Maven
Maven
Beginner
Q1: What is Maven?
Maven is a build automation and project management tool primarily for Java projects.
Q2: What problems does Maven solve?
Dependency management, standardized build lifecycle, and reproducible project structure.
Q3: What is POM?
Project Object Model file (pom.xml) describing project metadata and build configuration.
Q4: Why is pom.xml central in Maven?
It defines coordinates, dependencies, plugins, profiles, and lifecycle behavior.
Q5: What are Maven coordinates?
groupId, artifactId, version (GAV) uniquely identifying artifacts.
Q6: What is groupId?
Organization or domain-based namespace for project artifacts.
Q7: What is artifactId?
Module/library name within group.
Q8: What is version?
Artifact release identifier (e.g., 1.0.0).
Q9: What is packaging in Maven?
Artifact type produced by build (jar, war, pom, etc.).
Q10: Default packaging type?
jar if unspecified.
Q11: What is Maven lifecycle?
Ordered sequence of build phases executed to build/test/package/deploy software.
Q12: Three built-in lifecycles?
clean, default (build), site.
Q13: What is a phase?
Named step in lifecycle (compile, test, package, verify, install, deploy…).
Q14: What is a goal?
Specific task executed by a plugin (e.g., compiler:compile).
Q15: Phase vs goal?
Phase is lifecycle step; goals are plugin tasks bound to phases.
Q16: What does mvn clean do?
Runs clean lifecycle, removing previous build output (target directory).
Q17: What does mvn compile do?
Compiles main source code.
Q18: What does mvn test do?
Runs tests (usually unit tests) in test phase.
Q19: What does mvn package do?
Packages compiled code into distributable artifact (jar/war).
Q20: What does mvn verify do?
Runs checks/verification after packaging (integration with QA gates/plugins).
Q21: What does mvn install do?
Installs built artifact into local Maven repository.
Q22: What does mvn deploy do?
Publishes artifact to remote repository for team/shared usage.
Q23: What is local repository?
Local cache/store of artifacts, usually under ~/.m2/repository.
Q24: What is remote repository?
Server-hosted artifact repository (Maven Central, Nexus, Artifactory, etc.).
Q25: What is Maven Central?
Default public repository hosting open-source Maven artifacts.
Q26: What is dependency in Maven?
External artifact required by project.
Q27: How declare dependency?
Inside <dependencies> section in pom.xml.
Q28: What is dependency scope?
Defines classpath visibility and transitivity behavior.
Q29: Common scopes?
compile, provided, runtime, test, system, import.
Q30: compile scope meaning?
Available in all classpaths and transitive by default.
Q31: provided scope meaning?
Needed for compile/test but expected from runtime container (not packaged transitively as runtime).
Q32: runtime scope meaning?
Not needed at compile time, required at runtime/test runtime.
Q33: test scope meaning?
Only available during test compilation/execution.
Q34: What is transitive dependency?
Dependency brought indirectly by another dependency.
Q35: Why transitive deps are useful?
Reduce manual declaration burden.
Q36: Risk of transitive dependencies?
Version conflicts and hidden classpath surprises.
Q37: What is dependency conflict in Maven?
Multiple versions of same artifact appear in dependency graph.
Q38: Maven conflict resolution default?
“Nearest definition” in dependency tree wins.
Q39: How inspect dependency tree?
Use mvn dependency:tree.
Q40: What is exclusion in dependency?
Prevent specific transitive artifact from being included.
Q41: What is dependencyManagement?
Central section controlling dependency versions without direct inclusion.
Q42: dependencyManagement vs dependencies?
Management defines versions/rules; dependencies actually include artifacts.
Q43: What is parent POM?
POM inherited by child project for shared configuration.
Q44: Why use parent POM?
Consistency and reduced duplication across modules/projects.
Q45: What is multi-module Maven project?
Aggregator project building multiple modules together.
Q46: What is aggregator POM packaging?
Usually pom packaging.
Q47: Standard Maven directory layout?
src/main/java, src/test/java, src/main/resources, etc.
Q48: Why follow standard layout?
Convention over configuration; plugin defaults work seamlessly.
Q49: What is plugin in Maven?
Extension component adding build functionality.
Q50: Common core plugins?
compiler, surefire, failsafe, jar, resources, clean, install, deploy.
Q51: What is surefire plugin?
Runs unit tests in test phase.
Q52: What is failsafe plugin?
Runs integration tests, typically in integration-test/verify phases.
Q53: Why separate unit and integration tests?
Faster feedback and clearer pipeline stages.
Q54: What is settings.xml?
User/global Maven runtime configuration (repos, mirrors, credentials, profiles).
Q55: Should credentials be stored in pom.xml?
No; use settings.xml/CI secret management.
Q56: Beginner Maven anti-pattern?
Copy-pasting huge plugin config without understanding lifecycle impact.
Q57: Another beginner anti-pattern?
Using dynamic/snapshot dependencies in production releases carelessly.
Q58: Beginner reproducibility baseline?
Pin plugin/dependency versions explicitly.
Q59: Beginner CI baseline?
Run clean verify on every pull request.
Q60: Beginner best practice?
Keep POM minimal, explicit, and convention-aligned.
Intermediate
Q61: What is BOM in Maven?
Bill of Materials POM centralizing compatible dependency versions.
Q62: How import BOM?
Use dependencyManagement with scope import and type pom.
Q63: Why use BOM?
Version alignment and fewer dependency conflicts.
Q64: What is effective POM?
Fully resolved POM after inheritance, profiles, and defaults.
Q65: How view effective POM?
mvn help:effective-pom.
Q66: What is effective settings?
Resolved settings after global/user/profile interpolation.
Q67: How inspect effective settings?
mvn help:effective-settings.
Q68: What is Maven profile?
Conditional configuration activated by property/JDK/OS/file/explicit flag.
Q69: Why use profiles?
Environment-specific behavior (dev/ci/release) without duplicating POMs.
Q70: Profile activation methods?
-P flag, properties, OS, JDK version, file presence.
Q71: Profile anti-pattern?
Encoding business logic and excessive complexity in profiles.
Q72: What is pluginManagement?
Centralized plugin versions/config inherited by children.
Q73: pluginManagement vs plugins?
Management defines defaults; plugins section binds executions.
Q74: Why pin plugin versions?
Avoid non-reproducible builds due to plugin version drift.
Q75: What is Maven Wrapper?
Project-local wrapper scripts ensuring consistent Maven version usage.
Q76: Why use Maven Wrapper in teams?
Eliminates “works on my Maven version” problems.
Q77: What is snapshot version?
Mutable development version ending with -SNAPSHOT.
Q78: Snapshot vs release artifact?
Snapshot can change; release should be immutable.
Q79: What is updatePolicy for snapshots?
Controls frequency of checking remote snapshot updates.
Q80: What is checksumPolicy?
Defines behavior on artifact checksum mismatch (warn/fail).
Q81: What is mirror in settings.xml?
Redirect repository requests through specified mirror (e.g., internal proxy).
Q82: Why use repository manager (Nexus/Artifactory)?
Caching, access control, proxying, and artifact governance.
Q83: What is dependency convergence?
Ensuring consistent single versions across transitive graph.
Q84: How enforce convergence?
Maven Enforcer rules and BOM management.
Q85: What is Maven Enforcer Plugin?
Plugin enforcing project/build rules (Java version, banned deps, convergence, etc.).
Q86: What is reproducible build in Maven context?
Same source produces same artifact bytes/metadata (as much as possible).
Q87: Common reproducibility issues?
Timestamps, plugin drift, generated file ordering, environment differences.
Q88: What is flatten-maven-plugin concept?
Produces simplified consumer POM for publication/use cases.
Q89: What is versions-maven-plugin?
Helps inspect/update dependency/plugin versions.
Q90: What is dependency mediation?
Maven selecting one artifact version among conflicts.
Q91: How force specific dependency version?
Declare direct dependency or manage version in dependencyManagement.
Q92: What is optional dependency?
Dependency not transitively inherited by default consumers.
Q93: What is classifier?
Extra artifact variant label (sources, javadoc, tests, native variants).
Q94: What is attached artifact?
Additional artifact produced in build besides main packaging.
Q95: What is shade plugin?
Creates uber/fat jar and can relocate packages.
Q96: Shade vs assembly plugin?
Shade focuses class relocation/uber jars; assembly builds custom distributions.
Q97: What is resource filtering?
Replacing placeholders in resource files during build.
Q98: Resource filtering risk?
Accidental modification/leakage of binary/sensitive content.
Q99: What is toolchains plugin?
Selects configured JDK/toolchain independent from runtime JAVAHOME.
Q100: Why use toolchains?
Consistent cross-JDK builds in CI/dev.
Q101: What is reactor build?
Maven building modules together in dependency-aware order.
Q102: How build specific module with dependencies?
Use reactor flags like -pl and -am.
Q103: What is -amd?
Build selected module and dependents (affected downstream modules).
Q104: What is parallel build flag?
-T for multithreaded module build.
Q105: Parallel build caveat?
Plugins/tests must be thread-safe; ordering assumptions may break.
Q106: What is incremental build challenge in Maven?
Core Maven is not fully incremental like some newer build tools.
Q107: Mitigation for slow builds?
Module boundaries, test splitting, cache/proxy, parallelism, plugin tuning.
Q108: What is surefire vs failsafe lifecycle binding?
Surefire in test phase; failsafe in integration-test + verify.
Q109: Why verify phase important with failsafe?
Ensures integration test failures fail build properly.
Q110: What is JaCoCo plugin use?
Code coverage measurement/reporting.
Q111: Coverage anti-pattern?
Chasing percentage metrics without meaningful assertions.
Q112: What is site lifecycle in Maven?
Generates project reports/documentation site.
Q113: Why site lifecycle less common now?
Many teams use external docs/CI dashboards, but it remains useful.
Q114: What is GPG signing in Maven release?
Cryptographically signing artifacts for integrity/trust.
Q115: What is release plugin concept?
Automates version bump/tag/release flow (opinions vary on usage).
Q116: Why some teams avoid release plugin?
Complexity and SCM workflow mismatch; prefer explicit CI release scripts.
Q117: What is CI-friendly versioning?
Using properties (e.g., revision) to inject versions in pipelines.
Q118: What is build cache role with Maven?
Primarily repository cache/proxy; remote build cache support varies by tooling.
Q119: What is intermediate anti-pattern?
Huge parent POM mixing unrelated concerns for every module.
Q120: Better parent strategy?
Layered parents/BOMs with clear scope and ownership.
Q121: What is security scanning in Maven pipelines?
Analyze dependencies/plugins for known vulnerabilities/licenses.
Q122: Why scan plugins too?
Build plugins execute code and can introduce supply-chain risk.
Q123: What is license compliance check?
Ensure dependency licenses meet organization policy.
Q124: Intermediate maturity signal?
Team can explain classpath, lifecycle bindings, and dependency graph decisions.
Q125: Intermediate troubleshooting flow?
effective-pom -> dependency tree -> plugin execution debug -> CI env parity.
Q126: What is -X in Maven?
Debug logging mode for detailed troubleshooting.
Q127: What is -U flag?
Forces update checks for snapshots/releases metadata.
Q128: What is offline mode (-o)?
Build using local repository only without remote access.
Q129: Intermediate reliability principle?
Builds should be deterministic, policy-checked, and environment-consistent.
Q130: Intermediate best practice?
Standardize parent/BOM/plugin governance and keep modules cohesive.
Advanced
Q131: What is enterprise Maven governance?
Organization-wide control of dependencies, plugins, repos, and release policies.
Q132: What is golden parent POM?
Curated parent enforcing approved plugin/dependency defaults and quality gates.
Q133: What is platform BOM strategy?
Central BOMs per tech stack aligned with tested compatibility matrix.
Q134: What is dependency allowlist/denylist model?
Explicitly permit trusted artifacts and block risky/unapproved ones.
Q135: What is transitive risk management challenge?
Indirect dependencies can introduce vulnerabilities unexpectedly.
Q136: Mitigation for transitive risk?
SBOM generation, continuous scanning, and strict upgrade cadence.
Q137: What is SBOM in Maven ecosystem?
Machine-readable dependency inventory produced during build/release.
Q138: Why SBOM matters?
Compliance, incident response, and supply-chain transparency.
Q139: What is artifact provenance?
Traceability of who built artifact, from which source, with what tools.
Q140: How strengthen provenance in Maven pipelines?
Signed commits/tags, signed artifacts, immutable CI, attestations.
Q141: What is hermetic build principle?
Build isolated from undeclared external influences for reproducibility/security.
Q142: Maven hermeticity challenge?
Plugins/dependencies often fetched from remote repos unless mirrored/pinned.
Q143: How approximate hermetic Maven builds?
Internal mirrored repos, locked versions, controlled toolchains, offline-capable CI steps.
Q144: What is build promotion model?
Promote same artifact binary across environments instead of rebuilding.
Q145: Why avoid rebuilding per environment?
Rebuilds can produce drift and invalidate prior test assurances.
Q146: What is monorepo Maven scaling challenge?
Large reactor size and cross-module coupling slow feedback.
Q147: Mitigation for monorepo scale?
Clear module boundaries, selective builds, parallel CI partitioning.
Q148: What is graph-aware CI optimization?
Run only impacted module tests/builds based on dependency graph changes.
Q149: What is flaky test impact on Maven pipelines?
Erodes trust and blocks reliable release automation.
Q150: How manage flaky tests?
Detection, quarantine with SLA, root-cause fix ownership.
Q151: What is remote caching/proxy tuning at scale?
Optimize repository manager throughput, TTLs, and storage cleanup.
Q152: What is checksum fail policy importance?
Prevents corrupted/tampered artifacts entering builds.
Q153: What is namespace takeover/dependency confusion risk?
Malicious artifact with similar coordinates/version hijacks resolution path.
Q154: Mitigation for dependency confusion?
Use internal repos/mirrors strictly and control external resolution.
Q155: What is plugin execution attack surface?
Compromised plugin can execute arbitrary build-time code.
Q156: Plugin security controls?
Pin versions, approve sources, scan/sign artifacts, restrict network/permissions in CI.
Q157: What is reproducible timestamp control?
Configure archiver/jar settings for deterministic file metadata.
Q158: What is bytecode target consistency issue?
Mismatched compiler/source/target settings break runtime compatibility.
Q159: How enforce Java compatibility?
maven-compiler-plugin + enforcer + toolchains.
Q160: What is multi-release JAR concept?
JAR containing version-specific classes for different Java runtimes.
Q161: Multi-release JAR tradeoff?
Flexibility vs increased build/test complexity.
Q162: What is advanced versioning strategy?
Semantic versioning + compatibility checks + automated release notes.
Q163: What is API compatibility enforcement?
Binary/source compatibility checks in CI before release.
Q164: What is dependency lock concept in Maven?
Not native like some tools; approximated via BOM/enforcer/fixed versions.
Q165: What is release train model?
Coordinated version set across many modules/services on regular cadence.
Q166: Release train risk?
Coordination overhead and delayed independent delivery.
Q167: What is polyglot build challenge with Maven?
Integrating non-JVM assets/tools while preserving deterministic lifecycle.
Q168: What is containerized Maven build benefit?
Consistent build environment across dev/CI platforms.
Q169: Containerized build caveat?
Cache warm-up and I/O overhead if not optimized.
Q170: What is disaster recovery concern for Maven infra?
Repository manager outage can block builds/deploys organization-wide.
Q171: DR mitigation for artifact infrastructure?
Backups, geo-replication, mirror failover, cache seeding.
Q172: What is advanced anti-pattern in Maven ecosystems?
Unbounded parent POM inheritance with opaque plugin side effects.
Q173: Better architectural principle?
Explicit minimal conventions + strong automated policy enforcement.
Q174: What is final reliability principle?
Builds must be deterministic, test-gated, and reproducible on demand.
Q175: What is final security principle?
Trust nothing by default: verify dependencies, plugins, and artifacts continuously.
Q176: What is final performance principle?
Optimize feedback loops via module design, selective CI, and cache strategy.
Q177: What is final governance principle?
Central standards with team autonomy through well-defined extension points.
Q178: What is final operations principle?
Continuously observe build health: duration, flake rate, failure taxonomy.
Q179: What is final architecture principle?
Align module boundaries with domain boundaries to reduce build coupling.
Q180: Final maturity principle?
Maven excellence is disciplined dependency governance plus fast, reproducible delivery.
Bonus: Minimal Maven POM Template (Spring Boot style)
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <groupId>com.example</groupId> <artifactId>demo</artifactId> <version>1.0.0</version> <packaging>jar</packaging> <properties> <java.version>21</java.version> <maven.compiler.release>${java.version}</maven.compiler.release> </properties> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter</artifactId> <version>3.3.2</version> </dependency> </dependencies> <build> <plugins> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-compiler-plugin</artifactId> <version>3.13.0</version> <configuration> <release>${maven.compiler.release}</release> </configuration> </plugin> </plugins> </build> </project>