Enforcing JDK Version and Dependency Convergence with the Maven Enforcer Plugin
Learn how to configure the Maven Enforcer Plugin to fail builds when the JDK is too old or when dependencies appear in multiple versions, ensuring a stable and reproducible build.
07 Oct 2025, 16:56 UTC

Desired outcome
Configure a Maven project so that the build aborts if any of the following occurs:
- The JDK used to run Maven is older than a specified minimum version.
- Two or more different versions of the same dependency appear in the effective classpath.
This prevents subtle runtime class‑path conflicts and guarantees that developers and CI agents use a supported Java release.
Prerequisites
- Maven 3.6.0 or newer installed and available on
PATH. - A Maven project with a
pom.xmlfile that you can edit (write access required). - Network access to Maven Central to download the Enforcer plugin (version 3.0.0 or later).
Procedure
- Open the project’s
pom.xmlin a text editor. - Locate the
<build>section. If it does not contain a<plugins>element, add one. - Add an execution of the Maven Enforcer Plugin bound to the
verifylifecycle phase (or any phase that runs after dependency resolution, e.g.,install). - Inside the plugin configuration, define two rules:
<requireJavaVersion>and<dependencyConvergence>. - Save the file and commit the change if you use version control.
<build>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-enforcer-plugin</artifactId>
<version>3.0.0</version>
<executions>
<execution>
<id>enforce-java-and-deps</id>
<phase>verify</phase>
<goals>
<goal>enforce</goal>
</goals>
<configuration>
<rules>
<requireJavaVersion>
<version>11</version>
</requireJavaVersion>
<dependencyConvergence/>
</rules>
<fail>true</fail>
</configuration>
</execution>
</executions>
</plugin>
</plugins>
</build>
Expected checks
When you run a build that includes the verify phase (e.g., mvn clean install or mvn verify), the Enforcer plugin will:
- Print an informational line showing the required Java version, e.g.,
[INFO] Required Java version is 11. - If the running JDK is older than the specified version, the build fails with a message like
[ERROR] Failed while enforcing requireJavaVersion: Required Java version is 11 but you are using 1.8.0_292. - If any artifact appears with multiple versions, the failure message includes
[ERROR] Failed while enforcing dependencyConvergence: Found multiple versions of org.apache.commons:commons-lang3 in the dependency tree.
When both rules are satisfied, the build proceeds normally and you will see the plugin execution reported as successful:
[INFO] --- maven-enforcer-plugin:3.0.0:enforce (enforce-java-and-deps) @ my-project --- [INFO] All enforcer rules passed.
Recovery options
If the build fails because of a JDK version mismatch:
- Ensure the desired JDK is installed.
- Set
JAVA_HOMEto point to that JDK, or configure a Maven toolchain in~/.m2/toolchains.xml. - Re‑run the build.
If the failure is due to dependency convergence:
- Inspect the dependency tree:
mvn dependency:tree -Dverbose. - Locate the artifact reported as conflicting.
- Align the versions by adding a
<dependencyManagement>section (or updating existing declarations) to force a single version. - Alternatively, exclude the unwanted transitive version with an
<exclusion>in the offending dependency. - Re‑run the build.
Limitations
- The Enforcer plugin only evaluates its rules when bound to a lifecycle phase. If you omit the
<execution>or bind it to a phase that never runs (e.g.,none), the rules are silently ignored, giving a false sense of safety. - Versions of the plugin prior to 3.0.0 use a different XML schema for rules. Using an older version with the configuration shown above will cause a parse error and halt the build.
- The plugin checks the JDK version used to launch Maven, not the
targetorsourcelevels set in themaven-compiler-plugin. Ensure both are aligned if you need to enforce a specific language level.
Verification
- Confirm Maven version:
mvn -v. The output should showApache Maven 3.6.0or higher. - Run a clean build:
mvn clean install. Observe that the build succeeds and the Enforcer log lines appear. - To test the JDK rule, temporarily set
JAVA_HOMEto a JDK older than the version specified in the plugin (e.g., JDK 8 when the rule requires 11) and re‑runmvn verify. The build should fail with a requireJavaVersion error. - To test dependency convergence, add a direct dependency that forces an older version of a library already present elsewhere (e.g., add
<dependency><groupId>org.apache.commons</groupId><artifactId>commons-lang3</artifactId><version>3.5</version></dependency>while another dependency pulls in 3.13). Runmvn verifyand expect a dependencyConvergence failure. - After each test, revert the change (reset
JAVA_HOMEor remove the offending dependency) and confirm the build passes again.
Rollback
Adding the Enforcer plugin modifies the pom.xml. To roll back:
- Remove the entire
<plugin>block formaven-enforcer-plugin(or comment it out). - Save the file and commit if using version control.
- Run
mvn clean installto verify the build proceeds without the enforcement step.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.