After installing the plugin to your local repository (mvn install), you can use the simplified commands:
# Simple analysis with default settings
mvn capslock:analyze
# Analyze with all features enabled
mvn capslock:analyze -Dcapslock.includeTest=true -Dcapslock.showTree=true -Dcapslock.fetchOptionalMetadata=trueThe plugin prefix capslock allows you to use short commands instead of the full plugin coordinates:
| Short Command | Full Command |
|---|---|
mvn capslock:analyze |
mvn com.github.serj:mvn-capslock:1.0-SNAPSHOT:analyze |
JCapsLock can analyze optional dependencies that projects declare but don't automatically include:
# Analyze optional dependencies in the dependency tree
mvn capslock:analyze -Dcapslock.includeOptional=true# Discover and analyze optional dependencies from POM files
# This finds optional dependencies not in your dependency tree
mvn capslock:analyze -Dcapslock.fetchOptionalMetadata=truemvn capslock:analyze \
-Dcapslock.includeTest=true \
-Dcapslock.includeOptional=true \
-Dcapslock.fetchOptionalMetadata=true \
-Dcapslock.showTree=true \
-Dcapslock.verbose=truemvn capslock:analyze -Dcapslock.package=org.apache.commons:commons-compressmvn capslock:analyze \
-Dcapslock.format=json \
-Dcapslock.outputFile=capabilities.json# Show all capabilities including test and optional dependencies
mvn capslock:analyze \
-Dcapslock.includeTest=true \
-Dcapslock.fetchOptionalMetadata=true \
-Dcapslock.verbose=true \
-Dcapslock.outputFile=security-audit.txt| Parameter | Property | Default | Description |
|---|---|---|---|
format |
capslock.format |
text |
Output format: text, json, sarif |
verbose |
capslock.verbose |
false |
Show detailed capability usage |
includeSafe |
capslock.includeSafe |
false |
Include CAPABILITY_SAFE in output |
includeOptional |
capslock.includeOptional |
true |
Analyze optional dependencies |
includeTest |
capslock.includeTest |
false |
Analyze test scope dependencies |
fetchOptionalMetadata |
capslock.fetchOptionalMetadata |
false |
Discover optional deps from POMs |
showTree |
capslock.showTree |
true |
Display dependency tree structure |
package |
capslock.package |
- | Specific package to analyze |
outputFile |
capslock.outputFile |
- | Output file path |
skip |
capslock.skip |
false |
Skip analysis |
Optional dependencies are dependencies that a library declares as "optional" in its POM. They are not automatically included in your project but may be needed for certain features.
- Security: Optional dependencies might be pulled in at runtime
- Compliance: Need to know all possible capabilities
- Feature Discovery: Understand what capabilities are available with optional features
If a library has optional compression support:
<dependency>
<groupId>org.apache.commons</groupId>
<artifactId>commons-compress</artifactId>
<optional>true</optional>
</dependency>With fetchOptionalMetadata=true, JCapsLock will:
- Detect this optional dependency from the POM
- Analyze its capabilities
- Mark them as "optional" in the report
- First Run: Start with basic
mvn capslock:analyzeto see direct dependencies - Deep Dive: Add
-Dcapslock.fetchOptionalMetadata=trueto discover optional capabilities - CI/CD: Use
-Dcapslock.format=sariffor integration with security tools - Debugging: Use
-Dcapslock.verbose=trueto see detailed call chains