basics

~10 s

check scans each module on its own and produces a report per module. aggregate scans the whole multi-module project together and produces a single combined report at the root.

open as a page

How does versions-maven-plugin help you stay on top of outdated dependencies, and how is it different from a vulnerability scanner?

level: middleimportance: should knowfreq 45%

basics

~10 s

versions-maven-plugin reports newer available versions of your dependencies and plugins (for example with display-dependency-updates) and can update your pom. It only checks for newer versions, not for security vulnerabilities.

open as a page

What role does PGP signing via the maven-gpg-plugin play in supply-chain integrity, and how does signature verification differ from checksum verification?

level: seniorimportance: should knowfreq 30%

basics

~20 s

The maven-gpg-plugin signs your artifacts with a private PGP key, producing .asc files. Consumers verify the signature with your public key, proving the artifact came from you and wasn't altered — something a plain checksum cannot prove.

open as a page

How do you ensure the generated bom.xml/bom.json is published alongside your build, and how is it consumed downstream?

level: seniorimportance: should knowfreq 30%

basics

~10 s

The cyclonedx-maven-plugin attaches the BOM as a secondary build artifact by default, so mvn install/deploy publish it next to the JAR with a 'cyclonedx' classifier. CI then feeds it to scanners like Dependency-Track.

open as a page

CycloneDX vs SPDX — what are these SBOM formats and how do they relate to the Maven plugin?

level: seniorimportance: should knowfreq 35%

basics

~10 s

Both are standard SBOM formats. CycloneDX (OWASP) is security-focused and is what cyclonedx-maven-plugin emits natively (xml/json). SPDX (Linux Foundation) is license/compliance-focused; for SPDX in Maven you use a different plugin or convert.

open as a page

How do you handle false positives from dependency-check, and what goes into a suppression file?

level: seniorimportance: should knowfreq 35%

basics

~20 s

You write a suppression.xml file listing specific CVEs to ignore for specific dependencies, then point the plugin at it. It tells the scanner that a particular finding is a false positive (or accepted risk) so it stops failing the build.

open as a page

How do you prevent a Maven build (and its repository manager) from silently falling back to untrusted public repositories for internal coordinates?

level: principalimportance: should knowfreq 25%

basics

~20 s

Route all resolution through one trusted virtual repo (mirrorOf *), don't declare public repos in POMs, and configure the repo manager so internal groupId prefixes are never proxied from upstream. Use owned groupId namespaces so collisions can't exist publicly.

open as a page

What operational challenges does running dependency-check in CI introduce, and how do you keep the pipeline fast and reliable?

level: principalimportance: should knowfreq 30%

basics

~20 s

The big cost is downloading and updating the NVD database, which is large and slow and can hit rate limits. You fix this by caching the database, using an NVD API key, updating it once centrally, and not re-downloading it in every build.

open as a page

How would you use a Maven-generated SBOM to drive license and compliance audits across many services?

level: principalimportance: nice to knowfreq 20%

basics

~10 s

Generate a CycloneDX SBOM in every service's build, publish it centrally, and run automated policy checks on the component/license inventory to flag disallowed licenses and vulnerable components, gating releases that violate policy.

open as a page