Skip to main content

Sonatype Nexus Repository 3.90.0 - 3.90.5 Release Notes

Ready to Upgrade?

Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.

What's New in 3.90.5?

Released August 17, 2026

This release introduces the following bug fixes to the 3.90.x release line:

Issue ID

Description

NEXUS-50761

Sonatype Nexus Repository now considers all assigned roles and privileges when browsing repository content, allowing users with content selector privileges to view content permitted by their other roles.

NEXUS-50690

npm v1 searches now return results as expected in PostgreSQL environments.

NEXUS-47909

Maven group repositories now serve archetype-catalog.xml hash files as expected instead of returning a 500 error.

What's New in 3.90.4?

Released July 2, 2026

This release backports the following bug fixes to the 3.90.x release line:

Issue ID

Description

NEXUS-52952

The npm proxy repository Invalidate Cache operation now completes as expected without browser timeout errors caused by long-running per-asset cache invalidation operations.

NEXUS-52362

Maven group repositories now honor the lowest metadataMaxAge value from proxy members so merged maven-metadata.xml content refreshes correctly from upstream sources.

NEXUS-51520

npm group repositories now correctly invalidate cached metadata when upstream proxy repositories apply PCCS filtering. Metadata invalidation now completes successfully for npm group repositories when versioned package paths are requested, ensuring that cache updates propagate correctly when PCCS or IQ policies filter available versions in upstream proxies.

NEXUS-51319

npm proxy repositories now send valid ETags, ensuring cached tarballs return 304 responses instead of triggering re-downloads.

NEXUS-50552

The Browse menu now appears for users who have content selector privileges with browse action, matching the visibility behavior of standard repository-view permissions.

What's New in 3.90.3?

Released April 8, 2026

Note

Sonatype Nexus Repository 3.90.3 is available for download from the Nexus Repository 3 Download archive.

Added Skip Processing Configuration

NEXUS-51666 – Added a skipProcessing configuration option to BlobRepositoryMismatchTask for eligible direct upgrades. See our Support Knowledgebase article for details.

What's New in 3.90.2?

Released March 23, 2026

New Instance Migrator Helps Nexus Repository 3.70.5 Deployments Move to Nexus Repository Cloud or Self-Hosted Nexus Repository 3.90.2 Without Downtime

Sonatype Nexus Repository now provides a migration path from OrientDB 3.70.5 to modern, supported platforms without requiring service interruption. With the new Instance migrator, you can migrate to either of the following without downtime:

  • Nexus Repository Cloud

  • Nexus Repository self-hosted version 3.90.2+

Migration preserves core configuration and repository data, enabling a seamless transition to a more scalable and supported architecture.

Key Capabilities

  • Preserves repository data and configuration

    Migrates hosted repository content, repository configurations, and associated settings to the target environment.

  • Maintains user and access configurations

    Transfers users, roles, and authentication mappings to ensure continuity of access control.

  • Secure handling of sensitive data

    Encrypts and transfers secrets using supported security standards during migration.

  • Automated validation checks

    Prevents invalid configurations, such as missing blob stores, and provides clear feedback during migration.

  • No service interruption

    Keeps your source instance online and operational throughout the migration process.

Important Migration Requirements

  • Blob stores must exist on the target instance

    Create blob stores in the target environment before migration. Do not reuse storage locations from the source instance.

  • Shared storage is not supported

    Using the same S3 bucket, Azure container, or file path across source and target instances can lead to data corruption.

  • LDAP/Crowd users require external server configuration

    While user tokens and role mappings for LDAP/Crowd users will migrate successfully, the target instance must be manually configured to connect to the same external authentication servers for these users to authenticate after migration.

  • Some configurations require manual setup

    SSL/TLS certificates export from the source but may require manual import configuration on the target instance depending on your environment.

  • Proxy/group repository cached content does not migrate

    Only hosted repository content is migrated.

For full migration requirements and process details, see the Instance Migrator help documentation. You can download the instance migrator for version 3.70.5 from the OrientDB Downloads page.

Bug Fixes in 3.90.2

This release includes the following additional bug fixes

Issue ID

Description

NEXUS-51040

Docker proxy repositories handle bearer token authentication requests without encountering null pointer exceptions during HTTP context operations.

NEXUS-50764 & NEXUS-39228

Group repositories now properly detect policy-filtered version changes in member proxy repositories, ensuring metadata remains current and complete across npm and PyPI formats.

What's New in 3.90.1?

Released March 6, 2026

Fix for Nexus Repository 3.90.0 Community Edition

This release fixes an issue that prevented Sonatype Nexus Repository 3.90.0 Community Edition deployments from starting upon initial installation or upgrade.

Community Edition users can now safely upgrade to 3.90.1.

What’s New in 3.90.0?

Released March 5, 2026

Support for Terraform Group Repositories

Sonatype Nexus Repository now supports the Terraform group repositories, allowing you to aggregate multiple Terraform hosted and proxy repositories into a single endpoint. This capability simplifies configuration for developers by providing one consistent URL for Terraform modules and providers, while centralizing control and visibility for repository administrators.

Terraform group repositories include intelligent caching with configurable TTL values for modules and provider versions, along with request deduplication to reduce redundant upstream queries. When the same version exists in multiple member repositories, you can apply configurable conflict resolution strategies to determine which artifact is served. The implementation also tracks member health and automatically handles unhealthy members, while exposing comprehensive metrics to help you monitor cache performance and overall repository health.

For full details, see the Terraform Repositories help documentation.

Support for Swift Hosted Repositories

Sonatype Nexus Repository now supports Swift hosted repositories, enabling you to publish and manage Swift packages as .zip files with MIME type validation. This capability allows teams to securely store and distribute internal Swift artifacts and approved third-party components through Nexus Repository, providing a centralized and reliable source for Swift dependencies.

Swift hosted repositories support enterprise controls such as access management and auditing, along with optional anonymous access where appropriate. For full details, see the Swift Repositories help documentation.

Re-enabled Repair - Execute Data Repair Plan Task

In Sonatype Nexus Repository 3.90.0, the Repair - Execute Data Repair Plan task is re-enabled by default. We previously disabled this task in 3.88.0 to prevent potential data loss while we addressed issues affecting the Verify and Repair and Data Repair Plan tasks.

You can now safely use the Repair - Execute Data Repair Plan task to correct data inconsistencies between the database and blob store. This update restores the intended maintenance workflow and allows you to run data repair operations with confidence.

This re-enablement aligns with the introduction of Recovery Mode, which provides a controlled operational state to help protect data integrity during repair and reconciliation activities.

New Recovery Mode for Safe Data Reconciliation

Sonatype Nexus Repository now includes Recovery Mode, a controlled operational state designed to support safe reconciliation between the database and blob storage after outages or data inconsistencies. When enabled, Recovery Mode helps protect data integrity by preventing specific background tasks from interfering with repair operations. This feature is available only for self-hosted deployments and requires administrative privileges. Before enabling Recovery Mode, consult Sonatype Support to confirm it is appropriate for your situation.

For full details, see the Recovery Mode help documentation.

New User Token API

A new User Token API allows administrators to create, view, and delete user tokens. With the appropriate privileges, administrators can generate tokens for specific users and realms, retrieve token summaries (excluding sensitive fields), and manage tokens across individual or all realms, including options to include expired tokens in responses.

For full details, see the User Token API help documentation.

Improved Transparency for Policy-Compliant Component Selection in npm Metadata

Sonatype Nexus Repository now enhances policy-compliant component selection (PCCS) by exposing filtered npm package versions directly in the package metadata. When PCCS filters versions that violate your Repository Firewall policies, those versions appear in the sonatype_filtered_versions field in the component's metadata. This update provides clearer visibility into which versions were excluded, helping teams quickly understand why a version is unavailable and identify an acceptable alternative.

Granular Permissions for Log Management API in Nexus Repository Cloud Environments

Sonatype Nexus Repository Cloud now supports more granular access control for the Log Management API. Previously, access to the Log Management API required the broad nexus:* permission, which is granted only to the nx-admin role. You can now grant access to this API using the built-in nexus:logging:read permission and the associated nx-logging-read privilege. This update enables teams to follow the principle of least privilege by allowing service accounts to download logs without granting administrative access across the entire tenant.

Removed Legacy Application Health Check and Hosted Repository Analysis

In this release, we removed the legacy Application Health Check plugin from Sonatype Nexus Repository. This plugin previously provided both Application Health Check and Hosted Repository Analysis capabilities.

Sonatype Lifecycle replaces these capabilities with more robust and fully supported software composition analysis. Lifecycle offers CLI-based scans, binary uploads, comprehensive policy evaluation, and continuous monitoring across your development lifecycle.

Removing these features reduces technical debt, eliminates non-functional UI elements and APIs, and simplifies the Nexus Repository codebase.

Note

This change applies to self-hosted Nexus Repository deployments only. These capabilities were never available in Nexus Repository Cloud.

Bug Fixes in 3.90.0

The following sections group recent fixes by functional area to make them easier to scan and reference. Together, they reflect improvements across repository formats, search, HA, storage, migration, security, usability, and operational reliability.

Repository Format–Specific Fixes

These fixes address behavior specific to individual repository formats such as Docker, Maven, NuGet, Yum, APT, Helm, npm, Terraform, and RubyGems. The updates improve metadata accuracy, caching behavior, authentication handling, concurrency, and client compatibility to ensure predictable and standards-compliant interactions across all supported ecosystems.

Issue ID

Description

NEXUS-50951

From Nexus Repository version 3.89.0+, newly created Docker repositories must use lowercase names. This fix allows users to edit, via the UI, the configuration of upgraded Docker repositories that have mixed/upper case naming.

NEXUS-50929

Raw hosted repositories now support anonymous access to paths matching Terraform provider patterns when anonymous access is enabled globally.

NEXUS-50181

Optimized Docker image retrieval by digest to achieve performance comparable to tag-based pulls.

NEXUS-50105

Imported Docker images now maintain the correct content-type metadata for manifests and tags.

NEXUS-50056

Corrected the Docker tags pagination Link header to include the complete repository path.

NEXUS-49785

Enhanced Firewall quarantine checks for Docker proxy repositories to better handle concurrent pulls.

NEXUS-46841

Improved Docker token handling to reliably process concurrent authentication requests.

NEXUS-50362

Maven repositories now correctly return 404 responses for non-existent checksum signature files.

NEXUS-50243

Corrected maven-metadata.xml generation in nested Maven groups.

NEXUS-44467

Improved Maven POM uploads to correctly handle version numbers containing hyphens.

NEXUS-50205

NuGet v3 search queries now correctly handle format-specific sorting parameters.

NEXUS-45352

NuGet group repositories now retrieve cached packages from available proxy members.

NEXUS-44177

NuGet v3 search queries now return locally cached replicated packages.

NEXUS-50153

Yum group repositories now serve cached metadata during background regeneration.

NEXUS-49769

Browse UI now removes outdated Yum metadata entries after repodata regeneration.

NEXUS-43881

Improved cleanup of directory browse nodes in Yum repositories.

NEXUS-37102

Optimized thread management in APT and Yum repositories to prevent blocking during concurrent operations.

NEXUS-23790

The distribution field is now optional when configuring APT proxy repositories.

NEXUS-46491

Helm repository metadata now updates correctly following database migration.

NEXUS-50706

Improved cache invalidation for npm proxy repositories handling special-character package names.

NEXUS-50718

Terraform hosted repositories now correctly generate and expose required provider metadata.

NEXUS-49752

Firewall audits for RubyGems repositories now exclude metadata files from evaluation.

Search and Indexing

This set of fixes improves the accuracy, consistency, and performance of search operations. Enhancements address filtering logic, wildcard and token handling, database-specific behavior, and request optimization so that users and automation tools receive correct and complete results across deployment types.

Issue ID

Description

NEXUS-50711

Checksum-based searches now correctly filter results when combined with repository or format parameters.

NEXUS-50435

Improved search API handling of the prerelease parameter when using H2 databases.

NEXUS-49722

Improved search tokenization to correctly index components with underscores in group names.

NEXUS-49164

Enhanced search functionality in HA deployments to correctly handle wildcard queries with hyphens.

NEXUS-40204

Optimized HEAD request handling in proxy repositories to improve response times.

High Availability, Clustering, and Concurrency

These updates strengthen reliability in clustered and high availability deployments. They resolve state consistency issues, improve concurrency handling, clarify clustering diagnostics, and reduce the likelihood of race conditions or configuration mismatches across nodes.

Issue ID

Description

NEXUS-50277

Improved repository deletion in HA deployments to maintain consistent state across nodes.

NEXUS-50168

Added warnings for unsafe file blob store paths in HA deployments.

NEXUS-48604

Improved LDAP credential rotation handling in HA clusters.

NEXUS-46663

Parallel API requests to create content selectors now complete successfully without race conditions.

NEXUS-40099

Enhanced HA deployment log messages to clarify clustering configuration mismatches.

Blob Stores and Storage Management

These fixes focus on blob store validation, lifecycle management, and cleanup behavior. They improve correctness and resilience for both file- and S3-based storage, ensuring safe configuration, reliable deletion, and consistent data handling across UI and API operations.

Issue ID

Description

NEXUS-50503

Improved credentials provider lifecycle management for S3 blob stores using AWS IRSA.

NEXUS-44209

Compact blob store task now removes soft-deleted blobs after relocation.

NEXUS-37989

Strengthened blob store name validation across UI and REST API operations.

NEXUS-28332

Blobstore deletion now works correctly regardless of the chosen name.

Import, Export, and Migration

This group enhances upgrade, migration, import, and export workflows. The improvements ensure schema completeness, preserve metadata integrity, increase resilience to interruptions, and optimize performance when working with large or complex repositories.

Issue ID

Description

NEXUS-50612

Upgrades from versions prior to 3.67.0 now include required database schema changes.

NEXUS-50402

Asset import operations now preserve original uploader identity and IP address attributes.

NEXUS-45357

Improved repository import process to handle non-UTF-8 metadata files.

NEXUS-42488

Improved asset blob reference migration reliability after restarts or interruptions.

NEXUS-42251

Optimized repository export prerequisite checks for large repositories.

NEXUS-34351

Optimized import task performance for repositories with millions of flat-directory assets.

NEXUS-34303

Database migrator now handles assets referencing missing components with improved logging.

NEXUS-42709

Database migration logs now accurately reflect filtered records.

Security and Authentication

These changes improve system security posture and authentication reliability. They address third-party library vulnerabilities, permission model consistency, credential handling edge cases, and secure communication behavior across integrations and identity providers.

Issue ID

Description

NEXUS-50640

SAML authentication now handles reverse proxy configurations that strip cookies during the identity provider redirect process.

NEXUS-49531

Upgraded the CycloneDX core library to address an XML External Entity vulnerability.

NEXUS-47010

Updated proxy repository authentication to properly handle passwords containing special characters.

NEXUS-47819

Administrators can now remove all roles from SAML users through the API.

NEXUS-46805

Simplified permission requirements for Content Replication configuration.

NEXUS-13303

Improved email server connection handling to support plaintext SMTP when Trust Store is enabled.

UI, Permissions, and Usability

These fixes align user interface behavior with documented expectations and API behavior. They improve visibility, ordering, task reporting accuracy, and permission handling to create a more predictable and consistent administrative experience.

Issue ID

Description

NEXUS-50592

Content selectors now appear in alphabetical order in the privilege dropdown.

NEXUS-48336

Settings menu access now works correctly for users with nx-users-* privileges.

NEXUS-48281

Task duration displays now reflect actual execution time.

NEXUS-40728

Move Up and Move Down buttons now correctly reorder repositories in rebuild tasks.

Metrics, Logging, and Diagnostics

These updates enhance observability and troubleshooting. They improve log accuracy and persistence, align UI and API metrics, remove unused telemetry, and provide better diagnostic data to support operational monitoring and issue resolution.

Issue ID

Description

NEXUS-50133

Support zip log truncation now retains the most recent log entries.

NEXUS-48701

Removed the unused nexus_cluster.log file from deployments.

NEXUS-47716

Metrics displayed in the UI now align with REST API values.

NEXUS-47618

Removed unused S3 blob storage metrics from the Prometheus endpoint.

NEXUS-47362

ROOT logger level settings now persist across system restarts.

NEXUS-46315

Added JVM memory and garbage collection monitoring logs.

Configuration and Deployment

This category includes fixes that improve installation, configuration validation, and deployment workflows. The changes clarify documentation, prevent common misconfigurations, and ensure operator- and platform-based installations behave as expected.

Issue ID

Description

NEXUS-47399

Corrected PostgreSQL configuration documentation examples.

NEXUS-45379

H2 database backup task now trims whitespace from configured backup paths.

NEXUS-43752

OpenShift Operator now correctly populates the ingress TLS hosts field.

Performance and Startup Optimization

These improvements reduce startup time and operational overhead. They streamline scheduler initialization and capability loading to help instances become fully operational more quickly after restart or configuration changes.

Issue ID

Description

NEXUS-46266

Optimized Firewall Audit Capability initialization to reduce startup time.

NEXUS-50273

Improved Quartz scheduler initialization to reduce restart delays.

Known Issues & Upgrade Guidance

This section captures known issues in the 3.90.x line as well as upgrade guidance.

Impacted Version(s)

Version in which Issue is Resolved

Description

3.90.2

3.92.0 and 3.90.4

Sonatype is aware of an issue in Sonatype Nexus Repository 3.90.2 where npm group repositories may serve stale package metadata after upstream repositories are updated. This issue is fixed in version 3.92.0.

This issue occurs when requesting packages with versions or dist-tags (for example, npm install storybook@latest or npm install @sonatype/[email protected]). The cache invalidation process fails, causing the group repository to return outdated version information.

Symptoms may include:

  • npm builds failing with version mismatch errors.

  • Recently published package versions not visible through the group repository

  • Server logs showing errors such as: IllegalArgumentException: Non URL-safe name

Workaround

Manually invalidate the package cache through the Nexus UI: Browse → Select repository → Right-click package → Invalidate cache

3.90.x – 3.92.x

3.93.0

Sonatype is aware of an issue affecting Sonatype Nexus Repository deployments that use Maven group repositories with Maven proxy repositories as direct members.

When a Maven group repository has proxy repositories as direct members, the group may serve its cached merged `maven-metadata.xml indefinitely without rechecking the proxy members. This can occur even when the proxy repositories are configured with metadataMaxAge=0, causing Maven or Gradle clients to miss newly deployed SNAPSHOT versions from upstream repositories.

This issue affects flat Maven group repositories with direct proxy members. Direct requests to the proxy repositories continue to honor the proxy metadata cache setting.

Workaround

If you use Maven group repositories with direct proxy members, upgrade to Nexus Repository 3.93.0. Until you can upgrade, manually invalidate the affected group repository cache after upstream deployments by using the repository invalidate-cache REST endpoint.

Coming Soon

Change to Nexus Repository Docker Image Base and Tagging

As of 3.91.0, the base nexus3 image will be built off of alpine instead of ubi. This should be an invisible change for anyone using our image from dockerhub. If you are building an image off of our image, you will need to update your build process. Effective with 3.94.0, we will no longer publish new versions of the nexus3 image with the -ubi and -alpine suffix.

Change to Private Network Blocking Default Behavior

Sonatype Nexus Repository will soon block private networks by default. Customers are encouraged to review their configurations for any internal IP addresses or private network ranges and update them as needed to prevent service disruptions.

Note that this is a change to the default behavior only; you will still be able to configure this setting to allow private network access if your deployment requires it.

This update is designed to improve security by preventing unauthorized or unintended access from Nexus Repository to internal services. It helps protect production environments where repository administrators should not be able to connect to arbitrary internal endpoints.

Note that this was previously planned to become the default behavior in the 3.90.0 release; however, we have delayed its implementation to a future release.