Skip to main content

Firewall for Artifactory Release Notes

Ready to Upgrade?

Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.

Date

Version

Notes

September 23, 2026

2.7.4

  • FIRE-607 – Quarantined NuGet v3 package downloads now return an HTTP 409 status with the quarantine reason, allowing nuget and dotnet restore to display the policy block instead of reporting that the package was not found.

  • FIRE-809 – The Sonatype Repository Firewall for JFrog Artifactory plugin now synchronizes repository mode changes with Sonatype Lifecycle after startup, including changes made through firewall.properties, the UI, or REST APIs.

August 5, 2026

2.7.3

  • NEXUS-52052 -Firewall for JFrog Artifactory plugin initialization errors now appear in logs, allowing customers to identify the root cause of repository synchronization failures.

  • FIRE-642 - Large artifact uploads through an Apache reverse proxy with the optional SafeListener enabled now complete successfully.

June 15, 2026

2.7.2

  • NEXUS-52909 - Improved repository configuration synchronization reliability in the Artifactory plugin for High Availability (HA) deployments. Repository configuration updates now continue to synchronize correctly after node reloads, helping ensure Sonatype IQ Server remains up to date with repository changes while reducing unnecessary communication with IQ Server.

May 25, 2026

2.7.1

  • NEXUS-52367 - The Artifactory plugin now handles streaming uncached packages correctly in Tomcat 10 environments, preventing NullPointerException crashes during package downloads.

December 16, 2025

2.6.1

  • NEXUS-44957 – Sonatype Repository Firewall for Artifactory now correctly distinguishes between IO and HTTP exceptions in HA environments, allowing nodes to recover connectivity with Sonatype IQ Server without requiring a restart.

  • NEXUS-49455 – Helm chart operations now work as expected when the Sonatype Repository Firewall plugin is enabled.

  • NEXUS-48333 – Repositories with Store Artifacts Locally set to false are now skipped, preventing plugin initialization failures.

May 13, 2025

2.6.0

  • Support for Hugging Face

  • This release fixes an issue where, when multiple plugins were installed under the Artifactory plugin directory, the firewallVersion API was sometimes returning incorrect versions.

March 18, 2025

2.5.0

  • This release provides support for JFrog Artifactory 7.104.5 and later

October 23, 2024

2.4.13

  • Disabled repositories no longer appear in the IQ Server repositories view for both hosted and proxy repositories.

  • Release supports up to JFrog Artifactory 7.98.15

August 5, 2024

2.4.12

  • We have added the functionality for the quarantine message to include a customizable response.

July 12, 2024

2.4.11

  • Integrated Tomcat listener to improve the delivery of Firewall messaging through the HTTP reason phrase.

  • Improved performance when enabling or disabling a repository

  • Improved query performance when getting the repository summary information to avoid OOM

September 14, 2023

2.4.8

  • Added REST API endpoints to allow admin users to change the configuration, reload the plugin, and check the IQ Server connection

  • Fixed an issue with incorrect MODE selection

  • Fixed an issue when using cargo sparse indexes

  • Requires Sonatype IQ Server release 168.

    • Firewall Guided Setup can now be used to configure Artifactory repositories.

July 17, 2023

2.4.7

  • Adding Fail Open Mode to enable users to ALLOW or DENY access to quarantined objects while IQ connection failures

June 1, 2023

2.4.5

  • Fixed an issue where new component audit/quarantine notifications were not sent

April 6, 2023

2.4.4

  • Added support for Policy Compliant Component Selection for npm

  • Added support for Namespace Confusion Protection

  • Improved logging during plugin initialization

October 19, 2022

2.4.3

  • Fixed an issue with the retrieval of the version number for JFrogArtifactory

  • Fixed an issue with a high availability cache strategy. The firewall.cache.quarantine.strategy configuration settings are deprecated and will now be ignored

August 19, 2022

2.4.2

  • Fixed issue with API incompatibility with JFrogArtifactory 7.38+

October 8, 2021

2.2

  • Added High-Availablity sections

February 8, 2021

2.0.20210202-144950.fea7183

  • Fixed issue with the 'Repository Manager' name in the 'Repositories' view in IQ Server.

October 6, 2020

1.5.20200826-145900.1e80e0e

  • Ability to re-quarantine a component

May 8, 2019

1.3.20190506-103422.bcec6d6

  • Fixed CSRF issue with IQ URL

April 1, 2019

1.2.20190401-141713.4839bdb

  • Audit the entire repository when enabled

  • Improved how to access the IQ policy report URL

  • Improved IQ connection handling

  • More graceful handling if the firewall.properties configuration file goes missing

  • Fixed issue when using a web application path

March 18, 2019

1.1.20190318-124352.6da59c5

  • Added support for proxies

  • Improved IQ summary report URL

  • Allow readers to access the Evaluation Summary

March 1, 2019

1.0.20190228-114947.80c1638

  • Initial release

Known Issues & Upgrade Guidance

This section captures known issues in the IQ 206 line as well as upgrade guidance.

Impacted Version(s)

Version in which Issue is Resolved

Issue Description

2.4.8 and later

For repositories already synchronized with IQ Server, changes to the repository mode in firewall.properties are overwritten during the next configuration synchronization interval. As a result, changes between audit, quarantine, and policy-compliant component selection do not persist.