Skip to main content

Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes

Known Issue in Sonatype Nexus Repository 3.83.0 - 3.89.1

There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the Verify and Repair or Data Repair Plan tasks can incorrectly delete valid assets, leading to potential data loss.

This issue is fixed in version 3.90.0.

Upgrade to version 3.90.0 before running the Verify and Repair or Data Repair Plan tasks.

Possible Need to Rebuild Search Index

Search in High Availability (HA) environments is now case-insensitive for component and asset fields. However, components indexed using earlier versions may not appear in search results if they contain uppercase characters.

To ensure complete and accurate search results, manually run the Repair - Rebuild repository search task for any affected repositories after upgrading.

What's New and Noteworthy in 3.85.1?

Released January 15, 2026

Repair - Execute Data Repair Plan Task Disabled

To prevent potential data loss caused by a known issue impacting Sonatype Nexus Repository 3.83.0 and later, this release disables the Repair - Execute Data Repair Plan task by default.

Attempting to run this task will result in a failure and an error in the logs. The task remains visible in the UI, and any existing instances of this task will not be removed. However, execution is blocked by default.

While it is possible to manually re-enable this task by setting the nexus.reconcile.task.enabled property to true, it is important that you not do so until you are using a release that restores support.

We will announce when it is safe to re-enable this task in a future release note.

What’s New and Noteworthy in 3.85.0?

Released October 7, 2025

Predictable S3 Bucket URLs for Nexus Repository Cloud

Sonatype Nexus Repository Cloud now supports predictable S3 bucket URLs for binary downloads, making it easier for teams to configure and manage outbound traffic rules in their tenants.

This update introduces a standardized URL format that includes region and tenant identifiers. With this structure, you can quickly identify and allow necessary traffic from Nexus Repository Cloud without relying on dynamic URLs. This is especially useful in tightly controlled network environments where pre-approving outbound traffic is required.

For more details, see the Nexus Repository Cloud help documentation.

Firewall API Endpoint Alignment

The Firewall API now consistently uses the /api/v2/firewall/ path for all but the malware defense-specific endpoints. Previously existing /api/v2/malware-defense/ paths remain supported for backward compatibility.

The /api/v2/malware-defense/evaluate API continues to be available and uses malware-defense in its path.

Bug Fixes in 3.85.1

Issue ID

Description

NEXUS-50152

The blob attribute loading process no longer deletes properties files on transient I/O errors or unhandled exceptions.

Bug Fixes in 3.85.0

Note

A bug in the UI has been reported where the Upload Component button is missing when browsing repositories. This issue will be fixed in later updates.

Issue ID

Description

NEXUS-17448

Calls to the Crowd user manager are now skipped when Crowd is not configured. Related log messages have been downgraded from WARN to DEBUG.

NEXUS-41430

Audit log messages for asset update and delete events now include the full path to the corresponding blob within the blobstore.

NEXUS-42187

The Use Nexus truststore checkbox in repository settings is now editable in the UI for users with nx-repository-admin privileges.

NEXUS-44626

The Repository - Import external files task now successfully recognizes network-mounted drive paths when Nexus Repository is running as a Windows service.

NEXUS-44791

The application now uses the HOSTNAME environment variable as the primary source for determining the hostname, preventing unnecessary error logs during startup in containerized HA environments.

NEXUS-45297

APT snapshots for non-flat repositories now include by-hash metadata files generated from stored asset checksums, ensuring full compatibility with Ubuntu 24.04 and allowing functional snapshot usage.

NEXUS-45343

RubyGems uploaded via the UI or REST API are now correctly included in the specs.4.8.gz file.

NEXUS-45370

Improved logs for quarantined npm and PyPI package versions.

NEXUS-45788

The search assets API now correctly supports sorting by the last_updated field.

NEXUS-45844

NuGet V2 proxy repositories no longer throw a java.lang.IllegalStateException: Duplicate key during package restore operations.

NEXUS-45943

Modified how secret mappings are handled in the Helm chart to prevent volume binding failures during deployment.

NEXUS-45973

Re-enabled SHA1 encryption in the Nexus Repository Docker image to restore compatibility with Azure-hosted PostgreSQL instances and other external services that still rely on SHA1-based certificates.

NEXUS-46115

Uploading to a NuGet group repository now correctly returns a 405 response.

NEXUS-46127

Addressed a UI error that could occur after session timeouts, preventing crashes when returning to an inactive tab.

NEXUS-46281

Database migrations now correctly set the id column in the docker_foreign_layers table to an integer type, preventing data conversion errors when retrieving Docker layers after migrating between H2 and PostgreSQL.

NEXUS-46487

The Admin - Change repository blob store task now preserves the original blobCreated timestamp.

NEXUS-46507

The Format field is no longer required when editing Repository Content Selector privileges.

NEXUS-46697

APT staging moves now correctly update metadata in both source and target repositories.

NEXUS-46966

Logger name inputs are now validated to prevent invalid characters or formatting.

NEXUS-47019

Added additional logging to improve visibility into search index purge operations triggered by component deletions.

NEXUS-47022

APT metadata is now automatically updated when components are removed by cleanup policies, ensuring metadata reflects the current state of hosted repositories.

NEXUS-47364

The INSTALL4J_ADD_VM_PARAMS environment variable is now safely quoted during processing to prevent errors when it includes special characters.

NEXUS-47406

Conan search results are now correctly scoped to the specified repository.

NEXUS-47446

Composer proxy repositories now correctly handle packages with missing metadata.

NEXUS-47512

The tagging UI now uses pagination to efficiently load and display tag data.

NEXUS-47652

Selecting the Nexus Repository logo in the UI now correctly redirects to the configured nexus-context-path.

NEXUS-47770

Startup messages about unknown or obsolete capability types are now logged at the INFO level instead of WARN, reducing unnecessary alerts for expected conditions.

NEXUS-47851 & NEXUS-48501

Components removed from Sonatype Nexus Repository by a clean-up policy are now correctly removed from the Sonatype Repository Firewall quarantine list.

NEXUS-47948

The Plan Repair and Execute Repair tasks no longer appear in Nexus Repository Cloud deployments.

NEXUS-48106

YUM group metadata is now properly shared across nodes in an HA cluster after repository membership changes, preventing repeated and unnecessary remerging of repomd.xml during cross-node requests.

NEXUS-48162

HA search is now case-insensitive by default.

NEXUS-48509

Changing the Maximum Connection Pool Size setting no longer puts Nexus Repository into an invalid state, ensuring the application remains available without requiring a restart.

NEXUS-48511

Uploads to hosted repositories backed by group blob stores now defer makeBlobPermanent to member stores, eliminating unnecessary blob copying and improving performance.

NEXUS-48564

The root.level system property is now correctly honored at startup, allowing debug logging to be enabled before Nexus Repository initializes.

NEXUS-48573

Made change to improve the Admin - Compact Blob Store task performance.

NEXUS-48595

Using the nexus.blobstore.get.maxRetries=0 property no longer prevents file uploads by ensuring the blob retrieval logic executes at least once before retry handling begins.

NEXUS-48602

The internal node heartbeat cleanup task no longer fails with SQL syntax errors.

NEXUS-48644

Logging out of the Nexus Repository user interface now correctly ends the session in HA environments.