Monthly Updates
A transparent look at our monthly work on Apache Maven
JUNE 2026
LatestDependency vulnerability monitoring, Maven Artifact plugin buildinfo work, Surefire and 3.10.0 prep, first atr-maven-plugin release, and Getting Started docs
Security of the Supply Chain
- Improve dependency vulnerability monitoring for the Apache Maven project familySecurity
- Analyze Maven Artifact plugin to make improvements for buildinfo generation and build comparisonImprovement
- Remove deprecated deployment feature for buildinfo files from Maven Artifact pluginMaintenance
Maintenance
- Fixing issues of new Surefire mode using JUnit Platform onlyBug Fix
- Preparing release 3.10.0Maintenance
- Preparing for upgrade of Release Drafter from 6.x to 7.xMaintenance
Modernization of Core Features
- Working on atr-maven-plugin to support the release process with ATR (Apache Trusted Releases) service; first release of the pluginFeature
- Migration of JUnit 3 based tests that use AbstractMojoTestCase to JUnit 5 in Maven Changelog pluginImprovement
Documentation
- Authoring Getting Started documentationDocs
- Starting a writing guide for documentation in generalDocs
MAY 2026
Progress on Maven 3.10.0 release train, CycloneDX and buildinfo improvements, ATR release tooling, and Getting Started documentation
Security of the Supply Chain
- Improve on CycloneDX 1.7 ECMA specification implementation for JavaSecurity
Maintenance
- Release train for 3.10.0 has been started with backporting features from 4.x branchMaintenance
- Testing and fixing of the 3.10.0 release trainMaintenance
- Check and fix ASF maintained Maven plugins with 3.10.0Maintenance
- Release Maven 3.9.16 with bug fixesBug Fix
Modernization of Core Features
- Tool to automate the local release process for Apache MavenImprovement
- Working on atr-maven-plugin to support the release process with ATR (Apache Trusted Releases) serviceFeature
Documentation
- Draw up suggestion for "Getting Started" contentDocs
- Draw up conception for learning pathsDocs
- Getting Started docs content initializedDocs
- Extensive reviews of first two "Getting Started" PRsDocs
APRIL 2026
Focus on security supply-chain improvements, Maven 3.10.0 preparation and starting better tooling support for Apache Maven internal release process
Security of the Supply Chain
- Improve on cyclonedx 1.7 ECMA specification inconsistencies with OWASPSecurity
Maintenance
- Prepare for Maven 3.10.0 ReleaseMaintenance
Modernization of Core Features
- Starting a tool to automate partially release process/stepsImprovement
- Update documentation for Surefire 3.6Docs
Documentation
- Initialize the documentation tooling for 'Getting Started' DocumentationDocs
MARCH 2026
Major progress on supply chain security with CycloneDX 1.7 validation, Maven 3.10.0 release preparation, and JUnit 5 migration.
Security of the Supply Chain
Maintenance
- Prepare for Maven 3.10.0 ReleaseMaintenance
Modernization of Core Features
- Update architecture documentation for Surefire 3.6: add information about the new unified testing providerDocs
Documentation
- Researched and evaluated documentation platforms and toolsDocs
FEBRUARY 2026
Surefire JUnit Platform PR merged, documentation and bug fixing in Initializer for Apache Maven
Modernization of Core Features
- Surefire JUnit Platform PR merged — unified testing provider now availableFeature
Documentation
- Create documentation about architecture of Initializer for Apache MavenDocs
JANUARY 2026
Starting 'Getting Started' Documentation, Finalising migration Maven Surefire Plugin to JUnit Platform, Announce Initializer for Apache Maven
Security of the Supply Chain
Modernization of Core Features
- Finalising Refactoring of surefire plugin to use only the Junit Platform to run tests for junit3,4,5,6 and TestNG.Maintenance
- Start creating Architecture Documentation and Blog Posts about Java Module support in Maven 4Docs
Documentation
- Kick off Meeting for 'Getting started' documentationDocs