Load: view .claude/skills/maven-dependency-audit/SKILL.md
Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Uses standard Maven plugins - no additional tooling required.
- "Check for outdated dependencies"
- "Audit dependencies before release"
- "Find security vulnerabilities in pom.xml"
- "Why is commons-logging in my project?"
> view .claude/skills/maven-dependency-audit/SKILL.md
> "Audit dependencies for pf4j"
→ Runs checks, categorizes updates by severity, generates report
| Tool | Purpose |
|---|---|
mvn versions:display-dependency-updates |
Find outdated dependencies |
mvn dependency:tree |
Analyze dependency graph |
mvn dependency:analyze |
Find unused dependencies |
mvn dependency-check:check |
Security vulnerability scan (OWASP) |
- Run monthly or before each release
- Patch updates are usually safe; major updates need review
- Use
-Dincludes=groupIdto filter large dependency trees - Consider enabling GitHub Dependabot for automated alerts