This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: Features: Bug Fixes: NEXUS-49805 – The login screen no longer displays the instructions for resetting the initial admin password after it has already been reset. NEXUS-49789 – Importing a previously exported Raw hosted repository on Windows now correctly preserves the original directory structure instead of merging it into the asset name. NEXUS-49742 – Staging move operations on PostgreSQL now perform faster and clean up empty browse nodes more efficiently. NEXUS-49718 – UI load times have been improved for users with a large number of assigned privileges by optimizing how permissions are calculated and checked during login. NEXUS-49714 – Tag-based searches and staging move operations in High Availability environments now correctly handle tag names in a case-insensitive manner. NEXUS-49613 – Component searches in High Availability environments now return only exact matches when no wildcards are used. NEXUS-49566 – R proxy repositories now support SHA256 content-addressable package archives. NEXUS-49472 – The UI now allows uploading assets to directory paths that include uppercase letters. NEXUS-49424 – The Verify and Repair Data Consistency task now accurately reports elapsed time in logs. NEXUS-49369 – The frontend REST API now returns only active Nexus modules. NEXUS-49226 – Refreshing a task log using the UI refresh icon now correctly loads the log without triggering a 404 error. NEXUS-49156 – The Repositories page now displays the Size column as long as at least one repository format has completed the blob size copy task. NEXUS-49142 – The login process now uses a dynamic timeout based on UI settings. NEXUS-49069 – Uptime log entries once again include Nexus version information. NEXUS-48982 – Concurrent requests to the same asset across High Availability nodes no longer result in errors. NEXUS-48739 – npm proxy repositories now correctly update package metadata when a cached package is deleted locally. NEXUS-48504 – The Search API now correctly returns blobCreated and blobStoreName values for assets. NEXUS-48393 – Cleanup policies using regex patterns with quantifiers now produce consistent and accurate results between preview and execution. NEXUS-47174 – Compact Blob Store tasks can now run concurrently across different blob stores. NEXUS-46878 – Removed default memory-related JAVA_OPTS values from the Docker image. NEXUS-46839 – Helm hosted repositories now correctly block redeployment of .prov files when the disable redeploy policy is enabled. NEXUS-46163 – Repository target privileges migrated from Nexus Repository 2 are correctly transformed and visible in the Roles UI. NEXUS-45941 – The REST API for creating Maven group repositories now correctly honors the specified versionPolicy. NEXUS-45291 – Yum group repository logs now include the specific member repository name when an ETag is missing. NEXUS-45234 – Repository content selector privileges created via the REST API with the ALL action are now correctly displayed in the UI with all actions selected. NEXUS-44316 – Search API requests that previously failed with a 500 error due to orphaned records in the search_components table are now handled gracefully. An upgrade task removes these invalid entries to restore search functionality without manual intervention. NEXUS-41564 – Docker Garbage Collection task logs now include more detailed information about deleted and retained assets. NEXUS-40516 – UI searches performed by non-admin users now correctly display and navigate to the expected components and assets within group repositories. NEXUS-36868 – Helm proxy repositories now correctly preserve string values like appVersion from index.yaml. NEXUS-31898 – Warnings caused by expected BypassHttpErrorException conditions during Docker proxy operations are now logged at the DEBUG level instead of WARN. NEXUS-26593 – The Docker - Delete incomplete uploads task no longer logs unnecessary WARN messages when encountering already soft-deleted blobs. NEXUS-25286 – Nexus Repository now starts successfully even if a Docker repository is configured to use the same port as the main application connector.
| December 17, 2025 | 3.88.0 January 13, 2026 |
Maintenance release | December 10, 2025 | 3.88.0 January 13, 2026 |
This self-hosted patch release fixes multiple bugs impacting Nexus Repository 3.87.0 deployments that use Azure blob stores. Known Issue in Sonatype Nexus Repository 3.87.1 Sonatype is aware of an issue impacting Sonatype Nexus Repository 3.87.1 High Availability (HA) deployments that use group blob stores created using the REST API. After upgrading, the Blob Stores page can fail to load, and errors are logged during startup. If you are using Nexus Repository in an HA configuration and have configured group blob stores via API, we recommend delaying your upgrade to 3.87.1 until a fix is available. | N/A | 3.87.1 (December 8, 2025) |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: Features: Introduced a new GET /v1/capabilities/types API endpoint to retrieve metadata about available capability types. (self-hosted only) Added wo new properties (nexus.security.password.iterations and nexus.security.secrets.iterations) that allow administrators to configure the number of PBKDF2 iterations used when encrypting user passwords and sensitive secrets like API keys and tokens.
Bug Fixes: NEXUS-49653 – Authenticated users accessing the /saml endpoint are now redirected to the welcome page instead of receiving a blank page, restoring expected behavior for bookmarked SAML entry points. NEXUS-49606 – Search queries to the /v1/search/assets API now return correct results for group IDs containing uppercase letters in non-HA environments. NEXUS-49458 – Added a new composite index on to significantly improve query performance and reduce database CPU usage during frequent component lookups. NEXUS-49225 – Helm chart uploads now correctly extract the chart name and version from the Chart.yaml file inside the .tgz package, ensuring charts are indexed and retrievable even when the uploaded filename does not match the metadata. NEXUS-49134 – License information is now correctly extracted from the License-Expression field in PyPI packages using Metadata-Version 2.4, ensuring accurate license display for Python components retrieved through proxy repositories. NEXUS-49114 – R proxy repositories now correctly respect the metadataMaxAge setting by using the appropriate cache controller for metadata assets, ensuring timely refresh of files like PACKAGES without requiring manual cache invalidation. NEXUS-49041 – LDAP group searches are now capped to a configurable maximum number of results. By default, this limit is set at 1,000 results. Administrators of self-hosted deployments can change the LDAP group search result limit by updating the nexus.ldap.groupSearchLimit property in the $data-dir/sonatype-work/nexus3/etc/nexus.properties. NEXUS-48893 & NEXUS-49913 – Yum repositories with a deploy-once policy now correctly treat RPMs with the same name and version but different architectures as separate components, allowing uploads of multiple architecture variants without conflict. NEXUS-48680 – Containerd clients can now successfully push to Docker repositories with path-based routing enabled, as Nexus Repository correctly handles token authentication requests in this configuration. NEXUS-48567 – Password and secret hashing iteration counts are now configurable via system properties. NEXUS-48460 & NEXUS-40930 – Cleanup Policy Preview now correctly handles regular expressions containing special characters. NEXUS-48329 – The Total Size reported for Azure blob stores now accurately reflects actual storage usage. NEXUS-48260 – Content selector expressions using negative patterns now correctly enforce permissions during download and browse actions. NEXUS-48245 – YUM group repositories now support .zst-compressed metadata files. NEXUS-48163 – The index.yaml file in hosted Helm repositories now consistently appears as a file instead of a folder in the UI. NEXUS-48088 – Cargo proxy repositories now correctly honor all specified settings when created via API. NEXUS-47508 – Conan package versions that include pre-release tags now display correctly in the browse tree. NEXUS-46700 – The /beta/system/information API endpoint is only accessible in Nexus Repository Pro. NEXUS-46107 – Maven group repositories now automatically clean up orphaned metadata assets and browse nodes when member repositories are removed. NEXUS-44903 – Only one Docker garbage collection task can run at a time on a repository. NEXUS-44812 – Hosted R repositories now correctly generate the required PACKAGES index file, ensuring full compatibility with tools like Azur. NEXUS-43967 – The User Token Cleanup task now deletes only expired tokens from the User-Token-Realm. NEXUS-43821 – The Compact Blob Store task now gracefully handles 404 errors returned by Azure during deletion, treating them as warnings instead of failures. NEXUS-35061 – Support zips generated on PostgreSQL and H2 now correctly include the key_store_data table.
| December 3, 2025 | 3.88.0 January 13, 2026 |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: Features: Bug Fixes: NEXUS-49753 – Repository permission checks now defer evaluation of content selectors using the path variable to the asset level, restoring search and tag operations that failed after upgrading to 3.86.0 - 3.86.2. NEXUS-49331 – Export assets tasks now correctly export npm packages from hosted and proxy repositories by properly registering the required filter component, ensuring assets are written without directory structure errors. NEXUS-49536 – Cleanup policies using both Retain criteria and Asset Name Matcher now correctly process all matching components, even in large component sets that exceed the batch limit, for both preview and actual cleanup execution. NEXUS-48987 – In high availability environments, concurrent requests to download the same artifact from different nodes now succeed reliably. NEXUS-48851 – S3 blob store secrets containing special characters are now correctly handled during upgrade. NEXUS-48839 – Bearer token URLs for anonymous Docker pulls no longer include the repository path, preventing 400 errors when using certain reverse proxy configurations. NEXUS-48160 – Task-specific log files are now preserved when deploying via Helm charts, improving troubleshooting by maintaining separate logs per task type while still supporting the combined allTasks.log output for Kubernetes environments. NEXUS-48087 – Repository deletions now complete successfully even when group cleanup operations encounter issues; affected groups are logged for review. NEXUS-47905 – The archetype-catalog.xml file is now automatically updated after deploying new SNAPSHOT base versions of Maven archetypes, eliminating the need to manually delete the file to reflect recent changes. NEXUS-47551 – Outbound requests for scoped npm packages now correctly encode slashes, ensuring compatibility with strict registries and restoring support for scoped package installs in environments that require encoded URLs. NEXUS-46876 – Group npm repositories now support a configurable TTL for metadata caching, ensuring package metadata stays up to date and preventing stale data from blocking access to valid package versions. NEXUS-46707 – The licensing UI now displays a more accurate message when updating a license, clarifying that a restart is only required if installing a license for the first time. NEXUS-45478 – Disabled capabilities can now be edited and saved successfully, eliminating the need to delete and recreate them to update settings. NEXUS-43689 – Creating LDAP server connections via the Swagger UI now works as expected. NEXUS-43675 – Temporary files generated during Docker content validation are now properly managed to prevent uncontrolled disk usage in the tmp directory. NEXUS-36481 – Docker group repository searches now handle invalid responses from member proxy repositories more gracefully.
| November 26, 2025 | 3.87.0 (December 2, 2025) and 3.88.0 (January 13, 2026) |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: A new Configuration API provides endpoints to export and import Nexus Repository configuration and to retrieve or migrate asset metadata between instances. See the Configuration API help documentation. New, modernized login experience for all Nexus Repository editions. Bug Fixes: NEXUS-49474 – Firewall for Docker scans work as expected when using Sonatype IQ Server 196 or earlier. NEXUS-49470 – Improved Docker request performance by removing a circular dependency and eliminating a concurrency bottleneck in role and privilege processing. NEXUS-49379 – Ensured the default-features value in Cargo manifests defaults to true and updated attribute names to align with Cargo documentation. NEXUS-49331 – The Repository Export assets task now correctly exports npm packages from both hosted and proxy repositories. NEXUS-49200 – You can no longer accidentally create blob stores with invalid names via the API. NEXUS-49171 – APT repository metadata is now properly updated in both the source and target hosted repositories after performing a component move via the REST API. NEXUS-49154 – Refactored schema management to ensure all database changes are handled through Flyway migrations, preventing startup delays and outages caused by schema modifications under load. NEXUS-48542 – New login experience properly handles deep links. NEXUS-48505 – Corrected the Components API response to include the appropriate blob store name instead of returning null. NEXUS-47926 – Improved the asset export task to gracefully handle missing blobs by skipping over them and logging warnings, allowing the export to complete successfully even if some blobs are unavailable. NEXUS-47826 – Improved reliability of the rolling upgrade process by preventing timeouts during schema changes from leaving the system in a failed or partially upgraded state. NEXUS-47148 – Added validation for Composer package distribution types to prevent errors when processing certain upstream package metadata. NEXUS-46560 – Improved session timeout handling in the Usage Center. NEXUS-42345 – Added a global configuration option to control URL escaping behavior for proxy repositories. Details are included in the Configuring the Runtime Environment help documentation. NEXUS-42101 – Ensured that group-level maven-metadata.xml files are updated correctly when a version is deleted from a member repository. NEXUS-30725 – Corrected the REST API for npm proxy repositories to accept bearer tokens as documented. NEXUS-27044 – Enhanced LDAP logging to include full exception details and complete query information. NEXUS-25658 – Users only need edit and read privileges for a specific repository to access the Invalidate Cache button. NEXUS-25475 – Updated the REST API to accept writePolicy values regardless of letter casing, preventing repository misconfiguration and ensuring Docker pushes to group repositories work as expected. NEXUS-21637 – Improved support zip generation to prevent duplicate file path errors.
| November 19, 2025 | 3.87.0 (December 2, 2025) |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: Cloud usage visualizations are now available in a new Usage tab under the main Settings section of the Nexus Repository Cloud user interface. The historical usage visualizations for cloud now include a chart showing peak storage and total egress over time so that you can monitor usage trends for your tenant. Performance improvements for task startup and download throughput. Bug Fixes: NEXUS-49091 – Cleanup policies now properly delete components when using the H2 database. NEXUS-49043 – Improved performance of the Users page by optimizing role mapping queries to prevent timeouts in environments with a large number of user roles. NEXUS-49031 – Corrupted or unreadable blob properties files are now automatically deleted across all supported blob stores, allowing recovery tasks to proceed and preventing component download failures. NEXUS-48561 – The proprietary component synchronization process now excludes orphaned Maven components without assets, preventing unintended quarantining of valid open source components. NEXUS-48463 – Routing rules now apply correctly to Huggingface proxy repositories. NEXUS-48143 – Improved error handling in file and S3 blob stores now suppresses misleading warnings when simultaneous requests temporarily fail to update blob property files. NEXUS-47018 – Anonymous users with only nx-search-read and nx-repository-view-*-*-browse privileges can now successfully perform search operations as expected.
| November 6, 2025 | 3.87.0 (December 2, 2025) |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: (self-hosted only; 3.87.0+) In Sonatype Nexus Repository Pro, the OAuth2 realm will now be enabled by default when the nexus.jwt.enabled flag is set to true, either automatically in HA mode or when manually configured in nexus.properties. Bug fixes: NEXUS-49032 – Support zip generation no longer logs serialization errors or truncates logs when SAML is configured. NEXUS-48950 – Selecting components from Hugging Face models in Sonatype Nexus Repository no longer causes errors in the Version Graph UI. NEXUS-48889 – Search queries using double quotes for exact matches now return correct results in High Availability (HA) Sonatype Nexus Repository deployments, aligning behavior with documented expectations. NEXUS-48888 – Search queries containing slashes (/) now correctly encode the character, preventing 404 errors. NEXUS-45796 – Tag association requests in Sonatype Nexus Repository no longer return 404 errors immediately after uploading a component. NEXUS-43742 – Cleanup policies in Sonatype Nexus Repository can now be created via the REST API for all formats using "*" as the format value, ensuring support for automated, multi-format policy management. NEXUS-27439 – Anonymous access settings for Docker repositories in Sonatype Nexus Repository now correctly respect per-repository configurations, ensuring global anonymous permissions no longer override repository-level restrictions.
| October 29, 2025 | 3.87.0 (December 2, 2025) |
This cloud release contains the following bug fixes, which will be provided to self-hosted customers in a future release: NEXUS-48901 – Search and indexing operations no longer fail in PostgreSQL-backed instances when components contain unusually long keyword values that previously exceeded the byte limit for tsvector fields. NEXUS-48894 – Docker pull requests against repositories with Repository Firewall enabled no longer fail due to a missing base URL; the system now derives it from the inbound request instead of requiring manual configuration. NEXUS-48777 – Docker login requests now succeed for users with access to at least one Docker repository, even when path-based routing is enabled. NEXUS-48729 – Deleting an individual npm metadata asset from the Browse page now correctly updates the UI without falsely indicating that the entire package directory has been removed. NEXUS-48410 – The Blob Stores UI now displays Used Size instead of Total Size to more accurately reflect current storage usage and reduce confusion for administrators. NEXUS-48330 – Nexus Repository now correctly caches and reuses remote ETags for npm package root requests when PCCS is enabled. NEXUS-48259 – Nexus Repository now consistently serves PyPI package metadata for proxy repositories protected by PCCS, regardless of whether the request URL includes a trailing slash. NEXUS-48000 – APT hosted repositories now generate Filename fields in metadata without a leading slash. NEXUS-47658 – Updated browse node deletion to prevent PostgreSQL deadlocks during repository browse rebuilds. NEXUS-47655 – (Requires IQ 197 and Nexus Repository 3.86.0.) Firewall for Docker now uses the HTTP configuration defined in Nexus Repository (i.e., proxy settings, authentication, timeouts, and SSL certificates) when downloading image content for scanning, improving compatibility with restricted or customized network environments. NEXUS-47603 – Scoped npm packages in hosted repositories now appear with their full names (including the scope prefix) in search results. NEXUS-47545 – Failures during S3 blob store creation are now logged at the error level with full exception details, making it easier to diagnose issues without requiring debug-level logging. NEXUS-46449 – Tag association and disassociation with components are now recorded in the audit log. NEXUS-44162 – The Blob Store and Repositories pages now display a "Calculating..." message while metrics are still being processed after a database migration. NEXUS-40172 – The nodeHeartbeatExport.json file is now compressed as a ZIP archive, significantly reducing its size and making it easier to manage during support zip generation and HA troubleshooting.
| October 22, 2025 | 3.87.0 (December 2, 2025) |
This cloud release contains the following features and bug fixes, which will be provided to self-hosted customers in a future release: | October 14, 2025 | 3.86.0 (November 5, 2025) |
This cloud release contains the following bug fixes, which will be provided to self-hosted customers in a future release: NEXUS-49070 – Logins to SaaS deployments now succeed and Nexus Repository no longer stores the OIDC id_token in the cookie, avoiding the 4096-character size limit error. NEXUS-48902 – Search API results now return the actual storage location in the repository field when querying a group repository. NEXUS-48891 – The Search API now correctly supports queries with multiple repository names using OR. NEXUS-48827 – Upgrading to 3.84.1 no longer incorrectly enables path-based routing on existing Docker repositories that had no connector selected, preserving the original configuration state. NEXUS-41540 – Repository blob store migration now runs blob move operations in parallel using all available threads in the executor pool, improving task throughput and reducing migration time.
| October 9, 2025 | 3.86.0 (November 5, 2025) |
This cloud release contains the following, which will be provided to self-hosted customers in a future release: (self-hosted only; 3.86.0+) Added a License expiry notification capability that, when configured, will send an email to the administrator when your product license is approaching expiration. A banner will also appear in the user interface, and we've added a License check system status check. (self-hosted only; 3.86.0+) The OAuth2 configuration form in Nexus Repository now enforces required fields for all OIDC settings, claim settings, and the JWKS algorithm to prevent misconfiguration. We've also added a new field for the logout endpoint URL to the OIDC settings section.
Bug Fixes NEXUS-48748 – Wildcard version searches now return consistent results. NEXUS-49025 – Firewall report links using the legacy /malware-defense path now redirect correctly, with full backward compatibility implemented to ensure both /malware-defense and /firewall URLs load without errors. (Requires IQ 197 for self-hosted customers.) NEXUS-47736 – Asset Search API queries using the group parameter with spaces or uppercase letters now return correct results in High Availability environments. NEXUS-47712 – The Sonatype Lifecycle Component section in the Nexus Repository UI now correctly reflects the security status of Golang components, eliminating the misleading Unsupported format: go message when vulnerability data is available. NEXUS-47601 – The Conan proxy repository API now includes the conanVersion field in its response. NEXUS-44942 – Removed the deprecated X-XSS-Protection header from all responses.
| October 8, 2025 | 3.86.0 (November 5, 2025) |
This cloud release contains the following fixes, which will be provided to self-hosted customers in a future release: NEXUS-48624 – The Repair - Recalculate blob store storage task no longer double-counts soft-deleted blobs, ensuring accurate blob store size and component metrics. NEXUS-48190 – Content Selector privilege scopes based on format now work as expected. NEXUS-48148 – Pushing Helm charts no longer fails when the appVersion field is a number. NEXUS-47587 – Requests for package metadata in APT hosted repositories now wait for metadata rebuilds to complete, preventing 404 responses. NEXUS-47323 – Support zip generation via the REST API is now allowed for local administrator users regardless of license state.
| October 1, 2025 | 3.86.0 (November 5, 2025) |
This cloud release contains the following fixes, which will be provided to self-hosted customers in a future release: NEXUS-29298 – Routing rules assigned during repository creation using the REST API are now correctly applied and reflected in both the UI and subsequent API responses. NEXUS-47840 – The link in the Firewall column of the Nexus Repository Browse page now correctly redirects users to the Firewall report for the corresponding repository report. NEXUS-48619 – The Execute Plan Data Repair task now logs detailed information about asset record removals, improving visibility and traceability during data repair operations. NEXUS-48634 – The Verify and Repair Data Consistency and Execute Plan Data Repair tasks now correctly clear the deleted=true flag when restoring blobs, preventing persistent MissingBlobException errors after database rollback scenarios. NEXUS-48629 – The Sonatype Lifecycle Component section in the Nexus Repository UI now correctly reflects the security status of Conan components, eliminating the misleading Unsupported format: conan message when vulnerability data is available. NEXUS-40880 – Attempting to run the Database Migrator to migrate from an H2 to a PostgreSQL database without a nexus.mv.db file now fails with an error as expected.
| September 24, 2025 | 3.86.0 (November 5, 2025) |
Possible Need to Rebuild Search Index in 3.85.0 Search in High Availability (HA) environments is now case-insensitive for component and asset fields. However, components indexed using earlier versions may not appear in search results if they contain uppercase characters. To ensure complete and accurate search results, manually run the Repair - Rebuild repository search task for any affected repositories after upgrading. This cloud release contains the following bug fixes, which will be provided to self-hosted customers in a future release: NEXUS-48644 – Logging out of the Nexus Repository user interface now correctly ends the session in HA environments. NEXUS-48616 – Changed the log level from WARN to INFO for missing tasklogfile appender. NEXUS-48573 – Made change to improve the Admin - Compact Blob Store task performance. NEXUS-48511 – Uploads to hosted repositories backed by group blob stores now defer makeBlobPermanent to member stores, eliminating unnecessary blob copying and improving performance. NEXUS-47851 & NEXUS-48501 – Components removed from Sonatype Nexus Repository by a clean-up policy are now correctly removed from the Sonatype Repository Firewall quarantine list. NEXUS-47446 – Composer proxy repositories now correctly handle packages with missing metadata. NEXUS-47022 – APT metadata is now automatically updated when components are removed by cleanup policies, ensuring metadata reflects the current state of hosted repositories. NEXUS-44318 – Docker garbage collection now uses batch processing and memory-efficient data structures to reduce memory usage and improve performance when operating on large repositories. (included for on-prem in 3.86.0 - November 2025) NEXUS-42187 – The Use Nexus truststore checkbox in repository settings is now editable in the UI for users with nx-repository-admin privileges.
| September 18, 2025 | 3.85.0 (October 7, 2025) |
This cloud release contains the following bug fixes, which will be provided to self-hosted customers in a future release: NEXUS-48666 – Licenses that end with allowed special characters now parse correctly as expected. NEXUS-48602 – The internal node heartbeat cleanup task no longer fails with SQL syntax errors. NEXUS-48591 – IQ Server ceritificants stored in the Nexus Repository truststore continue to work as expected after restarting Nexus Repository. NEXUS-47770 – Startup messages about unknown or obsolete capability types are now logged at the INFO level instead of WARN, reducing unnecessary alerts for expected conditions. NEXUS-47652 – Selecting the Nexus Repository logo in the UI now correctly redirects to the configured nexus-context-path. NEXUS-46697 – APT staging moves now correctly update metadata in both source and target repositories. NEXUS-46487 – The Admin - Change repository blob store task now preserves the original blobCreated timestamp. NEXUS-45297 – APT snapshots for non-flat repositories now include by-hash metadata files generated from stored asset checksums, ensuring full compatibility with Ubuntu 24.04 and allowing functional snapshot usage. NEXUS-44791 – The application now uses the HOSTNAME environment variable as the primary source for determining the hostname, preventing unnecessary error logs during startup in containerized HA environments. NEXUS-44626 – The Repository - Import external files task now successfully recognizes network-mounted drive paths when Nexus Repository is running as a Windows service. NEXUS-17448 – Calls to the Crowd user manager are now skipped when Crowd is not configured. Related log messages have been downgraded from WARN to DEBUG.
| September 11, 2025 | 3.84.1 (September 17, 2025) & 3.85.0 (October 7, 2025) |
3.84.1 3.84.0 Support for OCI Image Manifest Specification and RPM Packages in Container Scanning Improved Stability for Concurrent Requests in Highly Available Deployments Updated Task Names for Data Repair Consistency Dependency Updates tika-core version upgraded from 1.28.4 to 3.2.2 bouncycastle version upgraded from 1.78.1 to 1.81 azure-identity version upgraded from 1.16.2 to 1.17.0
Multiple bug fixes
| September 9, 2025 (3.84.0 – self-hosted) September 17, 2025 (3.84.1 – self-hosted) | 3.84.0 |
This cloud release includes all bug fixes from the self-hosted 3.82.1, 3.83.1, 3.83.2, and 3.84.0 releases along with the following bug fixes that will be included in the October 3.85.0 self-hosted release: NEXUS-45343 – RubyGems uploaded via the UI or REST API are now correctly included in the specs.4.8.gz file. NEXUS-45370 – Improved logs for quarantined npm and PyPI package versions. NEXUS-45788 – The search assets API now correctly supports sorting by the last_updated field. NEXUS-45844 – NuGet V2 proxy repositories no longer throw a java.lang.IllegalStateException: Duplicate key during package restore operations. NEXUS-46507 – The Format field is no longer required when editing Repository Content Selector privileges. NEXUS-46966 – Logger name inputs are now validated to prevent invalid characters or formatting. NEXUS-47019 – Added additional logging to improve visibility into search index purge operations triggered by component deletions. NEXUS-47364 – The INSTALL4J_ADD_VM_PARAMS environment variable is now safely quoted during processing to prevent errors when it includes special characters. NEXUS-47512 – The tagging UI now uses pagination to efficiently load and display tag data. NEXUS-47948 – The Plan Repair and Execute Repair tasks no longer appear in Nexus Repository Cloud deployments. NEXUS-48050 – The global header search behavior now redirects to the correct search results page. NEXUS-48162 – HA search is now case-insensitive by default. NEXUS-48397 – The malware banner feature works as expected. NEXUS-48509 – Changing the Maximum Connection Pool Size setting no longer puts Nexus Repository into an invalid state, ensuring the application remains available without requiring a restart.
| September 8, 2025 (cloud release date) | 3.82.1, 3.83.1, 3.83.2, 3.84.0, and 3.85.0 (October 7, 2025) |
3.83.2 3.83.1 3.83.0 Firewall for Containers (Requires Sonatype IQ Server 194). Improved security options for password hashing and secrets encryption. Streamlined recovery with new Verify and Repair Data Consistency task, which replaces the now legacy Repair - Reconcile component database from blob store task. New cross-region disaster recovery documentation to help configure your HA deployment to support cross-region disaster recovery in AWS. Multiple bug fixes.
Sonatype Nexus Repository Now Available in the Cloud – Sonatype Nexus Repository Pro is now available as a fully managed, cloud-hosted service, eliminating the overhead of infrastructure management and allowing your development teams to focus on building and delivering secure and reliable software faster. Docker Registry Path-Based Repository Support.
| September 3, 2025 (3.83.2 – self-hosted release date) August 19, 2025 (3.83.1 – self-hosted release date) August 12, 2025 (3.83.0 – self-hosted and cloud release date) | 3.83.0 - 3.83.2 |
3.82.1 This release fixes an issue with the Repair - Reconcile component database from blob store task where running the task with the integrity check option enabled could incorrectly remove content from repositories that use an Azure blob store. 3.82.0 Known Issue in 3.82.0 with Repair - Reconcile component database from blob store task for Azure blob stores Sonatype has identified an issue in Sonatype Nexus Repository where running the Repair - reconcile component database from blob store task with the integrity check option enabled can incorrectly remove content from repositories that use an Azure blob store. If you are using an Azure blob store, do not run this task with integrity check selected. New Capabilities API to view, create, update, and delete capabilities. Firewall quarantine messaging restored and improved.
| August 26, 2025 (3.82.1 – self-hosted release date) July 9, 2025 (3.82.0 – self-hosted release date) | 3.82.0 - 3.82.1 |
Known Issue in 3.81.1: Quarantine Messages Missing from 403 Responses Sonatype is aware of an issue in Nexus Repository 3.81.1 that prevents all quarantine messages—both default and custom—from appearing in HTTP responses when components are blocked by Repository Firewall. Affected requests return only a generic “403 Forbidden” status with no explanatory message or link to the component report. This may impact environments that depend on these messages to inform users about quarantine reasons. Known Issue in 3.81.0: dotnet restore Command Fails We’ve identified an issue in Nexus Repository 3.81.0 that causes dotnet restore commands to fail due to NuGet v3 content requests returning 404 errors. This can disrupt build pipelines that rely on NuGet group repositories. If your environment uses the dotnet build tool, do not upgrade to 3.81.0. A fix is in progress and will be released as soon as possible. 3.81.0 Egress information available in the Usage tab under Licensing. Upgraded from Jetty 9 to Jetty 12. Performance improvements for Change Repository Blobstore task in Google Cloud environments. Integrate Sonatype Repository Firewall with Zscaler.
| June 11, 2025 (3.81.1) June 10, 2025 (3.81.0) (self-hosted release dates) | 3.81.0 - 3.81.1 |
New modern user interface Usage Center support for high availability Historical usage table with insights into month-to-month usage LDAP to SAML user token migration task Simplified cleanup for S3 blob stores with Compact Blob Store task and retention property Improvements to high availability configurations for AWS database failover Upgrade impact for those with custom Jetty configuration: in this release, we renamed the logging framework module from nexus-pax-logging to nexus-logging Hugging Face support for Firewall (requires Lifecycle 191) and Firewall for Artifactory Plugin (Plugin version 2.6.0)
| May 6, 2025 (self-hosted release date) | 3.80.0 |
3.79.1 Restored RUT auth realm for Community Edition Resolved known issue preventing uploads to Azure blob store Restored Windows service installation option Additional bug fixes
3.79.0 Monthly request metrics available in Usage Center Support for AWS Pre-Signed URL Downloads (Pro Only) Pre-Signed URLs for Hugging Face and PyPI Not Yet Supported As of release 3.79.0, the pre-signed URL feature does not yet support Hugging Face and PyPI. We will add support for these formats as soon as possible. Updates to Licensing Page in User Interface Firewall - New Malware Defense Evaluation REST API (Requires IQ Server 189+) Firewall - New Firewall REST API to protect against Namespace Confusion attacks (Requires IQ Server 189+) Firewall - New Firewall for Artifactory Plugin supporting latest Artifactory versions
| April 10, 2025 (3.79.1) April 1, 2025 (3.79.0) (self-hosted release dates) | 3.79.0 - 3.79.1 |
Known Issue for Community Edition 3.78.0-3.79.0 In Sonatype Nexus Repository 3.78.0 and 3.79.0, the RUT Auth Realm (rutauth-realm), which is used for authentication via remote user token, is not available for Community Edition deployments. Instances using rutauth-realm before upgrading will lose functionality, and downgrading is not possible without a database backup made before the upgrade. We are investigating this issue and will provide a fix as soon as possible. This issue does not impact Pro deployments or Community Edition 3.77.x deployments. Warning Sonatype is aware of an issue preventing successful installation of Sonatype Nexus Repository 3.78.2 as a Windows service. If you use Nexus Repository as a Windows service, do not upgrade to 3.78.x. We will release a fix for our Windows users as soon as possible. 3.78.3 3.78.2 3.78.1 Multiple fixes for bugs impacting release 3.78.0; see the full release notes for details. Reverted previous core dependency updates, including moving back to SLF4J 1.7 and Logback 1.2.
3.78.0 Breaking change for custom plugins: Nexus Repository migrates to Spring Boot architecture. Custom OSGi bundle deployment no longer supported. Important breaking change for Windows users. JReleaser replaces Install4J as our tool for building installers. If you configure Windows Service Manager to run Nexus Repository, please review the updated instructions in our installation help docs before upgrading for details, including the commands you will need to use for starting, stopping, and uninstalling the service. Unix archive now comes with platform-specific JDK and can no longer be used in a Mac environment. Simpliefied JDK upgrades with Nexus Repository source code migration to Java. ARM Docker images now available on Docker Hub. Improved npm audit security with Firewall integration. Sunsetting Log4J Visualizer and Bower format. Core dependency updates, including move from SLF4J 1.7 to SLF4J 2.0 and from Logback 1.2 to Logback 1.5. (Reverted in 3.78.1)
Breaking Changes with JFrog Artifactory 7.104 JFrog Artifactory 7.104 is the latest and is incompatible with the Repository Firewall plugin. JFrog Artifactory has introduced a newer version of groovy-core that is not backward compatible with the version the Repository Firewall plugin is compiled against. We recommend not upgrading to Artifactory 7.104 as doing so causes an interruption with the Repository Firewall service and exposes you to malware entering the environment. | August 15, 2025 (3.78.3) March 18, 2025 (3.78.2) March 7, 2025 (3.78.1) March 4, 2025 (3.78.0) (self-hosted release dates) | 3.78.0 - 3.78.3 |
Important The Nexus Repository 3.70.x line is the last release line to support OrientDB. If you must remain on OrientDB, you will need to remain on our 3.70.x release line until you can migrate to H2 or PostgreSQL. This marks OrientDB's transition to Extended Maintenance as defined in our sunsetting documentation. As of January 9, 2026, OrientDB is considered officially sunset. 3.70.4 | February 13, 2025 (3.70.4) October 10, 2024 (3.70.3) September 3, 2024 (3.70.2) July 10, 2024 (3.70.1) July 9, 2024 (3.70.0) (self-hosted release dates) | 3.70.0 - 3.70.4 |
3.77.2 3.77.1 Fixes an issue in 3.77.0 where using the X-Forwarded-Port header with that exact letter case caused Docker repositories to return a 500 Server Error due to a conversion issue. Fixes an issue in 3.77.0 that prevented the option to automatically remove malware from displaying when configuring the Automatic Malware Management task.
3.77.0 Nexus Repository OSS becomes Nexus Repository Community Edition Support for Hugging Face Proxy Repositories (Pro and Community Edition) Automatically Remove Malicious Components with Repository Firewall (Pro Only) Content Replication for Conan V2 (Pro Only) Helm Staging Support (Pro Only) Status Check for Embedded Database Use (H2 Only) Options like Vulnerability Lookup and Advanced Search no longer display in the standalone Firewall user interface available via Solution Switcher. You can find these items by switching to the Lifecycle option via Solution Switcher.
| February 25, 2025 (3.77.2) February 6, 2025 (3.77.1) February 4, 2025 (3.77.0) (self-hosted release dates) | 3.77.0 - 3.77.2 |
Known Issue Sonatype is aware of an issue impacting Azure Blob Store users where attempting to download binary files exceeding 2GB can cause Nexus Repository to become unresponsive. We will release a patch for this issue as soon as possible. 3.76.1 3.76.0 Native support for Conan 2.0 (Pro only) Malware remediation task Firewall added to solution switcher Google Cloud Platform (GCP) blob store Region field is now auto-populated when creating a new blob store
| January 23, 2025 (3.76.1) January 7, 2025 (3.76.0) (self-hosted release dates) | 3.76.0 - 3.76.1 |