Open Ingredients
|
maven-jar-plugin3.4.2
Classifier: LIBRARYSource
Security state
Critical 0High 0Medium 0Low 0Unassigned 0
Vulnerable components0
Inherited Risk Score0.0
Last BOM importMar 1, 2026, 12:24 AM
Last vulnerability analysisMay 8, 2026, 1:15 PM
Draft

What this plugin is

The Maven JAR Plugin assembles a project's compiled classes and resources into a `.jar` archive during the Maven `package` phase. It populates the `META-INF/MANIFEST.MF` with the entries downstream tooling — module descriptors, classpath, multi-release flag — relies on.

Why it matters

The output of this plugin is what ends up on Maven Central and in production classpaths. Manifests, multi-release JAR layout, and reproducible-build flags all flow through here. A misconfigured release of this plugin is a supply-chain hazard.

Open Elements' role

Open Elements contributes to the Maven JAR Plugin under the Support & Care programme and surfaces its security state via Open Ingredients.

Components
Outdated only
ComponentVersionLicenseStatusSeverities
aopalliance1.0
cdi-api1.2Apache-2.0outdated
checker-qual3.33.0MIToutdated
commons-codec1.16.1Apache-2.0outdated
commons-compress1.26.1Apache-2.0outdated
commons-io2.16.1Apache-2.0outdated
commons-lang33.8.1Apache-2.0outdated
error_prone_annotations2.18.0Apache-2.0outdated
failureaccess1.0.1Apache-2.0outdated
file-management3.1.0Apache-2.0outdated
guava32.0.1-jreApache-2.0outdated
guice4.2.1Apache-2.0outdated
j2objc-annotations2.8Apache-2.0outdated
javax.annotation-api1.2outdated
javax.inject1Apache-2.0
jsr3053.0.2Apache-2.0
listenablefuture9999.0-empty-to-avoid-conflict-with-guavaApache-2.0
maven-archiver3.6.2Apache-2.0outdated
maven-artifact3.6.3Apache-2.0outdated
maven-builder-support3.6.3Apache-2.0outdated
maven-core3.6.3Apache-2.0outdated
maven-model3.6.3Apache-2.0outdated
maven-model-builder3.6.3Apache-2.0outdated
maven-plugin-annotations3.12.0Apache-2.0outdated
maven-plugin-api3.6.3Apache-2.0outdated

No findings match the current filter.

Download SBOM

CycloneDX 1.x. Re-generated server-side; no registration required.

Talk to Support & Care