{"id":50897856,"url":"https://github.com/Ekryd/sortpom","last_synced_at":"2026-07-22T07:01:16.361Z","repository":{"id":28695758,"uuid":"32216000","full_name":"Ekryd/sortpom","owner":"Ekryd","description":"Maven plugin that helps the user sort pom.xml. ","archived":false,"fork":false,"pushed_at":"2026-07-21T04:52:00.000Z","size":3245,"stargazers_count":366,"open_issues_count":2,"forks_count":214,"subscribers_count":9,"default_branch":"master","last_synced_at":"2026-07-21T06:19:18.261Z","etag":null,"topics":["hacktoberfest","maven","maven-plugin","pom","sort","sortpom-plugin","xml"],"latest_commit_sha":null,"homepage":"https://github.com/Ekryd/sortpom/wiki/","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Ekryd.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE.md","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":["Ekryd"],"custom":["https://www.paypal.com/cgi-bin/webscr?cmd=_donations\u0026business=JB25X84DDG5JW\u0026lc=SE\u0026item_name=Encourage%20the%20development\u0026item_number=sortpom\u0026currency_code=EUR\u0026bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted"]}},"created_at":"2015-03-14T14:32:22.000Z","updated_at":"2026-07-21T04:52:04.000Z","dependencies_parsed_at":"2023-10-21T11:02:32.342Z","dependency_job_id":"78248fd9-750d-4a97-988f-f237930867ed","html_url":"https://github.com/Ekryd/sortpom","commit_stats":null,"previous_names":[],"tags_count":29,"template":false,"template_full_name":null,"purl":"pkg:github/Ekryd/sortpom","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekryd%2Fsortpom","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekryd%2Fsortpom/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekryd%2Fsortpom/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekryd%2Fsortpom/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Ekryd","download_url":"https://codeload.github.com/Ekryd/sortpom/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekryd%2Fsortpom/sbom","scorecard":{"id":44802,"data":{"date":"2025-08-11","repo":{"name":"github.com/Ekryd/sortpom","commit":"01251e6ae6a4f9b5e5cc73a4a0ce97c4c3bc6c97"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.1,"checks":[{"name":"Maintained","score":10,"reason":"28 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/26 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build-maven4.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/build.yml:15","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-maven4.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/build-maven4.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-maven4.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/build-maven4.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/Ekryd/sortpom/codeql-analysis.yml/master?enable=pin","Info:   2 out of   8 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (4) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-14T22:29:08.743Z","repository_id":28695758,"created_at":"2025-08-14T22:29:08.743Z","updated_at":"2025-08-14T22:29:08.743Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35751644,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-22T02:00:06.236Z","response_time":124,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hacktoberfest","maven","maven-plugin","pom","sort","sortpom-plugin","xml"],"created_at":"2026-06-16T01:31:30.083Z","updated_at":"2026-07-22T07:01:16.354Z","avatar_url":"https://github.com/Ekryd.png","language":"Java","funding_links":["https://github.com/sponsors/Ekryd","https://www.paypal.com/cgi-bin/webscr?cmd=_donations\u0026business=JB25X84DDG5JW\u0026lc=SE\u0026item_name=Encourage%20the%20development\u0026item_number=sortpom\u0026currency_code=EUR\u0026bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted"],"categories":["hacktoberfest"],"sub_categories":[],"readme":"# Hibernation\n\nDear SortPom users,\n\nThis project is entering hibernation. I do not have any plans to actively add features to the plugin, but if you have any vulnerabilities or major bugs to report, please do so. No, I do not plan to accept pull requests for new features.\n\nI have maintained this project for 17 years, and I no longer feel the same joy working on it. It has become another chore rather than something I enjoy.\n\nYou are always free to clone the repository and add the features you need yourself.\n\n# Sortpom Maven Plugin ![Icon](https://raw.githubusercontent.com/Ekryd/sortpom/master/misc/Sortpom.png)\n\n[![Build Status](https://circleci.com/gh/Ekryd/sortpom.svg?style=svg)](https://app.circleci.com/pipelines/github/Ekryd/sortpom)\n[![Coverage Status](https://coveralls.io/repos/github/Ekryd/sortpom/badge.svg?branch=master)](https://coveralls.io/github/Ekryd/sortpom?branch=master)\n[![Maven Central Version](https://img.shields.io/maven-central/v/com.github.ekryd.sortpom/sortpom-maven-plugin)](https://mvnrepository.com/artifact/com.github.ekryd.sortpom/sortpom-maven-plugin)\n[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=com.github.ekryd.sortpom%3Asortpom-parent\u0026metric=alert_status)](https://sonarcloud.io/dashboard?id=com.github.ekryd.sortpom%3Asortpom-parent)\n[![Licence](https://img.shields.io/github/license/Ekryd/sortpom?color=success)](https://github.com/Ekryd/sortpom/blob/master/LICENSE.md)\n[![Known Vulnerabilities](https://snyk.io/test/github/Ekryd/sortpom/badge.svg)](https://snyk.io/test/github/Ekryd/sortpom)\n\nMaven plugin that helps the user sort pom.xml by formatting the XML and organizing XML sections in a predefined order. \nThe main advantages to have standardized sorted poms are that they become more readable and that comparisons between different module poms becomes much easier.\n\n## Goals Overview ##\nThe SortPom Plugin has two goals.\n\n  * **mvn sortpom:sort** sorts the current pom.xml file. This goal will always sort the pom.xml file.\n\n  * **mvn sortpom:verify** only sorts the current pom.xml file if the xml elements are unsorted. This goal ignores text formatting (such as indentation and line breaks) when it verifies if the pom is sorted or not.\n\n![Icon](https://raw.githubusercontent.com/Ekryd/sortpom/master/misc/sortpom.jpg)\n\n## Usage ##\n\nThe Sortpom plugin will reorder the pom elements and format the xml structure in the pom-file. The plugin can be [configured](https://github.com/Ekryd/sortpom/wiki/Parameters) to sort by different standards or by a custom format. A backup file will be created by default, so that you can check how the pom-file has changed.\n\nSortpom works best if it is run every time during Maven compilation. [Configure](https://github.com/Ekryd/sortpom/wiki/Parameters) it once and then forget about it. Replace the plugin version with the latest one:\n```xml\n\u003cbuild\u003e\n  \u003cplugins\u003e\n    \u003cplugin\u003e\n      \u003cgroupId\u003ecom.github.ekryd.sortpom\u003c/groupId\u003e\n      \u003cartifactId\u003esortpom-maven-plugin\u003c/artifactId\u003e\n      \u003cversion\u003e4.0.0\u003c/version\u003e\n      \u003cexecutions\u003e\n        \u003cexecution\u003e\n          \u003cgoals\u003e\n            \u003cgoal\u003esort\u003c/goal\u003e\n          \u003c/goals\u003e\n        \u003c/execution\u003e\n      \u003c/executions\u003e\n    \u003c/plugin\u003e\n    ...\n  \u003c/plugins\u003e\n\u003c/build\u003e\n```\n\nIf you just want to perform a simple test what the plugin does then open a command prompt in your project home and enter\n```\nmvn com.github.ekryd.sortpom:sortpom-maven-plugin:4.0.0:sort -Dsort.predefinedSortOrder=custom_1\n```\n\nDetailed example of how the plugin can be configured to run every time you build your project; see [recommended configuration](https://github.com/Ekryd/sortpom/wiki/Recommended-configuration) wiki page\n\nThe plugin will not change how your Maven project is compiled  ([Exception](https://github.com/Ekryd/sortpom/wiki/Parameters-that-can-affect-your-build))\n\n## News ##\nAdded \n  * 2024-05-19: Released version 4.0.0. **THIS IS A BREAKING CHANGE!** Indentation for attributes are now 2 * indent size [#413](/../../issues/413), and the parameter `indentSchemaLocation` has been deprecated in favor of `indentAttribute`. [#412](/../../issues/412).\n  * 2024-03-10: Released version 3.4.1. Solves a bug, where whitespace was removed even if `xml:space=\"preserve\"` was used [#402](/../../issues/402).\n  * 2024-02-20: Released version 3.4.0. Added parameter for omitting newline at end of file [#399](/../../issues/399).\n  * 2023-08-04: Received an [Open Source Licence](https://jb.gg/OpenSourceSupport) for IntelliJ Ultimate. Once again, thank you [JetBrains](http://www.jetbrains.com/idea/)!!\n  * 2023-07-24: Released version 3.3.0. Added parameter for quiet output from the plugin [#338](/../../issues/338). Thanks, [gnodet](https://github.com/gnodet) for the PR!\n  * 2023-01-29: Released version 3.2.1. Dependency updates. No new functionality\n  * 2022-07-17: Released version 3.2.0. Added parameter `sortDependencyManagement` where dependency management can be sorted independently of dependencies [#210](/../../issues/210). Thanks, [Ssquan](https://github.com/ssquan) for the PR!\n  * 2022-05-29: Released version 3.1.3. Fix formatting if text and other content is placed together in a xml tag [#209](/../../issues/209)\n  * 2022-05-22: Released version 3.1.0. **THIS IS A BREAKING CHANGE!** Dropped support for Java 8. Updated underlying xml framework due to vulnerabilities. Updated other libraries and plugins. \n  * 2021-04-20: Released version 3.0.0. **THIS IS A BREAKING CHANGE!** The predefined sort order is now according to the recommended pom order (as decided in 2008). Blank lines in the POM are now kept by default. If dependencies are sorted by SCOPE, then imported bom-files will be sorted towards the top. [#93](/../../issues/93) [#105](/../../issues/105)\n  * 2020-02-24: Renewed Open Source Licence for Araxis Merge. Thank you [Araxis](https://www.araxis.com/merge/)!\n  * 2015-03-31: Moved the SortPom plugin to GitHub.\n\n## Versions ##\nhttps://github.com/Ekryd/sortpom/wiki/Versions\n\n## Plugin parameters ##\nhttps://github.com/Ekryd/sortpom/wiki/Parameters\n\n## Download ##\nThe plugin is hosted i [Maven Central](http://mvnrepository.com/artifact/com.github.ekryd.sortpom/sortpom-maven-plugin) and will be downloaded automatically if you include it as a plugin in your pom file.\n\n## Donations ##\nIf you use it, then please consider some encouragement. ⭐️ Star it in GitHub!  \n\n[![](https://www.paypalobjects.com/en_US/i/btn/btn_donateCC_LG.gif)](https://www.paypal.com/cgi-bin/webscr?cmd=_donations\u0026business=JB25X84DDG5JW\u0026lc=SE\u0026item_name=Encourage%20the%20development\u0026item_number=sortpom\u0026currency_code=EUR\u0026bn=PP%2dDonationsBF%3abtn_donateCC_LG%2egif%3aNonHosted)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FEkryd%2Fsortpom","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FEkryd%2Fsortpom","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FEkryd%2Fsortpom/lists"}