Skip to main content

Sonatype IQ Server 186 Release Notes

Released January 8, 2025

The Sonatype IQ Server 186 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.

Lifecycle.png Sonatype Lifecycle

Here's what's new for Sonatype Lifecycle in IQ Server release 186:

New AI Model Dashboard

Our new AI Model dashboard helps you understand which Hugging Face models are present in your applications and track usage trends across your organization. With this knowledge, you can make informed decisions to mitigate risks and optimize your AI strategy.

Screenshot of the AI Model Usage dashboard for the release notes

This dashboard provides detailed information on the Hugging Face models detected in your applications over the last 90 days. You can filter this data by organization, application, application category, and stage for targeted analysis. Visualizations include a breakdown of detected models, identical model identification across repositories, and a view of model usage in different applications.

To access the dashboard, ensure you are running IQ Server version 184 or higher, have scanned at least one application containing Hugging Face models, and have opted in to share telemetry data with Sonatype.

See the AI Model dashboard help documentation for full details.

Dashboard Performance Improvements

This release includes significant performance enhancements to the Lifecycle dashboard for customers using a PostgreSQL database. We've refactored the various tabs within the dashboard to optimize data retrieval, resulting in a faster and more responsive experience. Additionally, we've improved the Applications filter by limiting the initial display to 500 applications and providing clear guidance on how to refine your search for larger datasets. These changes ensure smoother navigation and improved usability.

Easier Onboarding with Automatic Role Assignment

You can now configure mappings between GitHub user attributes (like email, username, or full name) and your Identity Provider (IdP) values. This allows IQ Server to automatically match SCM users to existing IdP users during onboarding and grant them appropriate access to Lifecycle evaluations based on their contributions. This automation simplifies permission management, accelerates onboarding, and provides flexibility for organizations with diverse IdP configurations.

See the Source Control REST API documentation for full details on prerequisites and configuration.

Waiver Reasons in API Responses and User Interface

You now have immediate access to waiver reasons directly within API responses and across key areas of the user interface. This eliminates the need for extra API calls or navigating to detailed waiver views, saving you time and effort when integrating with other systems, generating reports, or simply understanding the rationale behind a waiver.

With waiver reasons readily available in API responses for active, expired, and similar waivers, as well as within the Waivers dashboard, violation details views, and exported CSV files, you gain a more streamlined and comprehensive understanding of your waiver decisions. This increased visibility promotes better collaboration, informed decision-making, and improved auditability within your software development lifecycle.

For details on waiver reasons, see the Waivers help documentation.

sonatype-developer-icon.png Sonatype Developer

Here's what's new for Sonatype Developer in IQ Server release 186:

Enhanced Vulnerability Remediation with Auto-Waivers for "No Path Forward" Issues

Sonatype Developer can now intelligently identify and automatically waive vulnerabilities in open-source components where no updated version is available to address the issue. Auto-waivers can help you focus on critical issues, streamline your policy violation management process, and minimize distractions for developers, ultimately improving software supply chain security and developer productivity.

Administrators can configure auto waivers to honor a maximum tolerated threat level at the organization or application level. This ensures control over risk tolerance and alignment with organizational security posture. Auto-waivers are visible on the waivers dashboard, in violation details, and on the license compliance application report. Users can also manually remove auto-waivers for specific violations when necessary. You can also manage auto-waivers programmatically through the API.

See the auto-waiver help documentation and auto-waiver API documentation for full details on configuring this powerful new feature.

Easy Access to Integrations

All available integrations are now presented on the homepage tabs for improved visibility and access.

sonatype-sbom-manager-icon.png Sonatype SBOM Manager

Here's what's new for Sonatype SBOM Manager in IQ Server release 186:

SBOM Manager Container Scans

Leveraging Sonatype Container Security, SBOM Manager now provides detailed SBOMs for OS-level components within your container images. This enhanced visibility empowers you to better understand and manage your software supply chain risks, leading to more informed decisions and improved security posture.

See the Importing SBOMs help documentation for more details on support for container analysis.

See Policy Violation Data in User Interface

You can now view policy violation data directly within SBOM Manager. This includes a summary of violations in the BOM header, a dedicated violations column for components, and detailed violation information (e.g., severity levels, threat, policy, constraint, and condition information) in the component details page.

Screenshot of an example SBOM with the new Policy Violation Summary and Violations column visible

Skip Validation Support for CDX and SPDX

You can bypass strict validation checks when importing CDX and SPDX files, providing more flexibility when working with potentially invalid SBOMs. During import, SBOM Manager will extract critical information (e.g., package names and versions) from invalid CDX and SPDX file imports. In addition to capturing essential data, the system preserves the original, unvalidated SBOM for future reference. This ensures that users have access to the complete SBOM if needed.

See SBOM Import for more details.

Search by License

You can now easily search for components by license, gaining immediate visibility into potential concerns across your projects. This new search functionality complements the existing component name search, providing a more comprehensive view of your SBOMs and empowering you to make informed decisions regarding license compliance and risk mitigation.

Improved Matching Process for SBOM Scans (Impacts Lifecycle and SBOM Manager)

The SBOM matching process now prioritizes hashes over coordinates (PURLs) to improve accuracy and reliability, particularly for ecosystems like PECOFF where coordinates may be inconsistent. This change ensures more precise component identification and enhances the overall quality of SBOM data.

Improved Component Sorting

Users can now sort components by name on the Bill of Materials (BOM) page for easier navigation and organization.

Original Binary Filename Visible in Bill of Materials Page

The Show metadata option within the Bill of Materials page now displays the original filename of the scanned binary, providing clearer traceability and association between your SBOM data and the corresponding source file.

Firewall.png Sonatype Repository Firewall

Here's what's new for Sonatype Repository Firewall in IQ Server release 186:

Quickly Access Firewall via Solution Switcher

We've enhanced navigation by adding Repository Firewall to the solution switcher, making it readily accessible alongside other Sonatype solutions like SBOM Manager and Sonatype Developer. This improvement streamlines your workflow and provides a more unified experience across the Sonatype platform.

Solution Switcher screenshot with Firewall highlighted

For details about how to use the solution switcher, see the solution switcher help documentation.

Sonatype-integrations-logo.png Notable Changes to Integrations

We also wish to call out the following significant changes to our integrations:

Please note that the IQ Server CLI for version 186 will be available for download shortly after the core IQ Server release in accordance with our staggered release schedule for Integrations.

IQ CLI is now a Standalone Solution

We're excited to announce that the IQ CLI is now a standalone solution. The standalone IQ CLI (i.e., IQ CLI 2.0) includes all the functionality you're used to but will now follow its own independent versioning and release cadence. This change allows for faster development, more frequent releases, and better integration with your existing workflows.

Note that this change means that the IQ CLI is now a separate download and is not included in the bundled IQ download. See the Download and Compatibility page to download the CLI.

Dependency Tree Visualization for Cargo (IQ CLI)

With IQ CLI 2.0, the dependency tree visualization now allows you to explore the full dependency tree of your Cargo projects, including direct and transitive dependencies sorted by threat level. This provides a comprehensive view of your project's dependencies and potential vulnerabilities, facilitating better risk assessment and management.

Note that for the dependency tree visualization to work for Cargo, both your Cargo.lock and Cargo.toml files must exist in the same location. For more details, see the dependency tree help documentation.

Bug Fixes

This release includes the following notable bug fixes:

Issue ID

Description

CLM-32560

The insight_brain_ods.lock table no longer contains excess records after we optimized the cluster lock mechanism with PostgreSQL Advisory Locks.

CLM-32392

Improved the performance and reliability of IQ HA support zip generation by optimizing the handling of large file systems.

You can also check out the Track Resolved Issues page for a running list of notable bug fixes in this and past releases.

Sunsetting Announcements

Refer to Sunsetting Announcements Details.

A-Name Identification has been officially sunset.

Sonatype Auditor has officially entered extended maintenance. Full details are available in Sonatype Auditor Sunsetting.