Skip to main content

Sonatype IQ Server 201 Release Notes

Released March 5, 2026

The IQ 201 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.

Sonatype_Logo_Favicon.png Improvements Impacting Multiple Solutions

This release includes the following improvements that impact multiple IQ Server-powered solutions:

Lifecycle Sonatype Lifecycle

This release includes the following changes for Sonatype Lifecycle:

New HeroDevs End-of-Life Components Dashboard Under Enterprise Reporting

Sonatype Lifecycle Enterprise Reporting now includes a HeroDevs End-of-Life Components dashboard, which provides centralized visibility into open-source components that have reached end-of-life (EOL) and are eligible for HeroDevs support. This dashboard helps you quickly understand your organization’s exposure by highlighting affected applications, surfacing the most widely used EOL components, and grouping supported components by ecosystem.

With flexible filters such as Application, Stage, Format, Component Name, and Last Scan Date, you can refine results to match your operational needs and focus on the areas of highest risk. Data refreshes monthly and reflects your selected scan scope, enabling you to make informed decisions about pursuing extended support and reducing security risk across your software supply chain.

Review your exposure and contact Sonatype to explore extended support options.

For full details, see our HeroDevs End-of-Life Components help documentation.

Additional Access Point for React2Shell Impact Report

Sonatype Lifecycle now provides access to the React2Shell Impact Reportthrough an Operational Reporting tab for those who do not have access to Enterprise Reporting. This report helps teams quickly assess potential exposure to React2Shell-related risks and identify affected applications or components.

Sonatype Developer Sonatype Developer

This release does not include any Developer-specific enhancements.

SBOM Manager Sonatype SBOM Manager

This release includes the following changes for Sonatype SBOM Manager:

New Search in Original BOM Tab

Sonatype SBOM Manager now includes case-insensitive search within its Original BOM tab. The search scans both keys and values across the entire document, highlights matches, and includes navigation controls so you can quickly move between results. Matching sections automatically expand, making it easier to locate relevant information without manually opening nested fields.

Sonatype Repository Firewall Sonatype Repository Firewall

This release includes the following changes for Sonatype Repository Firewall:

Additional Audit Log Entries for Quarantine

Sonatype Repository Firewall now records firewall.quarantine audit log events when a component is newly quarantined and when a user attempts to download a component that is already quarantined. These additional entries provide greater visibility into quarantine activity, helping security and operations teams better monitor policy enforcement and user interactions.

Bug Fixes

Issue ID

Description

NEXUS-49974

Streamlined the ZScaler integration to validate credentials through functional testing rather than requiring super admin access for configuration verification and malware URL management.

NEXUS-49650

Clicking a component row in the Auto Release from Quarantine page now navigates to the detailed component information view.

NEXUS-49174

The Firewall Evaluate API now accepts requests for coordinate-based package formats like Conan and Golang without requiring SHA1 hash values, streamlining integration for formats that use package URL matching.

NEXUS-48816

Removed the non-functional "Review Obligations" button from the Legal tab when viewing Firewall Repository components to provide a clearer user experience.

NEXUS-44853

Enhanced automatic synchronization between Firewall and Artifactory to provide accurate quarantine status messages when component metadata becomes out of sync.

NEXUS-43058

Quarantine summaries now display only compliant versions as alternatives, excluding pre-cached components that contain policy violations.

NEXUS-41977

The Repository Managers navigation item now displays an accurate count of repository managers and expands automatically when selected.

NEXUS-37403

Repository Audit now processes valid components successfully even when individual assets with missing pathnames are encountered in the batch.

NEXUS-49708

IQ Server connection verification now properly validates that the configured user has the required permissions before allowing the configuration to be saved.

NEXUS-47170

NuGet registry index JSON assets are now excluded from Firewall analysis by expanding the ignore pattern to filter all NuGet feed JSON metadata, ensuring repository reports focus only on actual package artifacts such as .nupkg files.

CLM-38540

Applications with more than 1000 reports can now be deleted successfully when using S3 storage.

CLM-38452

EPSS scores now appear consistently in vulnerability lookup and API responses, matching the data displayed in application reports.

CLM-38434

Policy violation "First Reported" dates now remain stable when policy conditions are reordered or modified, ensuring accurate tracking for compliance and SLA reporting.

CLM-38370

Improved license validation handling to ensure requests with valid licenses process successfully without intermittent authorization errors.

CLM-35001

Enhanced the source control API to enforce a minimum value of 60 seconds for pull request monitoring intervals, preventing invalid configurations that could impact server stability.

Coming Soon

Coming Soon: External Log Aggregation Required for IQ HA Deployments

The IQ HA Helm chart will soon no longer include bundled log aggregation via fluentd. Customers will be responsible for providing and managing their own logging solution, giving teams greater flexibility to choose tools that align with their operational standards and security requirements. This change does not impact core IQ functionality, but it does require planning for external log aggregation when installing or upgrading HA deployments.