Sonatype Nexus Repository 3.90.0 - 3.90.5 Release Notes
Ready to Upgrade?
Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.
What's New in 3.90.5?
Released August 17, 2026
This release introduces the following bug fixes to the 3.90.x release line:
Issue ID | Description |
|---|---|
NEXUS-50761 | Sonatype Nexus Repository now considers all assigned roles and privileges when browsing repository content, allowing users with content selector privileges to view content permitted by their other roles. |
NEXUS-50690 | npm v1 searches now return results as expected in PostgreSQL environments. |
NEXUS-47909 | Maven group repositories now serve |
What's New in 3.90.4?
Released July 2, 2026
This release backports the following bug fixes to the 3.90.x release line:
Issue ID | Description |
|---|---|
NEXUS-52952 | The npm proxy repository Invalidate Cache operation now completes as expected without browser timeout errors caused by long-running per-asset cache invalidation operations. |
NEXUS-52362 | Maven group repositories now honor the lowest |
NEXUS-51520 | npm group repositories now correctly invalidate cached metadata when upstream proxy repositories apply PCCS filtering. Metadata invalidation now completes successfully for npm group repositories when versioned package paths are requested, ensuring that cache updates propagate correctly when PCCS or IQ policies filter available versions in upstream proxies. |
NEXUS-51319 | npm proxy repositories now send valid ETags, ensuring cached tarballs return 304 responses instead of triggering re-downloads. |
NEXUS-50552 | The Browse menu now appears for users who have content selector privileges with browse action, matching the visibility behavior of standard repository-view permissions. |
What's New in 3.90.3?
Released April 8, 2026
Note
Sonatype Nexus Repository 3.90.3 is available for download from the Nexus Repository 3 Download archive.
Added Skip Processing Configuration
NEXUS-51666 – Added a skipProcessing configuration option to BlobRepositoryMismatchTask for eligible direct upgrades. See our Support Knowledgebase article for details.
What's New in 3.90.2?
Released March 23, 2026
New Instance Migrator Helps Nexus Repository 3.70.5 Deployments Move to Nexus Repository Cloud or Self-Hosted Nexus Repository 3.90.2 Without Downtime
Sonatype Nexus Repository now provides a migration path from OrientDB 3.70.5 to modern, supported platforms without requiring service interruption. With the new Instance migrator, you can migrate to either of the following without downtime:
Nexus Repository Cloud
Nexus Repository self-hosted version 3.90.2+
Migration preserves core configuration and repository data, enabling a seamless transition to a more scalable and supported architecture.
Key Capabilities
Preserves repository data and configuration
Migrates hosted repository content, repository configurations, and associated settings to the target environment.
Maintains user and access configurations
Transfers users, roles, and authentication mappings to ensure continuity of access control.
Secure handling of sensitive data
Encrypts and transfers secrets using supported security standards during migration.
Automated validation checks
Prevents invalid configurations, such as missing blob stores, and provides clear feedback during migration.
No service interruption
Keeps your source instance online and operational throughout the migration process.
Important Migration Requirements
Blob stores must exist on the target instance
Create blob stores in the target environment before migration. Do not reuse storage locations from the source instance.
Shared storage is not supported
Using the same S3 bucket, Azure container, or file path across source and target instances can lead to data corruption.
LDAP/Crowd users require external server configuration
While user tokens and role mappings for LDAP/Crowd users will migrate successfully, the target instance must be manually configured to connect to the same external authentication servers for these users to authenticate after migration.
Some configurations require manual setup
SSL/TLS certificates export from the source but may require manual import configuration on the target instance depending on your environment.
Proxy/group repository cached content does not migrate
Only hosted repository content is migrated.
For full migration requirements and process details, see the Instance Migrator help documentation. You can download the instance migrator for version 3.70.5 from the OrientDB Downloads page.
Bug Fixes in 3.90.2
This release includes the following additional bug fixes
Issue ID | Description |
|---|---|
NEXUS-51040 | Docker proxy repositories handle bearer token authentication requests without encountering null pointer exceptions during HTTP context operations. |
NEXUS-50764 & NEXUS-39228 | Group repositories now properly detect policy-filtered version changes in member proxy repositories, ensuring metadata remains current and complete across npm and PyPI formats. |
What's New in 3.90.1?
Released March 6, 2026
Fix for Nexus Repository 3.90.0 Community Edition
This release fixes an issue that prevented Sonatype Nexus Repository 3.90.0 Community Edition deployments from starting upon initial installation or upgrade.
Community Edition users can now safely upgrade to 3.90.1.
What’s New in 3.90.0?
Released March 5, 2026
Support for Terraform Group Repositories
Sonatype Nexus Repository now supports the Terraform group repositories, allowing you to aggregate multiple Terraform hosted and proxy repositories into a single endpoint. This capability simplifies configuration for developers by providing one consistent URL for Terraform modules and providers, while centralizing control and visibility for repository administrators.
Terraform group repositories include intelligent caching with configurable TTL values for modules and provider versions, along with request deduplication to reduce redundant upstream queries. When the same version exists in multiple member repositories, you can apply configurable conflict resolution strategies to determine which artifact is served. The implementation also tracks member health and automatically handles unhealthy members, while exposing comprehensive metrics to help you monitor cache performance and overall repository health.
For full details, see the Terraform Repositories help documentation.
Support for Swift Hosted Repositories
Sonatype Nexus Repository now supports Swift hosted repositories, enabling you to publish and manage Swift packages as .zip files with MIME type validation. This capability allows teams to securely store and distribute internal Swift artifacts and approved third-party components through Nexus Repository, providing a centralized and reliable source for Swift dependencies.
Swift hosted repositories support enterprise controls such as access management and auditing, along with optional anonymous access where appropriate. For full details, see the Swift Repositories help documentation.
Re-enabled Repair - Execute Data Repair Plan Task
In Sonatype Nexus Repository 3.90.0, the Repair - Execute Data Repair Plan task is re-enabled by default. We previously disabled this task in 3.88.0 to prevent potential data loss while we addressed issues affecting the Verify and Repair and Data Repair Plan tasks.
You can now safely use the Repair - Execute Data Repair Plan task to correct data inconsistencies between the database and blob store. This update restores the intended maintenance workflow and allows you to run data repair operations with confidence.
This re-enablement aligns with the introduction of Recovery Mode, which provides a controlled operational state to help protect data integrity during repair and reconciliation activities.
New Recovery Mode for Safe Data Reconciliation
Sonatype Nexus Repository now includes Recovery Mode, a controlled operational state designed to support safe reconciliation between the database and blob storage after outages or data inconsistencies. When enabled, Recovery Mode helps protect data integrity by preventing specific background tasks from interfering with repair operations. This feature is available only for self-hosted deployments and requires administrative privileges. Before enabling Recovery Mode, consult Sonatype Support to confirm it is appropriate for your situation.
For full details, see the Recovery Mode help documentation.
New User Token API
A new User Token API allows administrators to create, view, and delete user tokens. With the appropriate privileges, administrators can generate tokens for specific users and realms, retrieve token summaries (excluding sensitive fields), and manage tokens across individual or all realms, including options to include expired tokens in responses.
For full details, see the User Token API help documentation.
Improved Transparency for Policy-Compliant Component Selection in npm Metadata
Sonatype Nexus Repository now enhances policy-compliant component selection (PCCS) by exposing filtered npm package versions directly in the package metadata. When PCCS filters versions that violate your Repository Firewall policies, those versions appear in the sonatype_filtered_versions field in the component's metadata. This update provides clearer visibility into which versions were excluded, helping teams quickly understand why a version is unavailable and identify an acceptable alternative.
Granular Permissions for Log Management API in Nexus Repository Cloud Environments
Sonatype Nexus Repository Cloud now supports more granular access control for the Log Management API. Previously, access to the Log Management API required the broad nexus:* permission, which is granted only to the nx-admin role. You can now grant access to this API using the built-in nexus:logging:read permission and the associated nx-logging-read privilege. This update enables teams to follow the principle of least privilege by allowing service accounts to download logs without granting administrative access across the entire tenant.
Removed Legacy Application Health Check and Hosted Repository Analysis
In this release, we removed the legacy Application Health Check plugin from Sonatype Nexus Repository. This plugin previously provided both Application Health Check and Hosted Repository Analysis capabilities.
Sonatype Lifecycle replaces these capabilities with more robust and fully supported software composition analysis. Lifecycle offers CLI-based scans, binary uploads, comprehensive policy evaluation, and continuous monitoring across your development lifecycle.
Removing these features reduces technical debt, eliminates non-functional UI elements and APIs, and simplifies the Nexus Repository codebase.
Note
This change applies to self-hosted Nexus Repository deployments only. These capabilities were never available in Nexus Repository Cloud.
Bug Fixes in 3.90.0
The following sections group recent fixes by functional area to make them easier to scan and reference. Together, they reflect improvements across repository formats, search, HA, storage, migration, security, usability, and operational reliability.
Repository Format–Specific Fixes
These fixes address behavior specific to individual repository formats such as Docker, Maven, NuGet, Yum, APT, Helm, npm, Terraform, and RubyGems. The updates improve metadata accuracy, caching behavior, authentication handling, concurrency, and client compatibility to ensure predictable and standards-compliant interactions across all supported ecosystems.
Issue ID | Description |
|---|---|
NEXUS-50951 | From Nexus Repository version 3.89.0+, newly created Docker repositories must use lowercase names. This fix allows users to edit, via the UI, the configuration of upgraded Docker repositories that have mixed/upper case naming. |
NEXUS-50929 | Raw hosted repositories now support anonymous access to paths matching Terraform provider patterns when anonymous access is enabled globally. |
NEXUS-50181 | Optimized Docker image retrieval by digest to achieve performance comparable to tag-based pulls. |
NEXUS-50105 | Imported Docker images now maintain the correct content-type metadata for manifests and tags. |
NEXUS-50056 | Corrected the Docker tags pagination Link header to include the complete repository path. |
NEXUS-49785 | Enhanced Firewall quarantine checks for Docker proxy repositories to better handle concurrent pulls. |
NEXUS-46841 | Improved Docker token handling to reliably process concurrent authentication requests. |
NEXUS-50362 | Maven repositories now correctly return 404 responses for non-existent checksum signature files. |
NEXUS-50243 | Corrected maven-metadata.xml generation in nested Maven groups. |
NEXUS-44467 | Improved Maven POM uploads to correctly handle version numbers containing hyphens. |
NEXUS-50205 | NuGet v3 search queries now correctly handle format-specific sorting parameters. |
NEXUS-45352 | NuGet group repositories now retrieve cached packages from available proxy members. |
NEXUS-44177 | NuGet v3 search queries now return locally cached replicated packages. |
NEXUS-50153 | Yum group repositories now serve cached metadata during background regeneration. |
NEXUS-49769 | Browse UI now removes outdated Yum metadata entries after repodata regeneration. |
NEXUS-43881 | Improved cleanup of directory browse nodes in Yum repositories. |
NEXUS-37102 | Optimized thread management in APT and Yum repositories to prevent blocking during concurrent operations. |
NEXUS-23790 | The distribution field is now optional when configuring APT proxy repositories. |
NEXUS-46491 | Helm repository metadata now updates correctly following database migration. |
NEXUS-50706 | Improved cache invalidation for npm proxy repositories handling special-character package names. |
NEXUS-50718 | Terraform hosted repositories now correctly generate and expose required provider metadata. |
NEXUS-49752 | Firewall audits for RubyGems repositories now exclude metadata files from evaluation. |
Search and Indexing
This set of fixes improves the accuracy, consistency, and performance of search operations. Enhancements address filtering logic, wildcard and token handling, database-specific behavior, and request optimization so that users and automation tools receive correct and complete results across deployment types.
Issue ID | Description |
|---|---|
NEXUS-50711 | Checksum-based searches now correctly filter results when combined with repository or format parameters. |
NEXUS-50435 | Improved search API handling of the |
NEXUS-49722 | Improved search tokenization to correctly index components with underscores in group names. |
NEXUS-49164 | Enhanced search functionality in HA deployments to correctly handle wildcard queries with hyphens. |
NEXUS-40204 | Optimized HEAD request handling in proxy repositories to improve response times. |
High Availability, Clustering, and Concurrency
These updates strengthen reliability in clustered and high availability deployments. They resolve state consistency issues, improve concurrency handling, clarify clustering diagnostics, and reduce the likelihood of race conditions or configuration mismatches across nodes.
Issue ID | Description |
|---|---|
NEXUS-50277 | Improved repository deletion in HA deployments to maintain consistent state across nodes. |
NEXUS-50168 | Added warnings for unsafe file blob store paths in HA deployments. |
NEXUS-48604 | Improved LDAP credential rotation handling in HA clusters. |
NEXUS-46663 | Parallel API requests to create content selectors now complete successfully without race conditions. |
NEXUS-40099 | Enhanced HA deployment log messages to clarify clustering configuration mismatches. |
Blob Stores and Storage Management
These fixes focus on blob store validation, lifecycle management, and cleanup behavior. They improve correctness and resilience for both file- and S3-based storage, ensuring safe configuration, reliable deletion, and consistent data handling across UI and API operations.
Issue ID | Description |
|---|---|
NEXUS-50503 | Improved credentials provider lifecycle management for S3 blob stores using AWS IRSA. |
NEXUS-44209 | Compact blob store task now removes soft-deleted blobs after relocation. |
NEXUS-37989 | Strengthened blob store name validation across UI and REST API operations. |
NEXUS-28332 | Blobstore deletion now works correctly regardless of the chosen name. |
Import, Export, and Migration
This group enhances upgrade, migration, import, and export workflows. The improvements ensure schema completeness, preserve metadata integrity, increase resilience to interruptions, and optimize performance when working with large or complex repositories.
Issue ID | Description |
|---|---|
NEXUS-50612 | Upgrades from versions prior to 3.67.0 now include required database schema changes. |
NEXUS-50402 | Asset import operations now preserve original uploader identity and IP address attributes. |
NEXUS-45357 | Improved repository import process to handle non-UTF-8 metadata files. |
NEXUS-42488 | Improved asset blob reference migration reliability after restarts or interruptions. |
NEXUS-42251 | Optimized repository export prerequisite checks for large repositories. |
NEXUS-34351 | Optimized import task performance for repositories with millions of flat-directory assets. |
NEXUS-34303 | Database migrator now handles assets referencing missing components with improved logging. |
NEXUS-42709 | Database migration logs now accurately reflect filtered records. |
Security and Authentication
These changes improve system security posture and authentication reliability. They address third-party library vulnerabilities, permission model consistency, credential handling edge cases, and secure communication behavior across integrations and identity providers.
Issue ID | Description |
|---|---|
NEXUS-50640 | SAML authentication now handles reverse proxy configurations that strip cookies during the identity provider redirect process. |
NEXUS-49531 | Upgraded the CycloneDX core library to address an XML External Entity vulnerability. |
NEXUS-47010 | Updated proxy repository authentication to properly handle passwords containing special characters. |
NEXUS-47819 | Administrators can now remove all roles from SAML users through the API. |
NEXUS-46805 | Simplified permission requirements for Content Replication configuration. |
NEXUS-13303 | Improved email server connection handling to support plaintext SMTP when Trust Store is enabled. |
UI, Permissions, and Usability
These fixes align user interface behavior with documented expectations and API behavior. They improve visibility, ordering, task reporting accuracy, and permission handling to create a more predictable and consistent administrative experience.
Issue ID | Description |
|---|---|
NEXUS-50592 | Content selectors now appear in alphabetical order in the privilege dropdown. |
NEXUS-48336 | Settings menu access now works correctly for users with |
NEXUS-48281 | Task duration displays now reflect actual execution time. |
NEXUS-40728 | Move Up and Move Down buttons now correctly reorder repositories in rebuild tasks. |
Metrics, Logging, and Diagnostics
These updates enhance observability and troubleshooting. They improve log accuracy and persistence, align UI and API metrics, remove unused telemetry, and provide better diagnostic data to support operational monitoring and issue resolution.
Issue ID | Description |
|---|---|
NEXUS-50133 | Support zip log truncation now retains the most recent log entries. |
NEXUS-48701 | Removed the unused nexus_cluster.log file from deployments. |
NEXUS-47716 | Metrics displayed in the UI now align with REST API values. |
NEXUS-47618 | Removed unused S3 blob storage metrics from the Prometheus endpoint. |
NEXUS-47362 | ROOT logger level settings now persist across system restarts. |
NEXUS-46315 | Added JVM memory and garbage collection monitoring logs. |
Configuration and Deployment
This category includes fixes that improve installation, configuration validation, and deployment workflows. The changes clarify documentation, prevent common misconfigurations, and ensure operator- and platform-based installations behave as expected.
Issue ID | Description |
|---|---|
NEXUS-47399 | Corrected PostgreSQL configuration documentation examples. |
NEXUS-45379 | H2 database backup task now trims whitespace from configured backup paths. |
NEXUS-43752 | OpenShift Operator now correctly populates the ingress TLS hosts field. |
Performance and Startup Optimization
These improvements reduce startup time and operational overhead. They streamline scheduler initialization and capability loading to help instances become fully operational more quickly after restart or configuration changes.
Issue ID | Description |
|---|---|
NEXUS-46266 | Optimized Firewall Audit Capability initialization to reduce startup time. |
NEXUS-50273 | Improved Quartz scheduler initialization to reduce restart delays. |
Known Issues & Upgrade Guidance
This section captures known issues in the 3.90.x line as well as upgrade guidance.
Impacted Version(s) | Version in which Issue is Resolved | Description |
|---|---|---|
3.90.2 | 3.92.0 and 3.90.4 | Sonatype is aware of an issue in Sonatype Nexus Repository 3.90.2 where npm group repositories may serve stale package metadata after upstream repositories are updated. This issue is fixed in version 3.92.0. This issue occurs when requesting packages with versions or dist-tags (for example, Symptoms may include:
Workaround Manually invalidate the package cache through the Nexus UI: Browse → Select repository → Right-click package → |
3.90.x – 3.92.x | 3.93.0 | Sonatype is aware of an issue affecting Sonatype Nexus Repository deployments that use Maven group repositories with Maven proxy repositories as direct members. When a Maven group repository has proxy repositories as direct members, the group may serve its cached merged ` This issue affects flat Maven group repositories with direct proxy members. Direct requests to the proxy repositories continue to honor the proxy metadata cache setting. Workaround If you use Maven group repositories with direct proxy members, upgrade to Nexus Repository 3.93.0. Until you can upgrade, manually invalidate the affected group repository cache after upstream deployments by using the repository |
Coming Soon
Change to Nexus Repository Docker Image Base and Tagging
As of 3.91.0, the base nexus3 image will be built off of alpine instead of ubi. This should be an invisible change for anyone using our image from dockerhub. If you are building an image off of our image, you will need to update your build process. Effective with 3.94.0, we will no longer publish new versions of the nexus3 image with the -ubi and -alpine suffix.
Change to Private Network Blocking Default Behavior
Sonatype Nexus Repository will soon block private networks by default. Customers are encouraged to review their configurations for any internal IP addresses or private network ranges and update them as needed to prevent service disruptions.
Note that this is a change to the default behavior only; you will still be able to configure this setting to allow private network access if your deployment requires it.
This update is designed to improve security by preventing unauthorized or unintended access from Nexus Repository to internal services. It helps protect production environments where repository administrators should not be able to connect to arbitrary internal endpoints.
Note that this was previously planned to become the default behavior in the 3.90.0 release; however, we have delayed its implementation to a future release.