Open Ingredients
|
maven-jar-plugin3.4.2
Classifier: LIBRARYSource
Security state
Critical 0High 0Medium 0Low 0Unassigned 0
Vulnerable components0
Inherited Risk Score0.0
Last BOM importMar 1, 2026, 12:24 AM
Last vulnerability analysisMay 8, 2026, 2:15 PM
Draft

What this plugin is

The Maven JAR Plugin assembles a project's compiled classes and resources into a `.jar` archive during the Maven `package` phase. It populates the `META-INF/MANIFEST.MF` with the entries downstream tooling — module descriptors, classpath, multi-release flag — relies on.

Why it matters

The output of this plugin is what ends up on Maven Central and in production classpaths. Manifests, multi-release JAR layout, and reproducible-build flags all flow through here. A misconfigured release of this plugin is a supply-chain hazard.

Open Elements' role

Open Elements contributes to the Maven JAR Plugin under the Support & Care programme and surfaces its security state via Open Ingredients.

Components
Outdated only
ComponentVersionLicenseStatusSeverities
maven-repository-metadata3.6.3Apache-2.0outdated
maven-resolver-api1.4.1Apache-2.0outdated
maven-resolver-impl1.4.1Apache-2.0outdated
maven-resolver-provider3.6.3Apache-2.0outdated
maven-resolver-spi1.4.1Apache-2.0outdated
maven-resolver-util1.4.1Apache-2.0outdated
maven-settings3.6.3Apache-2.0outdated
maven-settings-builder3.6.3Apache-2.0outdated
maven-shared-utils3.2.1Apache-2.0outdated
org.eclipse.sisu.inject0.9.0.M2EPL-1.0outdated
org.eclipse.sisu.plexus0.9.0.M2EPL-1.0outdated
plexus-archiver4.9.2Apache-2.0outdated
plexus-cipher1.4Apache-2.0outdated
plexus-classworlds2.6.0Apache-2.0outdated
plexus-component-annotations2.1.0Apache-2.0outdated
plexus-interpolation1.27Apache-2.0outdated
plexus-io3.4.2Apache-2.0outdated
plexus-sec-dispatcher1.4Apache-2.0
plexus-utils4.0.1Apache-2.0outdated
slf4j-api1.7.36MIToutdated
snappy0.4Apache-2.0outdated
xz1.9outdated
zstd-jni1.5.5-11BSD-2-Clauseoutdated

No findings match the current filter.

Download SBOM

CycloneDX 1.x. Re-generated server-side; no registration required.

Talk to Support & Care