Sonatype IQ Server 192 Release Notes
Released June 11, 2025
The IQ 192 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.
Sonatype Lifecycle
This release includes the following changes for Sonatype Lifecycle:
New Insight for IQ 189+: Waivers Explorer
The Waivers Explorer dashboard is a powerful tool to help you optimize your vulnerability remediation process. It offers a comprehensive view of your organization's waived policy violations, allowing you to make informed decisions and strategically prioritize development deliverables while managing security risks.

The Waivers Explorer dashboard helps you analyze your active waivers by providing a breakdown of waivers scoped to root organizations, individual organizations, and applications. It also summarizes the volume of created waivers (manual and automated), gives a snapshot of upcoming waiver expirations, and highlights the top five most frequently waived policy violations for components and applications. With these insights, you can refine your remediation strategies based on your organization's risk tolerance.
This dashboard is available for IQ versions 189 and beyond. See the Waivers Explorer help documentation for full details.
New Insights for IQ 184+: Security Risk Trends and Security Risk Breakdown Dashboards Replace Security Risk Analysis
We have replaced the Security Risk Analysis dashboard with two new, more focused dashboards: Security Risk Trends and Security Risk Breakdown. These new dashboards provide enhanced visibility into your organization's security posture.
The Security Risk Trends dashboard allows you to monitor your applications' health and security over time. By tracking trends in open violations, fix rates, and mean time to remediate (MTTR), you can establish benchmarks and gain insights into your remediation strategies' effectiveness. This dashboard offers various filters to help you analyze specific areas of interest.

The Security Risk Breakdown dashboard provides a detailed view of vulnerability distribution and severity within your applications. This enables a more targeted approach to remediation, helping you prioritize efforts to maintain a low-risk security profile and meet compliance requirements. The dashboard highlights the Top 10 Violations Fixed, Top 5 Applications with Most Risk, Top 5 Most Common Vulnerabilities (CVEs), Top 5 Components with Most Risk, and Top 5 Common Weaknesses (CWEs). Interactive filters allow you to analyze risk based on various criteria, such as threat level, stage, and violation type.

These dashboards are available for IQ versions 184 and beyond. See the Security Risk Trends and Security Risk Breakdown help pages for full details.
Detect Objectionable AI Models with a New Policy Condition
Sonatype Lifecycle now includes a new AI Content policy condition that helps you detect AI models from Hugging Face containing offensive or demeaning language. These models are flagged as Objectionable based on Sonatype’s Component Intelligence team’s analysis, which looks for indicators such as "Not For All Audiences" or "NSFW" tags, as well as banned terms in the model’s name or README.
By configuring a policy with the AI Content condition, you can automatically identify and report violations when an objectionable AI model is introduced. This capability helps enforce organizational content standards and promotes responsible AI usage throughout your development lifecycle. For full details on configuring this new feature, see our help documentation on threats in AI models.
Enhanced Vulnerability Insights on Component Details
The Security tab on the Component Details page in Sonatype Lifecycle now provides more granular information about identified vulnerabilities. You will find a new column for Identification Source, giving you a clearer understanding of how vulnerabilities were identified. Additionally, the component details drawer now displays Vulnerability Detection Type and Identification Source. The pill at the top of the drawer also shows the security research type, such as fast track or deep dive, associated with the vulnerability.
These enhancements provide a more comprehensive view of your components' security posture. For a complete overview of the Component Details page, see our help documentation on component details.
Support for SPDX 2.2 SBOM Ingestion
Sonatype Lifecycle now offers expanded support for ingesting Software Bill of Materials (SBOMs), accommodating both SPDX v2.2 and the existing SPDX v2.3 formats. This enhancement provides greater flexibility and compatibility, allowing you to seamlessly analyze SBOMs generated in either of these widely adopted SPDX versions. By supporting both formats, Lifecycle ensures you can maintain comprehensive visibility into your software supply chain, regardless of the SPDX version used to generate your SBOMs. For full details, see our SPDX application analysis help documentation.
SAML Support for Automatic Role Assignment
The Automatic Role Assignment feature now supports matching for SAML accounts in addition to local and LDAP accounts. This enhancement allows for the automatic assignment of Lifecycle roles to GitHub contributors who authenticate via SAML, streamlining user provisioning and access management.
Sonatype Developer
This release includes the following changes for Sonatype Developer:
Create Pull Requests Directly from Priorities View
You can now configure Lifecycle/Developer to create pull requests (PRs) on the default branch in your SCM (e.g., GitHub) directly from the Priorities view. This new capability helps your teams integrate vulnerability remediation seamlessly into their development workflows. By streamlining the process of creating PRs for suggested remediations, you can significantly reduce your Mean Time To Resolution (MTTR) and maintain a stronger security posture.
![]() |
This new feature allows you to quickly initiate the fix for a direct dependency with a recommended upgrade right from where you prioritize your security issues. Lifecycle and Developer will ensure that the necessary conditions are met before allowing PR creation, helping you focus on actionable remediations.
For all the technical details on how to configure and use this feature, refer to our help documentation on creating PRs from priorities view.
Streamlined Waiver Request and Approval Workflow
Sonatype Lifecycle now provides an enhanced workflow for requesting and managing waivers, along with updated dashboards and views to keep all stakeholders informed of waiver statuses. The new Requested Waivers tab on the Waivers dashboard offers a quick overview of all policy violation waiver requests awaiting administrator approval. Administrators can review each request in detail and either apply or reject it directly.
This new feature supports users who need to de-prioritize the remediation of a violation but do not have the direct permission to waive it themselves. For full details, see our help documentation on requesting waivers.
Waiver Status Available in Priorities View
Sonatype Lifecycle's Priorities view now offers enhanced visibility into waived violations, allowing you to quickly understand their status and the impact on your builds. The Build Action column now clearly displays Waived when all violations for a component have been waived. A tooltip also indicates the exact time remaining until the waiver expires.
Additionally, the Suggested Remediation column now shows Waive Violations for violations without upgrade recommendations that are not reachable. When all violations are waived, this column also displays the total number of waived violations. A green Auto tab appears if at least one of the violations has been automatically waived, providing a quick visual cue.
For full details, see our help documentation on viewing waivers from Priorities view.
Sonatype SBOM Manager
This release includes the following changes for Sonatype SBOM Manager:
Comprehensive License Management in SBOM Manager Legal View
Sonatype SBOM Manager now includes a new Legal view, delivering robust license management through integration with Sonatype’s Advanced Legal Pack (ALP). This centralized view helps you identify component licenses within your SBOMs, flag policy issues, and generate detailed reports. It distinguishes between Effective, Declared, and Observed licenses—even when a component has multiple license terms—to provide deeper visibility into your legal obligations.
![]() |
Available to customers with licenses for SBOM Manager, Sonatype Lifecycle, and ALP, the Legal view supports license selection and overrides at the application, organization, and root organization levels. Built-in inheritance rules ensure consistency, while status options like Selected, Overridden, and Acknowledged give you the control and flexibility needed to stay compliant across your software portfolio.
For full details, see our Legal View help documentation.
Sonatype Repository Firewall
This release includes the following changes for Sonatype Repository Firewall:
Integrate Sonatype Repository Firewall with Zscaler for Enhanced Malware Protection
Sonatype Repository Firewall now integrates with Zscaler, a cloud-native cybersecurity platform, to provide an additional layer of defense against actively verified malware components. This integration automatically blocks malicious components from being downloaded directly from public repositories, protecting your organization from malware found in "shadow downloads."
For details on how to enable this protection, see our Zscaler integration help documentation.
Firewall User Interface Improvement
Sonatype Repository Firewall now provides clearer context when viewing a repository's summary page. The title and breadcrumbs for a given repository now include both the repository type (e.g., hosted or proxy) and its format. This enhancement helps you quickly identify and understand the specific characteristics of the repository you are viewing, improving navigation and overall clarity within Repository Firewall.
Bug Fixes
This release includes the following notable bug fixes:
Issue ID | Description |
---|---|
CLM-34990 | Sonatype Lifecycle now avoids generating filenames over 1000 characters during SBOM export, which allows for successful SBOM scanning and policy evaluation. |
CLM-34858 | The Dashboard now loads as expected when the application count exceeds 65,000 in Sonatype Lifecycle using PostgreSQL. |
Coming Soon
We’re excited to share that the following enhancements will be coming soon to Sonatype Repository Firewall and Sonatype Developer:
Firewall Support for Containers
Sonatype Repository Firewall will soon introduce support for containers, enabling you to proactively block the download of container images violating your organization's policy configurations before they enter your container ecosystem.
Proactive Dependency Management for InnerSource
Sonatype Developer will soon help you automate the management of InnerSource dependencies, making it easier to identify and upgrade shared libraries with low risk and high reward.