PrepZone Logo
PrepZone

Starters and the BOM

Curated dependency bundles and how the Spring Boot BOM keeps versions aligned.

Why this matters

  • Starters are how Boot keeps BookStore dependencies aligned — one starter, zero version numbers.
  • The BOM (Bill of Materials) pins compatible versions across the entire Spring ecosystem.
  • Choosing the wrong starter (web vs webflux) shapes your entire application architecture.

How starters work

A starter POM contains only dependencies — no application code:

Java
<!-- spring-boot-starter-web internally depends on: -->
<!-- spring-boot-starter, spring-boot-starter-json, -->
<!-- spring-boot-starter-tomcat, spring-web, spring-webmvc -->

Your BookStore pom.xml declares intent:

Java
<dependencies>
  <dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
  </dependency>
  <dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-data-jpa</artifactId>
  </dependency>
  <dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-validation</artifactId>
  </dependency>
</dependencies>

No version tags — the parent BOM supplies them.

spring-boot-starter-web
spring-boot-starterCore Boot + logging
spring-webmvcControllers and REST
tomcat-embed-coreEmbedded server
jackson-databindJSON serialisation
spring-boot-starter-web pulls in Tomcat, Jackson, Spring MVC and more with tested versions.

Starters BookStore uses

  • spring-boot-starter-web — Tomcat, Spring MVC, Jackson JSON.
  • spring-boot-starter-data-jpa — Hibernate, Spring Data JPA, JDBC, connection pool.
  • spring-boot-starter-validation — Hibernate Validator for @Valid on DTOs.
  • spring-boot-starter-security — Spring Security filter chain.
  • spring-boot-starter-test — JUnit 5, Mockito, AssertJ, MockMvc.

The Spring Boot BOM

spring-boot-starter-parent imports spring-boot-dependencies — a BOM listing every managed version:

Java
<parent>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-parent</artifactId>
  <version>3.4.1</version>
</parent>

Override a single version when needed:

Java
<properties>
  <flyway.version>10.4.0</flyway.version>
</properties>

The property name matches the BOM key. Avoid overriding Spring Framework versions — mismatches cause runtime NoSuchMethodError.

Starter naming convention

PatternMeaning
spring-boot-starter-{name}Official Boot starters
spring-boot-starter-{name}-testTest slice for a technology
{group}-spring-boot-starterThird-party starters (e.g. springdoc)
  • spring-boot-starter-{name}

    MeaningOfficial Boot starters
  • spring-boot-starter-{name}-test

    MeaningTest slice for a technology
  • {group}-spring-boot-starter

    MeaningThird-party starters (e.g. springdoc)

Third-party starters follow the same auto-config pattern but are not in the BOM — check their docs for compatible Boot versions.

Inspecting transitive dependencies

Java
./mvnw dependency:tree -Dincludes=org.hibernate

Shows exactly which starter pulled in Hibernate and at what version. Use this when resolving conflicts.

Test starter scope

Java
<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-test</artifactId>
  <scope>test</scope>
</dependency>

Test-scoped dependencies never appear in the production JAR. They include:

Common test dependencies

  • JUnit Jupiter
  • Mockito
  • AssertJ
  • Spring Test (@SpringBootTest, MockMvc)
  • JSONassert

Optional: spring-boot-starter-actuator

Java
<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-actuator</artifactId>
</dependency>

Adds /actuator/health and /actuator/metrics — essential for production BookStore deployments. Covered in the observability module.

Version alignment in multi-module builds

Parent POM for a BookStore monorepo:

Java
<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>org.springframework.boot</groupId>
      <artifactId>spring-boot-dependencies</artifactId>
      <version>3.4.1</version>
      <type>pom</type>
      <scope>import</scope>
    </dependency>
  </dependencies>
</dependencyManagement>

Child modules inherit versions without using spring-boot-starter-parent as their direct parent.

Quick recall

Everything you need if you only revisit this box.

  • Starters bundle related dependencies; you declare capability, not individual JARs.
  • spring-boot-starter-parent imports the BOM that pins all managed versions.
  • Never specify versions for BOM-managed dependencies unless overriding deliberately.
  • spring-boot-starter-test is test-scoped and includes JUnit, Mockito, and MockMvc.
  • Use dependency:tree to trace which starter pulled in a conflicting library.
  • Do not mix web and webflux starters without a deliberate architectural reason.

Test yourself

Answer these before moving on — recall is what makes it stick.