Sonatype IQ Server 200 Release Notes
Released February 4, 2026
The IQ 200 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.
Sonatype Lifecycle
This release includes the following changes for Sonatype Lifecycle:
New HeroDevs End-of-Life Components Dashboard Under Enterprise Reporting
Sonatype Lifecycle Enterprise Reporting now includes a HeroDevs End-of-Life Components dashboard, which provides centralized visibility into open-source components that have reached end-of-life (EOL) and are eligible for HeroDevs support. This dashboard helps you quickly understand your organization’s exposure by highlighting affected applications, surfacing the most widely used EOL components, and grouping supported components by ecosystem.
With flexible filters such as Application, Stage, Format, Component Name, and Last Scan Date, you can refine results to match your operational needs and focus on the areas of highest risk. Data refreshes monthly and reflects your selected scan scope, enabling you to make informed decisions about pursuing extended support and reducing security risk across your software supply chain.
Review your exposure and contact Sonatype to explore extended support options.
For full details, see our HeroDevs End-of-Life Components help documentation.
Expanded React2Shell Impact Report with In-Product Insights
Sonatype Lifecycle now provides an enhanced React2Shell Impact Report within a new Rapid Response Reports section under Enterprise Reporting. This update makes it easier to quickly access time-sensitive vulnerability insights from a centralized location, helping teams respond faster during critical security events.
In addition to the existing CSV download, the report now includes an Impact Summary section directly in the UI. This summary highlights key information such as the impacted applications, components, versions, and files, along with recommended next actions, waiver and evaluation status, and clear visibility into when an issue was first identified and when it was fixed.
Bringing these insights into the product supports faster, more confident decision-making during incident response.
Sonatype Developer
This release does not include significant changes to Sonatype Developer.
Sonatype SBOM Manager
This release includes the following changes for Sonatype SBOM Manager:
View Original BOM Details in User Interface
Sonatype SBOM Manager now includes an Original BOM tab on the SBOM detail page. This tab lets you view the SBOM exactly as it was uploaded, helping you validate and reference the original source of truth.
JSON-based SBOMs are displayed in an interactive tree viewer for easier exploration, while XML-based SBOMs are shown as formatted text. The Original BOM tab supports both CycloneDX and SPDX formats, making it easier to review and audit SBOMs without leaving the product.
Sonatype Repository Firewall
This release includes the following changes for Sonatype Repository Firewall:
Automatic Re-Evaluation for Age-Based Policy Constraints
Components quarantined by age-based policy constraints are now automatically re-evaluated and released once they exceed the defined age threshold, reducing manual intervention and improving development workflow efficiency.
Bug Fixes
Issue ID | Description |
|---|---|
NEXUS-49569 | Docker policy violations marked as legacy no longer bypass quarantine enforcement when Allow violations of this policy to be granted legacy status is enabled at the root organization level. |
NEXUS-47285 | The malware remediation task now skips components with empty or null hashes in NuGet proxy repositories, allowing the evaluation batch to continue running without interruption. (Will require Nexus Repository 3.88.0+ to be fully resolved.) |
NEXUS-47170 | NuGet registry index JSON assets beyond index.json are now excluded from analysis to prevent unnecessary Component-Unknown entries in repository reports. |
NEXUS-47131 | Long repository names in the Repository Firewall left-hand navigation now display correctly, and the back button from component details reliably returns users to the appropriate prior context in Repository Firewall. |
NEXUS-44585 | Users with repository-level access now see only authorized information without encountering 403 errors on the Firewall landing page or Repository Manager screen. |
CLM-38159 | Reduced query volume and improved component metadata evaluation performance for large component sets when performing policy evaluations for PCCS. |
CLM-34494 | IQ Server now provides a clearer error message when database connection fails due to incorrect PostgreSQL credentials. |
Coming Soon
Upgrade PostureandRolling RecapEnterprise Reports to be Sunset
Data for the Upgrade Posture and Rolling Recap Enterprise Reporting dashboards will no longer be refreshed after January 2026. These dashboards will be sunset and removed from Sonatype IQ on February 23, 2026.
Customers are advised to review their usage of these dashboards and plan accordingly. Additional guidance is provided in the Sonatype IQ Server Feature Status section.