Foojay Podcast #50: JCON Report, Part 2 - Maven, Software Security, Code Quality

A broken build pipeline or a sneaky transitive dependency can derail a Java project for days. The talks at JCON kept coming back to the same question. How do we keep our code readable, our dependencies safe, and our releases boring? In this second part of our JCON report, we sit down with Karl Heinz Marbaise, Steve Poole, Miro Wengner, Marit van Dijk, and Hinse ter Schuur for Foojay Podcast #50.

What we talked about

  • Apache Maven 4, Sonatype, and the Maven Repository
  • Software supply chain security and SBOMs across JVM languages
  • Disciplined engineering as a daily practice
  • Reading code with IntelliJ IDEA and the AI Assistant
  • Sustainable development through code reviews and merge requests

What stood out

The guests treat code quality as a team habit, not a tool. They show how Maven 4, SBOM tooling, and good review culture solve the same problem from different angles. Each guest gives one concrete change you can apply to your next pull request.

See the Foojay Podcast #50 for all info, shownotes, links, etc.