{"id":50897886,"url":"https://github.com/siom79/japicmp","last_synced_at":"2026-07-22T07:01:19.935Z","repository":{"id":10897662,"uuid":"13191344","full_name":"siom79/japicmp","owner":"siom79","description":"Comparison of two versions of a jar archive","archived":false,"fork":false,"pushed_at":"2026-05-21T19:16:56.000Z","size":12905,"stargazers_count":769,"open_issues_count":70,"forks_count":114,"subscribers_count":24,"default_branch":"master","last_synced_at":"2026-05-22T02:50:24.279Z","etag":null,"topics":["api-documentation","api-management","change-management","change-tracker","comparison","java"],"latest_commit_sha":null,"homepage":"https://siom79.github.io/japicmp","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/siom79.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2013-09-29T11:28:08.000Z","updated_at":"2026-05-21T19:17:17.000Z","dependencies_parsed_at":"2023-02-18T04:01:18.414Z","dependency_job_id":"e86083b0-de3f-402d-9d57-a478740d1558","html_url":"https://github.com/siom79/japicmp","commit_stats":null,"previous_names":[],"tags_count":80,"template":false,"template_full_name":null,"purl":"pkg:github/siom79/japicmp","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/siom79%2Fjapicmp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/siom79%2Fjapicmp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/siom79%2Fjapicmp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/siom79%2Fjapicmp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/siom79","download_url":"https://codeload.github.com/siom79/japicmp/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/siom79%2Fjapicmp/sbom","scorecard":{"id":827459,"data":{"date":"2025-08-11","repo":{"name":"github.com/siom79/japicmp","commit":"4a09354a3b107c92d570c592a8839182a0158f10"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":1,"reason":"Found 2/12 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/github-release.yml:13","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/github-release.yml:1","Warn: no topLevel permission defined: .github/workflows/mvn-site.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-release.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/github-release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/github-release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/github-release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mvn-site.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/mvn-site.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mvn-site.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/mvn-site.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/siom79/japicmp/release.yml/master?enable=pin","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":3,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'master'","Info: 'force pushes' disabled on branch 'master'","Info: 'branch protection settings apply to administrators' is required to merge on branch 'master'","Warn: 'stale review dismissal' is disabled on branch 'master'","Warn: branch 'master' does not require approvers","Warn: codeowners review is not required on branch 'master'","Warn: 'last push approval' is disabled on branch 'master'","Warn: no status checks found to merge onto branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 24 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T16:53:58.370Z","repository_id":10897662,"created_at":"2025-08-23T16:53:58.371Z","updated_at":"2025-08-23T16:53:58.371Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35751644,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-22T02:00:06.236Z","response_time":124,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api-documentation","api-management","change-management","change-tracker","comparison","java"],"created_at":"2026-06-16T01:31:30.084Z","updated_at":"2026-07-22T07:01:19.929Z","avatar_url":"https://github.com/siom79.png","language":"Java","funding_links":["https://www.buymeacoffee.com/mmois"],"categories":["java"],"sub_categories":[],"readme":"![japicmp](src/site/resources/images/japicmp.png)\n\nThe website is located at [https://siom79.github.io/japicmp](https://siom79.github.io/japicmp/).\n\njapicmp is a tool to compare two versions of a jar archive:\n``` bash\njava -jar japicmp-.0-jar-with-dependencies.jar -n new-version.jar -o old-version.jar\n```\nIt can also be used as a library:\n```java\nJarArchiveComparatorOptions comparatorOptions = new JarArchiveComparatorOptions();\nJarArchiveComparator jarArchiveComparator = new JarArchiveComparator(comparatorOptions);\nList\u003cJApiClass\u003e jApiClasses = jarArchiveComparator.compare(oldArchives, newArchives);\n```\njapicmp is available in the Maven Central Repository:\n[![maven](https://img.shields.io/maven-central/v/com.github.siom79.japicmp/japicmp.svg)](https://central.sonatype.com/artifact/com.github.siom79.japicmp/japicmp)\n``` xml\n\u003cdependency\u003e\n\t\u003cgroupId\u003ecom.github.siom79.japicmp\u003c/groupId\u003e\n\t\u003cartifactId\u003ejapicmp\u003c/artifactId\u003e\n\t\u003cversion\u003e0.26.1\u003c/version\u003e\n\u003c/dependency\u003e\n```\nA maven plugin allows you to integrate the checks into your build:\n\n``` xml\n\u003cplugin\u003e\n\t\u003cgroupId\u003ecom.github.siom79.japicmp\u003c/groupId\u003e\n\t\u003cartifactId\u003ejapicmp-maven-plugin\u003c/artifactId\u003e\n\t\u003cversion\u003e0.26.1\u003c/version\u003e\n\t\u003cconfiguration\u003e\n\t\t\u003coldVersion\u003e\n\t\t\t\u003cdependency\u003e\n\t\t\t\t\u003cgroupId\u003ejapicmp\u003c/groupId\u003e\n\t\t\t\t\u003cartifactId\u003ejapicmp-test-v1\u003c/artifactId\u003e\n\t\t\t\t\u003cversion\u003e${oldversion}\u003c/version\u003e\n\t\t\t\t\u003ctype\u003ejar\u003c/type\u003e\n\t\t\t\u003c/dependency\u003e\n\t\t\u003c/oldVersion\u003e\n\t\t\u003cnewVersion\u003e\n\t\t\t\u003cfile\u003e\n\t\t\t\t\u003cpath\u003e${project.build.directory}/${project.artifactId}-${project.version}.${project.packaging}\u003c/path\u003e\n\t\t\t\u003c/file\u003e\n\t\t\u003c/newVersion\u003e\n\t\t\u003cparameter\u003e\n\t\t\t\u003c!-- see documentation --\u003e\n\t\t\u003c/parameter\u003e\n\t\u003c/configuration\u003e\n\t\u003cexecutions\u003e\n\t\t\u003cexecution\u003e\n\t\t\t\u003cphase\u003everify\u003c/phase\u003e\n\t\t\t\u003cgoals\u003e\n\t\t\t\t\u003cgoal\u003ecmp\u003c/goal\u003e\n\t\t\t\u003c/goals\u003e\n\t\t\u003c/execution\u003e\n\t\u003c/executions\u003e\n\u003c/plugin\u003e\n```\n\nA Sonar Qube plugin integrates the results from the japicmp analysis into your code quality report: [sonar-japicmp-plugin](https://github.com/siom79/sonar-japicmp-plugin).\n\nBy using the available Ant task, you can also integrate japicmp into your Ant build files:\n\n``` xml\n\u003ctaskdef resource=\"japicmp/ant/antlib.xml\" classpathref=\"task.classpath\"/\u003e\n\u003cjapicmp oldjar=\"${project.build.directory}/guava-18.0.jar\"\n\t newjar=\"${project.build.directory}/guava-19.0.jar\"\n\t oldclasspathref=\"old.classpath\"\n\t newclasspathref=\"new.classpath\"\n\t onlybinaryincompatiblemodifications=\"false\"\n\t onlyModifications=\"true\"\n\t /\u003e\n```\n\n[melix](https://github.com/melix) has developed a [gradle plugin](https://github.com/melix/japicmp-gradle-plugin) for japicmp.\n\n## Online-Version\n\nThere is an online version of japicmp that lets you compare two artifacts from the maven central repository\nwithout installing the tool first. Just click [this](https://www.japicmp.de) link and give it a try.\n\n![japicmp-online](doc/japicmp_online.png)\n\n## MCP-Server\n\nThe [japicmp MCP server](https://github.com/siom79/japicmp-mcp-server) exposes japicmp's API comparison capabilities as\na tool for AI assistants that support the [Model Context Protocol (MCP)](https://modelcontextprotocol.io).\nIt allows AI agents such as Claude to compare two versions of a Maven artifact directly from a conversation — resolving\nboth JARs from Maven Central and returning a structured Markdown compatibility report, including binary and source\ncompatibility status, a semantic versioning verdict, and a detailed diff of every changed class, method, constructor,\nand field.\n\n## Motivation\n\nEvery time you release a new version of a library or a product, you have to tell your clients or customers what\nhas changed in comparison to the last release. Without the appropriate tooling, this task is tedious and error-prone.\nThis tool/library helps you to determine the differences between the java class files that are contained in two given\njar archives.\n\nThis library does not use the Java Reflection API to compute the differences, as the usage of the Reflection API makes\nit necessary to include all classes the jar archive under investigation depends on are available on the classpath.\nTo prevent the inclusion of all dependencies, which can be a lot of work for bigger applications, this library makes\nuse of the [javassist](https://www.javassist.org/) library to inspect the class files.\nThis way you only have to provide the two jar archives on the command line (and eventually libraries that contain\nclasses/interfaces you have extended/implemented).\n\nThis approach also detects changes in instrumented and generated classes. You can even evaluate changes in class file attributes (like synthetic) or annotations.\nThe comparison of annotations makes this approach suitable for annotation-based APIs like JAXB, JPA, JAX-RS, etc.\n\n\nThe goal of this project is to provide a fast and easy to use API comparison for Java. Therefore it does not aim\nto integrate change tracking of other types of artifacts (configuration files, etc.) as a generic implementation means\nto make compromises in terms of performance and ease of usage. japicmp for example compares two archives with about 1700 classes each\nin less than one second and therewith can be easily integrated in each build.\n\n## Features\n\n* Comparison of two jar archives without the need to add all of their dependencies to the classpath.\n* Differences are printed on the command line in a simple diff format.\n* Differences can optionally be printed as [Markdown](https://www.markdownguide.org/), XML or HTML file.\n* Per default private and package protected classes and class members are not compared. If necessary, the access modifier of the classes and class members to be\n  compared can be set to public, protected, package or private.\n* Per default all classes are tracked. If necessary, certain packages, classes, methods or fields can be excluded or explicitly included. Inclusion and exclusion is also possible based on annotations.\n* All changes between all classes/methods/fields are compared. japicmp differentiates between source and binary compatible changes (as described in the [Java Language Specification](http://docs.oracle.com/javase/specs/jls/se7/html/jls-13.html) and the [OpenJDK-Wiki](https://wiki.openjdk.org/spaces/csr/pages/32342052/Kinds+of+Compatibility)).\n* All changes between annotations are compared, hence japicmp can be used to track annotation-based APIs like JAXB, JPA, JAX-RS, etc.\n* A maven plugin is available that allows you to compare the current artifact version with some older version from the repository.\n* The option `--semantic-versioning` tells you which part of the version you have to increment in order to follow [semantic versioning](http://semver.org/).\n* If a class is serializable, changes are evaluated regarding the [Java Object Serialization Specification](http://docs.oracle.com/javase/7/docs/platform/serialization/spec/serialTOC.html).\n* Per default synthetic classes and class members (e.g. [bridge methods](https://docs.oracle.com/javase/tutorial/java/generics/bridgeMethods.html)) are hidden. They can be listed by using the option `--include-synthetic`.\n* The maven plugin allows project-specific filtering and reports using a custom [Groovy](https://groovy-lang.org/) script.\n\n## Downloads\n\nYou can download the latest version from the [release page](https://github.com/siom79/japicmp/releases) or directly from the [maven central repository](http://search.maven.org/#search%7Cga%7C1%7Ca%3A%22japicmp%22).\n\n## Buy me a coffee\n\nIf you like japicmp and would like to do me a favor for all the work I've done over\nthe years, please consider buying me a coffee [here](https://www.buymeacoffee.com/mmois).\n\n\u003ca href=\"https://www.buymeacoffee.com/mmois\" target=\"_blank\"\u003e\u003cimg src=\"https://cdn.buymeacoffee.com/buttons/default-orange.png\" alt=\"Buy Me A Coffee\" height=\"41\" width=\"174\"\u003e\u003c/a\u003e\n\n# Development\n\n## Reports\n\nUse the maven site plugin (`mvn site`) to generate the following reports:\n * findbugs\n * checkstyle\n * japicmp\n\n## Release\n\nThis is the release procedure:\n* Create a branch named release-v0.XX.X\n* Update ReleaseNotes.md.\n* If necessary: Set the release version in maven using [this Action](https://github.com/siom79/japicmp/actions/workflows/mvn-set-version.yml) on the release branch\n* Increment version in README.md / Site-Report by running [this Action](https://github.com/siom79/japicmp/actions/workflows/increment-version.yml) on the release branch\n* Run release [Action](https://github.com/siom79/japicmp/actions/workflows/release.yml)\n* Login to [Central repository](https://central.sonatype.com/publishing)\n\t* Download released artifact from staging repository.\n\t* Close and release staging repository if sanity checks are successful.\n* Update maven site report with [Action](https://github.com/siom79/japicmp/actions/workflows/mvn-site.yml) on the release branch\n* Run Github Release [Action](https://github.com/siom79/japicmp/actions/workflows/gh-release.yml) on the tag\n* Merge release branch into master\n\nIf the release fails, the version must be reverted and the tag created during the release has to be deleted:\n```bash\nmvn versions:set -DnewVersion=\u003cnew-version\u003e-SNAPSHOT\nmvn versions:commit\ngit push\ngit push --delete origin japicmp-base-\u003cnew-version\u003e\n```\nAfterward, the release action can be executed again.\n\n## Contributions\n\nPull requests are welcome, but please follow these rules:\n\n* The basic editor settings (indentation, newline, etc.) are described in the `.editorconfig` file (see [EditorConfig](http://editorconfig.org/)).\n* Provide a unit test for every change.\n* Name classes/methods/fields expressively.\n* Fork the repo and create a pull request (see [GitHub Flow](https://guides.github.com/introduction/flow/index.html)).\n\n## Website\n\nThe website can be generated by running this github [Action](https://github.com/siom79/japicmp/actions/workflows/mvn-site.yml)\non the tag.\n\nIt uses the [maven-scm-publish-plugin](https://maven.apache.org/plugins/maven-scm-publish-plugin/index.html) to\ngenerate the site report and push it to the [gh-pages](https://github.com/siom79/japicmp/tree/gh-pages) branch.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsiom79%2Fjapicmp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsiom79%2Fjapicmp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsiom79%2Fjapicmp/lists"}