Releases: apache/maven
Release list
3.10.0
🚀 New features and improvements
- Maven 3.10.x should use Maven 3.1 validation in strict mode (#1542) @gnodet
- Do not depend on maven-resolver-supplier-mvn3 (#13266) @cstamas
- [MNG-6797] - Remember if Maven model problems were encountered. (#298) @wilx
- feat: add relativePath validation (#12742) @cstamas
- Add validation for Plexus-based plugin dependency injection (#12651) @slawekjaranowski
- Introduce validation control (#12549) @cstamas
- Update to Resolver 2.0.21 (#12504) @cstamas
- [MNG-5913] - Allow defining aliases for existing server configurations in settings.xml (#12475) @slawekjaranowski
🐛 Bug Fixes
- Issue #13265: let a settings server declare the repository origins its credentials may be used with (#13275) @slawekjaranowski
- Backport #13040: treat reactor BOM imports as ProjectSorter edges so -am includes them (#13263) @gnodet
- [MNG-8174] - Fix NPE when a property references itself in a plugin configuration (backport #12932) (#12936) @elharo
- Fix #13200: publish a complete set from MavenProject.getArtifacts (#13204) @gnodet
- Fixes #13135: ensure completeness of the reactor summary, privilege f… (#13173) @rmannibucau
- [3.10.x] Fix #13084: sandbox profile activation context for external model builds (#13114) @gnodet
- Fix #13100: honor repositories from legitimately-active external model profiles (#13116) @gnodet
- Add support for MAVEN_PROJECTBASEDIR substitution in jvm.config (backport of MNG-8598 to 3.10.x) (#13115) @gnodet
- Scope server credentials and validate legacy relocation coordinates (#12954) @slachiewicz
- Honour configured policy and validate inputs on the legacy compat paths (#12978) @gnodet
- Add unit test for #12600 null-guard in forked executions (#12923) @gnodet
- Fix: make ProjectIndex thread-safe for parallel builds (backport #12832) (#12927) @gnodet
- Fail on misconfigured plugin-requested toolchains (#12616) @wilx
- Resolve classified POM artifacts from the reactor in Maven 3.x (#12659) @wilx
- [3.10.x] Convert paths for MSYS2 and jvm.config placeholders in bin/mvn (#12567) @gnodet
- Preserve dependency scope in plugin artifacts - fix #12497 (#12503) @slawekjaranowski
📝 Documentation updates
- docs: document plugin.xml V4 vs V3 (#13261) @gnodet
- [maven-3.10.x] Port the site documentation from APT to Markdown (#12712) @slachiewicz
- improve doc about deprecating plugin descriptor's requirement (#12555) @hboutemy
- Drop mention of Plexus XML (#12482) @cstamas
👻 Maintenance
- [3.10.x] maintenance: Align use of profiles (#13274) @cstamas
- Remove version from rat directory deployment (#13046) @slawekjaranowski
- Update NOTICE file in distribution packages (#13044) @slawekjaranowski
- Restrict what a repository-resolved model contributes to the build (#12953) @slachiewicz
- Validate coordinates and repository precedence during artifact resolution (#12952) @slachiewicz
- [MNG-8129] - Clarify relativePath validation comment (#12966) @gnodet
- [12811] Keep plexus-cipher at 2.0: POM note (#12879) @slachiewicz
- [3.10.x] Use try-with-resources (#12845) @slachiewicz
- Migrate the embedder-test-project fixture to JUnit 5 (#12717) @slachiewicz
- [maven-3.10.x] Port the site documentation from APT to Markdown (#12712) @slachiewicz
- Migrate legacy plugin Javadoc annotations in Maven Embedder tests (#12708) @wilx
- Replace custom
GraphLoggerwithDependencyGraphDumperin dependency resolution (#12639) @slawekjaranowski - Fix UT: do not use checkout directly (#12483) @cstamas
🔧 Build
- Replace nicoulaj checksum plugin with maveniverse checksum plugin (#13053) @slawekjaranowski
- 3.10.x Build by JDK 25, limit JDK to min and max LTS in build (#12848) @slawekjaranowski
- Update Maven version to 3.10.0-rc-1 in GH configuration (#12847) @slawekjaranowski
📦 Dependency updates
- [3.10.x] deps: Update to Maven Resolver 2.0.24 (#13271) @cstamas
- build: bump xmlunitVersion from 2.13.0 to 2.14.0 (#13237) @dependabot[bot]
- build: bump org.apache.maven:maven-parent from 49 to 50 (#13242) @dependabot[bot]
- Resolver 2.0.23 and validation cleanup (#13078) @cstamas
- Bump org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2 (#13134) @dependabot[bot]
- Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.3.0 to 3.3.1 (#13132) @dependabot[bot]
- Bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 (#13130) @dependabot[bot]
- Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.27 to 1.28 (#13129) @dependabot[bot]
- Bump actions/setup-java from 6.0.0 to 6.0.1 (#13110) @dependabot[bot]
- Bump jlineVersion from 3.30.16 to 3.30.17 (#13111) @dependabot[bot]
- Bump slf4jVersion from 2.0.18 to 2.0.19 (#13074) @dependabot[bot]
- Bump org.codehaus.modello:modello-maven-plugin from 2.8.0 to 2.8.1 (#13028) @dependabot[bot]
- [12811] Keep plexus-cipher at 2.0: POM note (#12879) @slachiewicz
- Bump actions/setup-java from 5.7.0 to 6.0.0 (#12860) @dependabot[bot]
- Deps: Bump to Resolver 2.0.22 (#12803) @cstamas
- Bump resolverVersion from 2.0.21 to 2.0.22 (#12823) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0 (#12825) @dependabot[bot]
- Bump com.google.guava:guava from 33.7.0-jre to 33.7.1-jre (#12796) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-utils from 3.6.1 to 3.6.2 (#12795) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 2.1.0 to 2.2.0 (#12794) @dependabot[bot]
- Bump org.codehaus.modello:modello-maven-plugin from 2.7.0 to 2.8.0 (#12793) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-classworlds from 2.12.0 to 2.12.1 (#12792) @dependabot[bot]
- Bump com.google.guava:guava from 33.6.0-jre to 33.7.0-jre (#12776) @dependabot[bot]
- Bump xmlunitVersion from 2.12.0 to 2.13.0 (#12673) @dependabot[bot]
- Bump actions/setup-java from 5.6.0 to 5.7.0 ([...
Maven 4.0.0-rc-7
This release candidate is expected to be the last before the Maven 4.0.0 GA release, which we aim to publish in the coming weeks, pending community feedback.
🚀 New features and improvements
- Log API enhancements and mojo MDC (#12690) @gnodet
- Optimize reactor sort and phase comparator performance (#12901) @gnodet
- Add AsyncDrainWriter to eliminate PrintWriter lock contention (#12892) @gnodet
- Add validation for Plexus-based plugin dependency injection (#12649) @slawekjaranowski
🔧 Maintenance
🐛 Bug Fixes
-
Improve standalone ApiRunner to properly apply settings (#13014) @gnodet
-
Strip executable() conditions from consumer POMs (#12960) @gnodet
-
Emit clear error when running JDK cannot compile source level (#12922) @gnodet
-
[mvnup] Add maven-war-plugin and maven-ear-plugin to plugin upgrade list (#12685) @gnodet
-
Fix #13191: add -Dmaven.maven3Personality hint to FATAL message for wrong parent relativePath (#13202) @gnodet
-
Fix #13200: publish a complete set from MavenProject.getArtifacts (#13203) @gnodet
-
Fix #13190: pre-build full reactor once using BUILD_PROJECT, drop temp dir in PluginUpgradeStrategy (#13197) @gnodet
-
Fix #13192: PomInlinerTransformer fails when CI-friendly property is defined in POM (#13195) @gnodet
-
Fix #13189: mvnup generates invalid JDK version constraint '(,-1]' (#13199) @gnodet
-
Fix mvnup compatibility: jar-plugin 3.4.2, exec-plugin submodule coverage, toolchain warning (#13179) @gnodet
-
Fixes #13135, ensure completude of the reactor summary but privilege failures to be last to stay human efficient (#13167) @gnodet
-
Fix glob patterns in exists()/missing() profile conditions on Windows (#13163) @gnodet
-
Fix #13084: sandbox profile activation context for external model builds (#13158) @gnodet
-
Fix: implement Node.getRepository() via local repository manager lookup (#13159) @gnodet
-
Fix #13100: honor repositories from legitimately-active external model profiles (#13155) @gnodet
-
[MNG-5146] - Fix parent relativePath mismatch check (#13157) @gnodet
-
Lower-case the OS family before matching it against the family names (#13154) @gnodet
-
Normalize lazy StAX parse failures in MavenXpp3Reader (#13149) @gnodet
-
Evaluate profile activation conditions lazily (#13144) @gnodet
-
[MNG-6979] - Initialize the current project from the execution root (#13143) @gnodet
-
Fix NPE on a recursive property reference in a list field (#13145) @gnodet
-
[MNG-6568] - Fix comparison cycles in version qualifiers (#13113) @gnodet
-
[MNG-8678] - Concurrent executor ignores java.lang.Error subclasses (#13067) @gnodet
-
Keep the basedir unset for a parent served from the project-local repository (#13212) @slachiewicz
-
Fix #13068: make PluginDependenciesResolver methods default (#13069) @ascheman
-
Fix filterByScope to expand lifecycle scopes for build ordering (#13070) @gnodet
-
Fix getDispatchedPaths() leaking mutable nested lists (#13057) @gnodet
-
[MNG-8174] - Fix NPE when a property references itself in a plugin configuration (#12935) @elharo
-
Fix #12985: Upgrade toolchains-plugin when adding select-jdk-toolchain execution (#13026) @gnodet
-
Fix ToolchainPluginStrategy to detect inherited source levels from parent POMs (#13025) @gnodet
-
Fix consumer POM leaving extension-contributed user properties uninterpolated (#13023) @gnodet
-
Fix #12986: Throw descriptive UnsupportedOperationException instead of NPE in MavenSession.lookup() (#13020) @gnodet
-
Fix #12989: mvnup plugin upgrades should respect project JDK version (#13024) @gnodet
-
[MNG-8633] - mvnup: inject standalone Nashorn for antrun JavaScript compatibility (#13022) @gnodet
-
mvnup: upgrade BND plugins to fix ConcurrentModificationException on JDK 17.0.13+ (#13021) @gnodet
-
[MNG-8765] - Pre-interpolate plugin configuration before type conversion (#13019) @gnodet
-
Fix #13004: enable deterministic profile activation for BUILD_CONSUMER (#13015) @gnodet
-
[MNG-8765] - Pre-interpolate plugin configuration before type conversion (#13017) @gnodet
-
Fix #12991: skip shade-plugin upgrade when custom ResourceTransformers are present (#13016) @gnodet
-
[MNG-12984] - Fix invalid Automatic-Module-Name entries in mvnup plugin upgrades (#13013) @gnodet
-
Fix compatibility spelling in CLI help text (#13012) @gnodet
-
[MNG-8708] - Fix parent inference (#13010) @gnodet
-
Scope server credentials and validate legacy relocation coordinates (#12977) @gnodet
-
Fix version comparison and parsing inconsistencies in maven-artifact (#12942) @slachiewicz
-
Validate metadata inputs across legacy and new API paths, clone proxies before decryption (#12945) @slachiewicz
-
[MNG-8450] - Report BOM import warnings only at declaration sites (#13003) @gnodet
-
[MNG-8287] - Fix consumer POM packaging profile resolution (#12967) @gnodet
-
Fix #12931: do not rewrite unmodified POMs in mvnup apply (#12972) @gnodet
-
Fix modello velocity phase for concurrent builder compatibility (#12963) @gnodet
-
Fix #12912: assign FastTerminal before starting the build thread (#12961) @gnodet
-
Fix #12774: skip consumer POM re-attachment on repeated task segments (#12916) @gnodet
-
Fix #12660: inherit version from imported BOM when local dep mgmt entry has no version (#12915) @gnodet
-
Fix #12912: use a dumb fallback terminal for all build-thread reentrant calls (#12921) @gnodet
-
Fix operator precedence skipping type=bom dependency imports (#12930) @gnodet
-
Fix: make ProjectIndex thread-safe for parallel builds (#12926) @gnodet
-
Fix #12602: Preserve Properties defaults in immutable copies (#12910) @goutamadwant
-
[MNG-8693] - Avoid resolving unused plugins for direct goals (#12920) @gnodet
-
Fix: interpolate properties in module/subproject path before filesystem resolution (#12924) @gnodet
-
Fix #12600: handle missing project index in forked executions (#12917) @gnodet
-
Re-include macOS JLine native libraries in distribution (#12888) @gnodet
-
Fix #2520: default maven.mainClass in Java instead of classworlds config (#12889) @gnodet
-
Fix #12646: project-local-repo clean race condition when root pom has parent (#12891) @GN...
Maven 4.0.0-rc-6
Notes
This new release candidate of Maven 4 is released to get feedback from users.
Maven 4 has restricted a few things compared to Maven 3, so make sure to run the mvnup tool before trying your project with Maven 4.
Issues fixed since RC-5
All known issues reported in the RC-5 release notes have been fixed:
- Bean configuration bug — field accessibility state was cached globally, causing plugin configuration injection failures. Fixed in #11433.
- Concurrency issue in the v4 API — a
ConcurrentModificationExceptionwas fixed in #11429. - BOM packaging — consumer POM conversion for BOM projects now correctly preserves dependency versions. Fixed in #11464.
- macOS Gatekeeper — the extracted JLine native binaries that triggered Gatekeeper have been removed from the distribution (#11997). The
xattrworkaround from RC-5 is no longer needed.
Known compatibility issues
The following are known compatibility issues when using Maven 4. Running
mvnup before building with
Maven 4 will fix many common plugin version issues automatically. The issues
below are those that require manual intervention or upstream fixes.
Stricter POM validation
Maven 4 enforces stricter validation than Maven 3. Projects may need to fix their POMs:
- Duplicate XML elements — duplicate
<artifactId>,<properties>, etc. are now rejected (Duplicated tagerror). Fix the source POM. - Duplicate dependency declarations — same
groupId:artifactIddeclared twice is now rejected (must be unique). - Uninterpolated expressions —
${...}expressions in repository URLs, distribution management IDs, and other fields that Maven 3 silently accepted are now rejected. - Invalid XML in transitive POMs — illegal processing instructions or undeclared namespace prefixes in transitive POMs cause
Non-parseable POMerrors. - Properties in
<module>paths — Maven 4 no longer interpolates properties like${spark.version}in<module>elements at POM reading time. - CI-friendly versions — projects using
${revision}withoutflatten-maven-pluginmay hit missing dependency version errors. - Invalid Collect Request — transitive dependencies with uninterpolated
${...}version expressions are rejected.
Transitive dependency resolution changes
Maven 4's TransitiveDependencyManager applies dependencyManagement at all transitive depths (Maven 3 only applied it at the first level). This is intentional but can change resolved versions:
- Dependencies previously on the classpath may disappear — add explicit declarations. See #12302.
maven-enforcer-pluginversion rules may trigger due to downgraded transitive versions.license-maven-pluginmay report new transitive dependencies not in the allow-list.- Karaf feature verification may fail due to OSGi bundle version mismatches.
Plugin and extension compatibility
Some plugins and extensions require specific versions for Maven 4:
- Quarkus — versions before 3.20 use
ServiceLocator/RepositorySystempatterns incompatible with Maven 4's Sisu-based DI. Upgrade to Quarkus 3.20+. - Tycho — versions before 5.0 use Guice/Sisu injection patterns broken by Maven 4. Upgrade to Tycho 5.0.3+.
- Develocity Maven extension — fails to initialize due to SLF4J classloading changes (
ClassNotFoundException: SimpleLogger). - pgpverify-maven-plugin — versions before 1.20 hit a
ClassCastExceptionwith Maven 4's resolver. See resolver#1957. - cyclonedx-maven-plugin — fails with
Invalid Version Range Requestwhen using${revision}CI-friendly versions. - maven-site-plugin — Velocity template rendering may fail with incompatible site plugin versions.
- maven-shade-plugin —
dependency-reduced-pom.xmlcan causeThe parents form a cycleerror. - commons-release-plugin —
clean-stagingfails under Maven 4.
Classloading changes
- Plugins relying on Maven 3's classrealm layout may encounter "foreign imports" errors (e.g., Quarkus, JAXB plugins).
- Maven 4's prefix-based repository routing may block artifacts not matching
/.meta/prefixes.txt.
Post-mvnup formatting
- spotless-maven-plugin and sortpom-maven-plugin may report formatting violations after
mvnupmodifies POM files. Re-run the formatter aftermvnup.
Other
- Broken upstream POMs — e.g.,
hadoop-project3.1.0–3.3.0 has invalid XML (<Xlint:-unchecked/>) causing parse errors. These need upstream fixes tracked in HADOOP-19923. - Enforcer POM element ordering — Maven 4's model builder reorders POM elements into a canonical order, which can break enforcer rules checking element ordering.
- SNAPSHOT handling — SNAPSHOT artifacts may show as "present, but unavailable" under Maven 4's different resolver metadata handling.
🚀 New features and improvements
- Backport the use of hardlink instead of file copy (#11564) @desruisseaux
- Accept Java module names as attached artifactId even if they differ from the project's artifactId (#11573) @desruisseaux
- Add module-aware resource handling for modular sources (#11700) @desruisseaux
- [MNG-8507] - Reduce allocation pressure in model building pipeline (#12540) @gnodet
- [Backport 4.0.x] Fix #12530: add mvnup upgrade strategies for Maven 4 known compatibility issues (#12560) @gnodet
- Introduce validation control (#12548) @cstamas
- Backport #12505: mvnup: widen exact Maven version pins to allow Maven 4 (#12508) @gnodet
- [MNG-5913] - Allow defining aliases for existing server configurations in settings.xml (#12473) @slawekjaranowski
- Backport #12454: mvnup upgrade strategies and compatibility improvements (#12467) @gnodet
- In failed build limit reactor summary to only failed modules (#12469) @slawekjaranowski
- [Backport 4.0.x] Add mvnup SourceStrategy for migrating to
elements (#12357) @gnodet - [Backport 4.0.x][#12353] Add jaxb2-maven-plugin to mvnup plugin upgrade list (#12356) @gnodet
- [Backport 4.0.x] Switch default resolver transport from JDK/methanol to Apache HttpClient (#12341) @gnodet
- Feat: Pull out maven-executor into its own project (#12004) (#12186) @cstamas
- [maven-4.0.x] Add maven-surefire-report-plugin to PluginUpgradeStrategy (#12114) @gnodet
- [maven-4.0.x] Fix #12087: add surefire and failsafe plugins to PluginUpgradeStrategy (#12109) @gnodet
- Backport: Maven Executor Fixes (#11987) @cstamas
- Promote java version in JavaToolchain (#11971) @slawekjaranowski
- Add time zone to Maven startup banner (#11781) @slawekjaranowski
- Update formatting of prerequisites-requirements error to improve readability (#11525) @slawekjaranowski
🐛 Bug Fixes
- Remove an optimization on PathSelector producing false negatives (#12623) @desruisseaux
- Remove erroneous path normalization optimization + regression test (#12621) @gnodet
- Fix #12583: Inverted file existence check in DefaultTransport.put() (#12619) @gnodet @elharo
- [MNG-8507] mvnup: skip dedup inside plugin
<configuration>elements (#12582) @gnodet - Fix BOM consumer POM leaving property references unresolved (#12627) @gnodet
- Use resource filtering for mng-12534 IT plugin mavenVersion to avoid hardcoded versions (58cb473) @gnodet
- [MNG-8425] Fix mvnenc init saving invalid master source configuration (#12564) @gnodet
- Consumer POM of multi-module project should exclude and elements (#11764) @desruisseaux
- Fix #12045: fix mvnup plugin upgrade strategy for inherited plugins from remote parent POMs (#12054) @gnodet
- Backport #12538: Handle Ctrl+C on Windows terminals (#12550) @gnodet
- [Backport 4.0.x] Fix #12531: filter NO_REPOSITORY sentinel from mapped exceptions in ArtifactResolverResult (#12561) @gnodet
- [Backport 4.0.x] Fix #12534: Wire up @after annotation processing in Maven core (#12566) @gnodet
- [Backport 4.0.x] Fix #12427: Reject path-traversal segments in coordinate ids and ...
3.10.0-rc-1
💥 Breaking changes
- Remove release-profile from super POM (#11999) @slawekjaranowski
- Remove deprecated plugin management from super POM (#11986) @slawekjaranowski
🚀 New features and improvements
- Feat: Align Maven 3.10.x and 4.0.x (#12442) @cstamas
- Feat: Align CP ordering with Maven 4 (#12327) @cstamas
- Feat: Apply latest Resolver 2.0.19 changes (#12246) @cstamas
- Feat: Maven 3.10.x super POM (#12032) @cstamas
- In failed build limit reactor summary to only failed modules (#11977) @slawekjaranowski
- Add time zone to Maven startup banner (#11972) @slawekjaranowski
- Feat: Version range filters plus (#11955) @cstamas
- Feat: Ability to disable site lifecycle (#11970) @cstamas
- Optimize log level rendering in MavenSimpleLogger (#11969) @slawekjaranowski
- Feat: Resolver 2.x update policy control via CLI (#11948) @cstamas
- Promote java version in JavaToolchain (#11968) @slawekjaranowski
- Feat: Transitive dep manager (#11939) @cstamas
- 3.10.x Upgrade slf4j to 2.0.17 (#11880) @olamy
- Do not force md download always (#11908) @cstamas
- Feat: user relocations backport (#11937) @cstamas
- Feat: Version range filtering (#11936) @cstamas
- Promote
project.rootDirectoryfor interpolation and profile activation (#11930) @slawekjaranowski - Feat: new artifact handler: fatjar (#11928) @cstamas
- Feat: migrate core to JSR330 (#11916) @cstamas
- Migrate from JAnsi to JLine, introduce MessageBuilderFactory (#11874) @slawekjaranowski
- Feat: Promote session.topDirectory and session.rootDirectory (#11779) @cstamas
- Feat: Maven 3.x with Resolver 2.x (#11778) @cstamas
- Feat: Generalize Maven 3.x extension handling (#11777) @cstamas
🐛 Bug Fixes
- [#12288] Backport: settings.xml activeByDefault profile props to LRM (#12333) @ascheman
- Fix illegal reflective access warning on JDK 11 (fixes #12167) (#12339) @gnodet
- Issue #12188 redirection of log output to a file does not redirect everything (#12189) @olamy
- Update binary distribution LICENSE with complete Apache License 2.0 text (#12063) @slawekjaranowski
- Bug: RSS was seeded but not exposed (#12033) @cstamas
- Export scope package from resolver-api 2.x (#12023) @slawekjaranowski
- Ensure
MavenProject#getPluginManagementnever returns null (#12010) @slawekjaranowski - Remove redundant required attributes from Settings model (#12005) @slawekjaranowski
- Remove redundant required attributes from Maven model (#11985) @slawekjaranowski
- Bug: Settings interpolation and strict parsing (#11776) @cstamas
- Trim
threadConfigurationto accept input surrounded with spaces (#11851) @pzygielo
📝 Documentation updates
- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#12444) @potiuk
- document default plugin versions (#12382) @hboutemy
- Maven 3.10.x site (#12370) @cstamas
- [[ISSUE-10329] - ](https://issues.apache.org/jira/browse/ISSUE-10329) - Document behaviour of UrlNormalizer (backport) (#12294) @gnodet
- Update Maven deps diagram for maven-jline (#12068) @Will-thom
- document the only supported value: 4.0.0 (#11859) @slawekjaranowski
👻 Maintenance
- push-to-atr profile for source+binaries in apache-maven subproject (#12450) @hboutemy
- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#12444) @potiuk
- Remove deprecated methods use (#12328) @cstamas
- Make def session builder have interface (#11967) @cstamas
- Feat: Add Automatic Module Names to Maven JAR Manifests (#11921) @cstamas
- Configure CI for 3.10.x branch (#11834) @slawekjaranowski
📦 Dependency updates
- Bump resolverVersion from 2.0.20-SNAPSHOT to 2.0.20 (#12426) @dependabot[bot]
- Bump jlineVersion from 3.30.14 to 3.30.15 (#12409) @dependabot[bot]
- Bump jlineVersion from 3.30.13 to 3.30.14 (#12400) @dependabot[bot]
- Bump org.apache.maven:maven-parent from 48 to 49 (#12399) @dependabot[bot]
- Bump actions/cache from 5.0.5 to 6.1.0 (#12362) @dependabot[bot]
- Bump actions/setup-java from 5.3.0 to 5.4.0 (#12374) @dependabot[bot]
- Bump version.sisu-maven-plugin from 1.0.0 to 1.0.1 (#12366) @dependabot[bot]
- Bump actions/checkout from 6.0.3 to 7.0.0 (#12321) @dependabot[bot]
- Bump actions/setup-java from 5.2.0 to 5.3.0 (#12283) @dependabot[bot]
- Bump xmlunitVersion from 2.11.0 to 2.12.0 (#12198) @dependabot[bot]
- Bump actions/checkout from 6.0.2 to 6.0.3 (#12212) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.10 to 9.10.1 (#12153) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (#12127) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.9.1 to 9.10 (#12060) @dependabot[bot]
- Deps: Resolver 2.0.18 and drop unused stuff (#12036) @cstamas
- Bump resolverVersion from 2.0.17 to 2.0.18 (#12104) @dependabot[bot]
- Deps: Bump Slf4j to 2.0.18 (#12048) @cstamas
- Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 (#12041) @dependabot[bot]
- [3.10.x] Bump to parent POM 48 (#12025) @cstamas
- Bump jlineVersion from 3.30.12 to 3.30.13 (#12013) @dependabot[bot]
- Bump jlineVersion from 3.30.11 to 3.30.12 (#12003) @dependabot[bot]
- Bump resolverVersion from 2.0.17-SNAPSHOT to 2.0.17 (#12008) @dependabot[bot]
- Bump jlineVersion from 3.30.9 to 3.30.11 (#11996) @dependabot[bot]
- Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#11982) @dependabot[bot]
- Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre (#11964) @dependabot[bot]
- Bump org.codehaus.modello:modello-maven-plugin from 2.6.0 to 2.7.0 (#11935) @dependabot[bot]
- Bump actions/cache from 5.0.4 to 5.0.5 ([#11946](https://gi...
3.9.16
🐛 Bug Fixes
- Trim
threadConfigurationto accept input surrounded with spaces (#12042) @slawekjaranowski - Backport: Maven 3.10.x fixed plugin resolution (#12022) @cstamas
📦 Dependency updates
- Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 (#12039) @dependabot[bot]
- [3.9.x] Bump to parent POM 48 (#12024) @cstamas
- Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#11980) @dependabot[bot]
- Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre (#11951) @dependabot[bot]
- Bump actions/cache from 5.0.4 to 5.0.5 (#11943) @dependabot[bot]
3.9.15
📝 Documentation updates
- Use new Maven logos in documentation (#11938) @slawekjaranowski
- document modelVersion only supported value: 4.0.0 (#11809) @hboutemy
📦 Dependency updates
- Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#11932) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 3.6.1 (#11876) @dependabot[bot]
- Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 (#11865) @dependabot[bot]
- Bump actions/cache from 5.0.3 to 5.0.4 (#11813) @dependabot[bot]
- Bump actions/download-artifact from 8.0.0 to 8.0.1 (#11790) @dependabot[bot]
3.9.14
🐛 Bug Fixes
- plexus-testing dependencies should be use in test scope (#11761) @slawekjaranowski
📦 Dependency updates
- Bump actions/upload-artifact from 6.0.0 to 7.0.0 (#11747) @dependabot[bot]
- Bump actions/download-artifact from 7.0.0 to 8.0.0 (#11748) @dependabot[bot]
3.9.13
🐛 Bug Fixes
- Bug: SecDispatcher is managed by legacy Plexus DI (#11711) @cstamas
- [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8 Java version in ranges as well (#11577) @cstamas
👻 Maintenance
- Update Maven plugin versions in default-bindings.xml (#11721) @slachiewicz
- Migrate to JUnit 5 - avoid using TestCase (#11547) @slawekjaranowski
📦 Dependency updates
- Maven Resolver 1.9.27 (#11732) @cstamas
- Bump resolverVersion from 1.9.25 to 1.9.26 (#11725) @dependabot[bot]
- Update Maven plugin versions in default-bindings.xml (#11721) @slachiewicz
- Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 (#11706) @dependabot[bot]
- Bump actions/cache from 5.0.2 to 5.0.3 (#11688) @dependabot[bot]
- Bump org.apache.maven:maven-parent from 45 to 47 (#11647) @dependabot[bot]
- Bump actions/checkout from 6.0.1 to 6.0.2 (#11666) @dependabot[bot]
- Bump actions/setup-java from 5.1.0 to 5.2.0 (#11667) @dependabot[bot]
- Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 (#11658) @dependabot[bot]
- Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.2.1 to 3.3.0 (#11657) @dependabot[bot]
- Bump actions/cache from 5.0.1 to 5.0.2 (#11659) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0 (#11620) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.9 to 9.9.1 (#11585) @slachiewicz
- Bump actions/upload-artifact from 5.0.0 to 6.0.0 (#11557) @dependabot[bot]
- Bump actions/download-artifact from 6.0.0 to 7.0.0 (#11556) @dependabot[bot]
- Bump actions/cache from 5.0.0 to 5.0.1 (#11558) @dependabot[bot]
3.9.12
🚀 New features and improvements
- [3.9.x] Apply resolver changes and improvements (#11536) @cstamas
- Update formatting of prerequisites-requirements error to improve readability (#11523) @slawekjaranowski
- Allow a Maven plugin to require a Java version (#11479) @slawekjaranowski
- Use MavenRepositorySystem in ProjectBuildingHelper instead of deprecated RepositorySystem (#11358) @slawekjaranowski
- Make maven.config use UTF8 (#11264) @cstamas
- Simplify prefix resolution (#11197) @slawekjaranowski
🐛 Bug Fixes
- Add default implementation for new method in MavenPluginManager (#11522) @slawekjaranowski
- Repository layout should be used in MavenRepositorySystem (#11495) @slawekjaranowski
- Fix plugin prefix resolution when metadata is not available from repository (#11290) @slawekjaranowski
- Improve source root modification warning message (#11105) @gnodet
- Bug: bad cache isolation between two sessions (#11082) @cstamas
- Set Guice class loading to CHILD - avoid using terminally deprecated methods (#11003) @slawekjaranowski
- Avoid parsing MAVEN_OPTS (3.9.x) (#10969) @BobVul
📝 Documentation updates
- clarify repository vs deployment repository (#11492) @hboutemy
- add maintained branches (#11448) @hboutemy
👻 Maintenance
- Add IntelliJ icon (#11408) @Bukama
- Build by JDK 25 (#11187) @slawekjaranowski
- Deprecate org.apache.maven.repository.RepositorySystem in 3.9.x (#11096) @slawekjaranowski
🔧 Build
- Bump actions/download-artifact from 5.0.0 to 6.0.0 (#11335) @dependabot[bot]
- Bump actions/upload-artifact from 4.6.2 to 5.0.0 (#11336) @dependabot[bot]
📦 Dependency updates
- Bump actions/cache from 4.3.0 to 5.0.0 (#11542) @dependabot[bot]
- Bump resolverVersion from 1.9.24 to 1.9.25 (#11533) @dependabot[bot]
- Bump actions/checkout from 6.0.0 to 6.0.1 (#11512) @dependabot[bot]
- Bump actions/setup-java from 5.0.0 to 5.1.0 (#11519) @dependabot[bot]
- Bump actions/checkout from 5.0.1 to 6.0.0 (#11476) @dependabot[bot]
- Bump actions/checkout from 5.0.0 to 5.0.1 (#11458) @dependabot[bot]
- Bump commons-cli:commons-cli from 1.10.0 to 1.11.0 (#11438) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-interpolation from 1.28 to 1.29 (#11416) @dependabot[bot]
- Bump commons-io:commons-io from 2.20.0 to 2.21.0 (#11417) @dependabot[bot]
- Bump xmlunitVersion from 2.10.4 to 2.11.0 (#11331) @dependabot[bot]
- Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 (#11231) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.8 to 9.9 (#11203) @dependabot[bot]
- Bump actions/cache from 4.2.4 to 4.3.0 (#11172) @dependabot[bot]
- Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre (#11143) @dependabot[bot]
- Bump xmlunitVersion from 2.10.3 to 2.10.4 (#11121) @dependabot[bot]
- Bump actions/cache from 4.2.3 to 4.2.4 (#11032) @dependabot[bot]
- Bump commons-cli:commons-cli from 1.9.0 to 1.10.0 (#11018) @dependabot[bot]
- Bump commons-io:commons-io from 2.19.0 to 2.20.0 (#10966) @dependabot[bot]
4.0.0-rc-5
Notes
This new release candidate of Maven 4 is released to get feedback from users.
Maven 4 has a restrained a few things comparent to Maven 3, so make sure to run the mvnup tool before trying to project with Maven 4.
Bean configuration bug
A bug has been found in the bean configuration system where field accessibility state is cached globally. This can cause plugin configuration injection to fail when the same configuration field is accessed multiple times or in different contexts during a build. This particularly affects the plugin unit tests.
This will be fixed by #11433 in the next release.
Concurrency issue in the v4 API
A concurrency issue has been found in the Maven 4 API (still in preview mode) and will be fixed by #11428 in the next release.
BOM packaging
Another bug has been found in how BOM projects are processed. When a project uses BOM packaging, the consumer POM is not being properly converted to standard POM packaging, and dependency versions could be lost in some cases.
This will be fixed by #11427 in the next release.
macOS: JLine native library may be blocked by Gatekeeper on first use
On macOS (especially Apple Silicon), the first invocation of mvn may fail to load the JLine native terminal library with an error such as:
java.lang.UnsatisfiedLinkError: .../libjline-native/Mac/arm64/libjlinenative.jnilib: dlopen(...): code signature ... not valid for use in process: library load disallowed by system policy
This occurs when the binary distribution is downloaded via a web browser, which applies the com.apple.quarantine extended attribute.
Workaround (one-time fix):
xattr -r -d com.apple.quarantine /path/to/apache-maven-4.0.0-rc-5/lib/jline-nativeRecommended download method (avoids the issue entirely):
curl -L -O https://archive.apache.org/dist/maven/maven-4/4.0.0-rc-5/binaries/apache-maven-4.0.0-rc-5-bin.tar.gz
tar -xzf apache-maven-4.0.0-rc-5-bin.tar.gzThis is a known issue #10747 and will be addressed in a future release.
💥 Breaking changes
🚀 New features and improvements
- Disable consumer POM flattening by default and add an opt-in feature (#11347) (#11370) @gnodet
- Make config files use UTF8 (#11263) (#11265) @cstamas
- Simplify prefix resolution (#11072) (#11073) @cstamas
- Add PathMatcherFactory.includesAll() (#11008) @desruisseaux
- Add skipMavenRc to ExecutorRequest and use it in ITs (#10944) @slawekjaranowski
- Add PathMatcherFactory service with directory filtering optimization (#10923) (#10926) @gnodet
- Allow configurable repository selection for version range resolution (backport) (#10890) @cstamas
- Switch resolver to use rwlock-local locks (#2546) (#2555) @gnodet
🐛 Bug Fixes
- Fix resource targetPath resolution to be relative to output directory (fixes #11381) (#11394) (#11406) @gnodet
- Fix MavenStaxReader location reporting for properties (#11402) (#11404) @gnodet
- Fix false parent cycle detection with flatten-maven-plugin (#11400) @gnodet
- Resolve property before model reflection to avoid recursion (#11385, fixes #11384) (#11390) @gnodet
- Explicitly register jdk ToolchainFactory for Maven 3 plugins (#11318) (#11369) @gnodet
- Fix -itr option not honored (#11359) (#11361) @gnodet
- Do not include invalid transitive repositories (#11357) (#11362) @gnodet
- Prevent infinite loop in RootLocator when .mvn directory exists in subdirectory (fixes #11321) (#11323) (#11350) @gnodet
- Fix [unknown project] messages in error output (#11324) (#11349) @gnodet
- Restore compatibility in maven-embedder (#11320) (#11340) @gnodet
- Add backward compatibility dependencies to maven-compat (#11301) (#11339) @gnodet
- Relative are resolved against the wrong directory (#11325) @desruisseaux
- Bug: when raw-streams are used, ensure system streams are set up (#11303) (#11310) @cstamas
- Fix plugin prefix resolution when metadata is not available from repository (#11287) (#11288) @gnodet
- Maven model 4.1.0 should not allow non-pom packaging for aggregators (#11279) (#11285) @gnodet
- Fix exception caused by duplicate dependencies in consumer pom (#11283) (#11286) @gnodet
- Remove use of toRealPath (#11250) (#11257) @cstamas
- Bugfix: fix CLI graceful death (#11239) (#11246) @cstamas
- Introduce RepositoryAwareRequest interface to consolidate repository handling (#11238) (#11244) @gnodet
- Fix repository ID interpolation in Maven 4 (#11224) (#11241) @gnodet
- Fix dependency groupId inference for Maven 4.1.0 model version (#11228) (#11240) @gnodet
- Consumer POM should keep only transitive dependencies, fixes #11162 (#11163) (#11235) @gnodet
- Fix StackOverflowError in parent POM resolution (backport #11106) (#11234) @gnodet
- Fix CI-friendly version processing with profile properties (fix #11196) (#11225) @gnodet
- Add phase upgrade support for Maven 4.1.0 model upgrades (#11226) @gnodet
- Fix GH-11199: Maven 4.0.0-rc-4 ignores defaultLogLevel (#11227) @gnodet
- Validate metaversions and detect extension conflicts (fixes #11181) (#11216) @cstamas
- Allow repository URL interpolation with improved validation (#11140) (#11210) @gnodet
- Improve mvn usage message (#11211) (#11213) @gnodet
- Enable the search for
module-info.classfile in theMETA-INF/versions/sub-directories of a JAR file. (#11153) (#11206) @gnodet - Fix #10939: DefaultModelXmlFactory: make location tracking opt-in—disabled by def… (#11092) @arturobernalg
- Fix #11000: fix help default text (#11099) @arturobernalg
- GH-10210: fix too eager decrypt of legacy passwords (#11138) (#11158) @cstamas
- #11055: Inject all services into mojos and enable easy real-session mojo testing (#11103) (#11139) @gnodet
- Fix ReactorReader to prefer consumer POMs over build POMs (#11107) (#11131) @gnodet
- model-builder: simplify subproject auto-discovery decision (#11124) (#11132) @gnodet
- Add missing equals and hashCode methods in modular Java path type. (#11130) @desruisseaux
- fix: include extension in equals/hashCode of DefaultArtifactCoordinates (#11101) @arturobernalg
- Fix #11127: enforce non-null keys for InputLocation lookups and document behavior (#11128) @gnodet
- Bug: bad cache isolation between two sessions (#11083) (#11085) @cstamas
- Fix targetPath parameter ignored in resource bundles (fixes #11062) (#11063) (#11080) @gnodet
- Maven Upgrade Tool: remove unused --force and --yes options (Fixes #11001) (#11066) (#11079) @gnodet
- Fix XMLReader#getURL and enable the unit test (#11069) (#11078) @gnodet
- [#11048] Fix race condition in MessageUtils (#11049) (#11077) @gnodet
- Uninterpolated repositories from parent POMs during model building (backport) (#11039) @cstamas
- Fix maven.mainClass property missing for external tools (#10998) (#11007) @gnodet
- Set Guice class loading to CHILD - avoid using terminally deprecated methods (#11002) @slawekjaranowski
- Avoid parsing MAVEN_OPTS (master/4.x) (#10970) (#10993) @gnodet
- Port the bug fixes identified when using that class in Maven clean and compiler plugin (#10935) ([#10936](https:...