Skip to main content

Sonatype Nexus Repository 3.92.0 - 3.92.3 Release Notes

The Sonatype Nexus Repository 3.92.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!

Ready to Upgrade?

Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.

What's New and Noteworthy in 3.92.3?

Released May 26, 2026

Additional Bug Fixes in 3.92.3

Sonatype Nexus Repository 3.92.3 contains the following additional bug fixes:

Issue ID

Description

NEXUS-52781

Search indexing for NuGet V2 proxy repositories now completes successfully when cached components contain empty package names, preventing PostgreSQL constraint violations during repository search rebuilds and upgrades.

NEXUS-52635

Concurrent npm and PyPI proxy requests under PCCS now coalesce across cluster nodes, preventing uncoordinated IQ Server evaluation calls that could exhaust heap memory and cause a full Firewall outage. (This fix requires IQ 204+ and Nexus Repository 3.92.3+.)

NEXUS-52434

PCCS evaluation results for npm and PyPI proxy repositories are now reused within the configured metadata cache window, improving performance for packages with large version counts.

What's New and Noteworthy in 3.92.2?

Released May 13, 2026

Additional Bug Fixes in 3.92.2

Sonatype Nexus Repository 3.92.2 contains the following additional bug fix:

Issue ID

Description

NEXUS-52588

This self-hosted-only patch release fixes an issue in 3.92.0 and 3.92.1 that caused the user interface in Community Edition deployments to freeze and become unresponsive after startup.

What's New and Noteworthy in 3.92.1?

Released May 12, 2026

Additional Bug Fixes in 3.92.1

Sonatype Nexus Repository 3.92.1 contains the following additional bug fix:

Issue ID

Description

NEXUS-52538

Self-hosted Sonatype Nexus Repository instances configured with a non-root context path (for example, /nxrm) now correctly load and navigate when users access URLs without a hash fragment.

What’s New and Noteworthy in 3.92.0?

Released May 7, 2026

Get a First Look at Sonatype Nexus Repository’s New User Interface

You can now preview a redesigned user experience in Sonatype Nexus Repository using a Switch to Nexus One UI toggle. This update introduces a more streamlined interface built to reduce clicks, improve navigation, and make repository search and browsing more intuitive. The new design aligns Nexus Repository with Sonatype’s other solutions, creating a more consistent experience across the Sonatype platform while lowering training overhead and cognitive load for users.

Untitled - Frame 3.jpg

To access the preview, an administrator must first enable the feature under Settings > System > Nexus One UI. Some areas are still under development and will appear as Coming Soon, including Users, Roles, Privileges, Upgrade, and Licensing. You can also provide feedback directly within the UI to help guide ongoing improvements as we continue to expand coverage and accelerate feature delivery.

Pub Repository Support for Dart and Flutter

Sonatype Nexus Repository now supports Pub repositories, enabling you to manage Dart and Flutter packages directly within your repository manager. With support for proxy, hosted, and group repositories, you can centralize access to public packages from pub.dev, publish internal packages with versioned metadata and checksums, and aggregate multiple repositories into a single endpoint. This integration helps improve control over package consumption and distribution while reducing reliance on external sources.

For full details, see the Pub repositories help documentation.

Support for Conda Hosted and Group Repositories

Sonatype Nexus Repository now includes hosted and group repository support for Conda, providing a complete solution for managing Python and data science packages.

With hosted repositories, you can publish proprietary Conda packages with full version control and automatically generated metadata. Group repositories allow you to combine proxy, hosted, and other group repositories into a single endpoint, simplifying client configuration and enabling unified package resolution. These enhancements make it easier to manage Conda ecosystems at scale while improving consistency and efficiency across development workflows.

For full details, see the Conda repositories help documentation.

Support for Helm Group Repositories

Sonatype Nexus Repository now supports Helm group repositories, allowing you to expose multiple Helm repositories through a single URL. By combining proxy, hosted, and other group repositories into one endpoint, you can simplify dependency management and reduce the need for complex client-side configuration.

For dull details, see the Helm repositories help documentation.

Instance Migrator Support for Migrating Swift, Terraform, and Conda Hosted Repositories

The Sonatype Nexus Repository Instance Migrator now supports migrating Swift, Terraform, and Conda hosted repositories, making it easier to move modern package ecosystems between instances. This enhancement helps you migrate critical artifacts and repository configurations with greater confidence, reducing manual effort and minimizing disruption during upgrades, consolidations, or infrastructure changes.

The migrator focuses on transferring essential package assets, such as Swift package archives and manifests, Terraform provider and module packages (including associated checksum and signature files), and Conda package binaries across supported architectures. Automatically generated metadata is excluded during migration and regenerated on the target instance, helping ensure consistency and integrity without unnecessary data transfer. This approach streamlines migrations while preserving repository structure and expected package behavior.

For setup and technical details, see the Instance Migrator help documentation.

Database Connection Pool Metrics Accessible via API

Sonatype Nexus Repository now exposes HikariCP database connection pool metrics through the Service Metrics Data API, providing deeper insight into system health and database utilization. You can track active, idle, total, and pending connections across connection pools, helping you better understand real-time demand and identify potential bottlenecks.

With this added visibility, you can make more informed decisions about connection pool sizing and quickly troubleshoot performance issues without relying on external monitoring. Note that this API does not appear in the in-product Swagger; instead, check out our Service Metrics Data API help documentation for details.

Server-Side Request Forgery (SSRF) Protection Enabled by Default and New SSRF API Endpoint

Sonatype Nexus Repository now enables SSRF protection by default for new installations, helping you secure outbound connections and reduce exposure to malicious requests without requiring additional setup. Existing installations are not impacted by this change, avoiding unintended service disruption. You can review your configuration, add trusted internal endpoints to an allowlist, and enable protection when ready.

This release also introduces a new administrative API to manage SSRF protection settings, giving you more flexible and centralized control over enablement and configuration. For full details, see the help documentation on securing Nexus Repository.

Usage Insights Dashboard Retains Daily Storage Metrics

The Usage Insights dashboard now retains daily storage metrics indefinitely, giving you a complete and uninterrupted view of storage trends over time. By aligning storage retention with the existing egress metrics model, this update eliminates gaps in historical data and provides more reliable long-term visibility.

With continuous access to storage usage history, you can better analyze growth patterns, support capacity planning, and make more informed decisions about repository management without losing critical historical context.

Webhook Support for Repository Firewall Events

Sonatype Repository Firewall now supports webhooks, providing real-time notifications when components are blocked or quarantined due to policy violations. This allows you to integrate Firewall events with external systems for faster incident response, alerting, and automation.

Webhook payloads include key details such as policy violations, threat levels, and component identifiers, helping you quickly understand and act on security events. Notifications also distinguish between new quarantines and repeated access attempts, giving you clear and actionable insight into Firewall activity.

For full details, see the Firewall Webhooks help documentation.

Firewall Bulk Waivers for Faster Quarantine Management

Sonatype Repository Firewall now supports Bulk Waivers, allowing you to waive multiple policy violations at one time while applying consistent scope, expiration, and context. This reduces manual effort and helps prevent inconsistencies when managing quarantined components across repositories.

Bulk Waivers are available directly from Repository Results or Component Details, making it easier to take action where quarantine status is visible. Built-in safeguards for unknown or unclaimed components help maintain control, while a complete audit trail ensures traceability for all actions.

For full details, see the Firewall Bulk Waivers and Bulk Waivers API help documentation.

Bug Fixes

Issue ID

Description

NEXUS-52952

The npm proxy repository Invalidate Cache operation now completes as expected without browser timeout errors caused by long-running per-asset cache invalidation operations.

NEXUS-52054

Terraform hosted repository signing key material and passphrase are now redacted in support zip exports.

NEXUS-51930

Firewall policy evaluation now applies to conditional GET requests (If-None-Match / If-Modified-Since), ensuring quarantined components return 403 Forbidden rather than 304 Not Modified.

NEXUS-51926

Raw repository searches that use trailing wildcards in the group field return matching assets as expected.

NEXUS-51882

PyPI hosted repository metadata stays consistent during concurrent uploads, with index assets marked as stale and rebuilt on demand rather than deleted mid-operation.

NEXUS-51864

Version-specific npm requests (e.g., /package/latest) no longer invalidate the PCCS cache, ensuring subsequent full metadata requests return the complete set of available package versions.

NEXUS-51814

Docker tag pagination Link headers now preserve the original connector-based request path, allowing clients to correctly retrieve subsequent pages of tags.

NEXUS-51795

The user-configured SAML Entity ID URI now takes precedence over the browser URL when building SP metadata and authentication requests.

NEXUS-51699

The BlobRepositoryMismatchTask now saves per-repository progress checkpoints, resumes after node restart, logs completion status and throughput, and scales thread count based on CPU cores.

NEXUS-51659

The Search API now returns a 400 error with a descriptive message when unsupported wildcard patterns are used in the repository name field.

NEXUS-51633

PyPI repository indexes are automatically invalidated and rebuilt on the next client request following a "Verify and Repair" blob restore operation.

NEXUS-51540

Maven group repository metadata propagates correctly through all nesting levels when new component versions are uploaded.

NEXUS-51523

The Repair - Data Repair Plan task summary log now reports "created plan entries" instead of "created plans."

NEXUS-51509

Concurrent Policy Compliant Component Selection requests are now deduplicated, reducing redundant upstream evaluations.

NEXUS-51485

Docker pull errors for quarantined images now include the quarantine reason and IQ report URL directly in the response body.

NEXUS-51397

The repository.blob.mismatch.task upgrade task now processes blobs concurrently without blocking other upgrade tasks.

NEXUS-51391

Content selectors using "starts with" expressions now correctly filter results for short path segments.

NEXUS-51389

Repositories that fail to initialize during startup are now skipped and marked offline, allowing Nexus Repository to start successfully without being blocked by individual repository failures.

NEXUS-51334

Fallback member retrieval in npm group repositories now logs clearer DEBUG-level messages without misleading Firewall references.

NEXUS-51327

Wildcard component name searches against paths with leading slashes now return correct results across all formats.

NEXUS-51319

npm proxy repositories now send valid ETags, ensuring cached tarballs return 304 responses instead of triggering re-downloads.

NEXUS-51283

This fix changes RubyGems metadata behavior so uploads trigger incremental index updates rather than full repository rebuilds.

NEXUS-51282

Download URLs in UI search results now point to the group repository path, allowing access without 403 errors.

NEXUS-51281

The Firewall Proprietary Names task now correctly implements the Cancelable interface.

NEXUS-51279

Search API requests using unsupported wildcard patterns now return HTTP 400 with a descriptive error message.

NEXUS-51267

Failed login attempts are again captured in the audit log with user ID, IP, and failure reason.

NEXUS-51266

text_pattern_ops indexes enable efficient prefix searches, eliminating slow sequential scans on large databases.

NEXUS-51247

Concurrent requests for the same component no longer generate ERROR-level log entries during blob property updates.

NEXUS-51112

Policy Compliant Component Selection now uses an increased timeout for PyPI metadata evaluation, supporting large packages.

NEXUS-50971

Upgrade ensures LDAP configuration events deserialize correctly across HA nodes, preventing REST API failures.

NEXUS-50945

OAuth2/OIDC authentication now uses Nexus’s managed HTTP client, supporting truststore and proxy settings.

NEXUS-50782

NuGet v2 proxy repositories now follow OData pagination links, ensuring all package versions are retrieved.

NEXUS-49855

Prefix wildcard searches now correctly match only components that begin with the specified term.

NEXUS-48607

The UI no longer experiences delays on initial load when telemetry endpoints are unreachable.

NEXUS-43728

Audit logs in HA clusters now record blob store creation events only on the originating node.

NEXUS-40929

The Health Check column automatically hides from Browse and Repositories pages when IQ Server Firewall is enabled, preventing unnecessary API calls since Firewall provides vulnerability data directly.

NEXUS-51520

npm group repositories now correctly invalidate cached metadata when upstream proxy repositories apply PCCS filtering. Metadata invalidation now completes successfully for npm group repositories when versioned package paths are requested, ensuring that cache updates propagate correctly when PCCS or IQ policies filter available versions in upstream proxies.

Known Issues & Upgrade Guidance

This section captures known issues in the 3.92.x line as well as upgrade guidance.

Resolved Known Issues

Impacted Version(s)

Version in which Issue is Resolved

Description

3.91.x – 3.93.0

3.93.1

When a PyPI proxy repository points to a remote repository that returns relative links for Python wheel files, Nexus Repository may incorrectly resolve those links when constructing the upstream download request. This can result in invalid upstream URLs and HTTP 404 responses returned to Python clients.

This issue is known to affect chained PyPI proxy configurations where one Nexus Repository instance proxies another Nexus Repository instance. PyPI proxy repositories configured to proxy PyPI.org directly are not known to be affected.

This issue is fixed in Nexus Repository 3.93.1. If you use chained PyPI proxy repositories with another Nexus Repository instance as the remote, upgrade to Nexus Repository 3.93.1.

3.90.x – 3.92.x

3.93.0

When a Maven group repository has proxy repositories as direct members, the group may serve its cached merged maven-metadata.xml indefinitely without rechecking the proxy members. This can occur even when the proxy repositories are configured with metadataMaxAge=0, causing Maven or Gradle clients to miss newly deployed SNAPSHOT versions from upstream repositories.

This issue affects flat Maven group repositories with direct proxy members. Direct requests to the proxy repositories continue to honor the proxy metadata cache setting.

If you use Maven group repositories with direct proxy members, upgrade to Nexus Repository 3.93.0. Until you can upgrade, manually invalidate the affected group repository cache after upstream deployments by using the repository invalidate-cache REST endpoint.

3.92.0 – 3.92.2

3.92.3

Upgrading can cause the search indexer to fail if a NuGet V2 proxy repository contains a cached package with an empty component name. When this occurs, search indexing fails for all repositories with a PostgreSQL constraint violation. The underlying NuGet data is not affected.

If you have NuGet V2 proxy repositories, do not upgrade to version 3.92.0 – 3.92.2; upgrade to 3.92.3+ instead.