Open Ingredients
|
maven-compiler-plugin3.13.0
Classifier: LIBRARYSource
Security state
Critical 0High 0Medium 0Low 0Unassigned 0
Vulnerable components0
Inherited Risk Score0.0
Last BOM importMar 1, 2026, 12:22 AM
Last vulnerability analysisMay 8, 2026, 2:15 PM
Draft

What this plugin is

The Maven Compiler Plugin is the standard plugin Maven uses to compile Java sources. It wires the JDK compiler into the Maven lifecycle and exposes the options every Java team relies on — target Java release, annotation processors, module path handling, and incremental compilation.

Why it matters

Every Maven-built Java artifact passes through this plugin. A defect or regression here changes the bytecode that ships to production for thousands of downstream projects on the same day a new release is published.

Open Elements' role

Open Elements contributes to the Maven Compiler Plugin through the Support & Care programme — security response, releases, and maintenance — and tracks its security posture publicly through Open Ingredients.

Components
Outdated only
ComponentVersionLicenseStatusSeverities
maven-resolver-provider3.6.3Apache-2.0outdated
maven-resolver-spi1.4.1Apache-2.0outdated
maven-resolver-util1.4.1Apache-2.0outdated
maven-settings3.6.3Apache-2.0outdated
maven-settings-builder3.6.3Apache-2.0outdated
maven-shared-incremental1.1Apache-2.0
maven-shared-utils3.4.2Apache-2.0
org.eclipse.sisu.inject0.9.0.M2EPL-1.0outdated
org.eclipse.sisu.plexus0.9.0.M2EPL-1.0outdated
plexus-cipher1.4Apache-2.0outdated
plexus-classworlds2.6.0Apache-2.0outdated
plexus-compiler-api2.15.0Apache-2.0outdated
plexus-compiler-javac2.15.0Apache-2.0outdated
plexus-compiler-manager2.15.0Apache-2.0outdated
plexus-component-annotations2.1.0Apache-2.0outdated
plexus-interpolation1.25Apache-2.0outdated
plexus-java1.2.0Apache-2.0outdated
plexus-sec-dispatcher1.4Apache-2.0
plexus-utils4.0.0Apache-2.0outdated
plexus-xml3.0.0Apache-2.0outdated
qdox2.0.3Apache-2.0outdated
slf4j-api1.7.36MIToutdated

No findings match the current filter.

Download SBOM

CycloneDX 1.x. Re-generated server-side; no registration required.

Talk to Support & Care