Sonatype Nexus Repository 3.94.0 – 3.94.2 Release Notes
The Sonatype Nexus Repository 3.94.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!
Release Timeline
3.94.0 – July 9, 2026
3.94.1 – July 24, 2026
3.94.2 – August 27, 2026
Check Known Issues Before Upgrading
This version line contains known issues.
Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.
What’s New and Noteworthy in This Release?
The Sonatype Nexus Repository 3.94.x release line includes the following new features and enhancements:
Repository Firewall: Support for conda-forge Upstreams
Sonatype Repository Firewall now supports conda-forge as an upstream for conda proxy repositories. You can configure a conda proxy repository to use the conda-forge upstream and apply Repository Firewall policies to packages retrieved from that source, expanding protection to one of the most widely used community-managed conda repositories.
This enhancement gives organizations greater flexibility when adopting conda while maintaining the same security and governance workflows they rely on for other supported package ecosystems. Customers who depend on packages from conda-forge can now confidently proxy that upstream through Repository Firewall and enforce quarantine and policy evaluation before components reach development environments.
Support for Open Container Initiative (OCI) Repositories
Sonatype Nexus Repository now supports native Open Container Initiative (OCI) hosted, proxy, and group repositories, giving you a single solution for managing container images and other OCI artifacts throughout your software supply chain. You can proxy content from external OCI registries, publish and protect internally developed artifacts, and expose multiple repositories through a single endpoint to simplify client configuration and artifact management.
This new repository format supports standard OCI-compatible tools, including Docker, Podman, Helm, ORAS, Cosign, Syft, Crane, and Skopeo, making it easier to adopt OCI workflows without changing existing tooling. In addition to container images, Nexus Repository can store and distribute Helm charts, Software Bills of Materials (SBOMs), signatures, attestations, and other OCI artifacts, helping organizations centralize artifact management while supporting modern software supply chain and container security practices.
For full details, see the OCI Repositories help documentation.
Proxy Private Amazon Elastic Container Registry (ECR) Registries with Docker Repositories
Sonatype Nexus Repository now supports proxying private Amazon ECR registries through Docker proxy repositories. You can configure a Docker proxy repository by providing your AWS account's ECR registry URL along with AWS IAM credentials, allowing Nexus Repository to centrally cache and serve container images stored in private ECR registries.
To simplify authentication, Nexus Repository automatically retrieves and caches the ECR authorization token on the first image pull using your configured AWS credentials. This capability reduces repeated authorization calls to Amazon ECR, lowers data transfer costs, and provides a consistent image source for development and CI/CD environments.
For full details, see the Proxy Repository for Docker help documentation.
PyPI Simple API v1.1 Support for Faster Dependency Resolution
Sonatype Nexus Repository now supports Simple API v1.1 (PEP 700) for PyPI repositories, enabling modern Python clients such as pip and uv to access richer package metadata. With this additional metadata, clients can make more informed dependency resolution decisions, reducing the number of requests and improving overall performance when installing packages.
This enhancement maintains full backward compatibility by preserving existing PEP 503 HTML and Simple API v1.0 behavior. Existing clients continue to function without change, while newer tools benefit from improved efficiency and faster dependency resolution workflows.
Java EE 10 Upgrade for Modernized Platform Infrastructure
Sonatype Nexus Repository now uses Java EE 10, modernizing the underlying servlet infrastructure and aligning core components with current standards. This update includes upgrades to key dependencies such as Jetty, RESTEasy, and OpenAPI 3, improving platform consistency, maintainability, and long-term compatibility with modern Java ecosystems.
Note
As part of this change, custom plugins, integrations, and tooling that rely on javax.servlet APIs must migrate to the corresponding jakarta.servlet APIs before upgrading. This ensures continued compatibility and allows extensions to take full advantage of the updated platform.
Improved Docker Repository Management Experience
Sonatype Nexus Repository now streamlines Docker repository management with guided connector configuration and enhanced usability. The system suggests appropriate ports during setup, reducing configuration errors and helping you get repositories up and running more quickly.
Search results now display richer image metadata, giving you better visibility into available artifacts. Additionally, generated docker pull commands automatically reference your Nexus Repository registry, ensuring accuracy and simplifying the process of retrieving images.
Improved Docker Proxy Repository Performance for Large Image Catalogs
Sonatype Nexus Repository now provides faster, more consistent Docker image pulls through proxy repositories, including repositories that proxy popular public images with large manifest histories. Manifest lookups during image metadata processing are now bounded, which keeps repository database activity efficient as the number of cached manifests grows.
This enhancement helps Docker images download quickly and predictably at scale, supporting more reliable CI/CD pipelines and reducing the risk of delays during image retrieval. The improvement applies automatically and requires no changes to existing repository configuration.
Simplified URL Encoding Configuration for Proxy Repositories
Sonatype Nexus Repository now centralizes URL encoding behavior for proxy repositories through the Preserve Encoded Characters setting. This update removes ambiguity by making the repository-level configuration the single control point, allowing you to manage how encoded characters are handled without relying on additional global properties.
Updated Defaults for Conan Proxy Repositories
Sonatype Nexus Repository now defaults new Conan proxy repositories to Protocol Version V2, aligning with the latest Conan ecosystem standards. This update helps ensure compatibility with modern Conan clients and reduces the need for manual configuration during repository setup.
Enhanced Compatibility for Terraform Proxy Repositories
Terraform proxy repositories now seamlessly proxy content from a wider range of compliant registries, including OpenTofu registries and registry.coder.com. By aligning with each registry’s discovery protocol, Nexus Repository reduces errors and improves reliability when retrieving modules and providers across diverse Terraform ecosystems.
Enhanced Docker Registry Experience
Sonatype Nexus Repository improves the experience of configuring, evaluating, and managing Docker repositories. When you configure a Docker repository, Nexus Repository can suggest an available connector port, reducing trial and error caused by port conflicts. Docker pull commands displayed in the user interface now include the registry hostname and port, helping developers pull images from the intended private registry instead of inadvertently pulling an image with the same name from Docker Hub.
Nexus Repository also provides more Docker image information directly in the user interface, including operating system, architecture, image and layer sizes, environment variables, labels, entrypoint and command information, working directory, exposed ports, creation details, and layer history. This additional context helps you evaluate images without first pulling them.
Immediate Session Invalidation on Password Change
Sonatype Nexus Repository now strengthens account security by immediately invalidating all active sessions when a user’s password is changed. This ensures that any existing sessions across devices or browsers are terminated as soon as new credentials are set.
Stronger API Key Generation with UUID v4
Sonatype Nexus Repository now generates API keys for NuGet, npm, Docker, and Conan formats using UUID v4. This update improves the randomness and uniqueness of generated keys, strengthening the overall security of authentication workflows across supported formats.
Existing API keys remain valid and continue to function without change. However, Sonatype recommends regenerating keys to take advantage of the enhanced security model and ensure alignment with current best practices.
Repository Firewall: New Malware Threat Landscape Dashboard
Sonatype Repository Firewall now includes the Malware Threat Landscape dashboard in Enterprise Reporting, providing organizations with a broader view of malware activity across the open source ecosystem. By surfacing ecosystem-wide malware trends alongside Firewall blocking activity, the dashboard helps security, platform, and engineering teams better understand the evolving threat landscape, assess potential exposure, and demonstrate the value of proactively blocking malicious components before they reach developers.
![]() |
The dashboard combines high-level metrics with interactive reporting to help teams monitor trends such as newly discovered malware, attack frequency, malware exposure, and Firewall prevention activity. With filtering by ecosystem, threat type, attack vector, and time period, organizations can investigate emerging threats, identify the ecosystems most affected by malware, and use this insight to strengthen software supply chain security strategies and communicate risk more effectively to stakeholders.
For full details, see the Malware Threat Landscape help documentation.
Repository Firewall: Centralized Waiver Request and Management
Sonatype Repository Firewall now includes a complete in-product waiver management workflow that streamlines how policy exceptions are requested, reviewed, approved, and maintained. Developers can submit waiver requests directly from policy violations, while administrators can review, approve, reject, and renew waivers through a centralized Waivers dashboard. This creates a more structured and transparent approval process, reducing manual coordination and helping ensure policy exceptions receive the appropriate level of oversight.
Repository Firewall: Waiver Expiration Email Notifications
Sonatype Repository Firewall can now send configurable email notifications before component waivers expire, helping organizations stay ahead of expiring policy exceptions. Administrators can define multiple reminder thresholds and notify individual recipients or role-based groups, giving teams ample time to review, renew, or remove waivers before they expire.
By proactively alerting the right stakeholders, this enhancement helps reduce the risk of unexpected component quarantines or workflow disruptions caused by expired waivers. It also improves governance by making waiver lifecycles more visible, encouraging regular review of policy exceptions, and helping ensure temporary waivers do not remain in place longer than intended.
For full details, see the Waiver Expiration Notifications help documentation.
Repository Firewall: Expanded Firewall Webhook Events
Sonatype Repository Firewall webhooks now support Violation Alert and Waiver Request events, enabling real-time notifications for repository proxy policies. This enhancement allows organizations to integrate Firewall activity more easily with ticketing systems, messaging platforms, and automated workflows, helping teams respond more quickly to new policy violations and waiver requests while reducing manual monitoring and accelerating security operations.
For full details, see the Firewall Webhooks help documentation.
Repository Firewall: Repository-Scoped Access to the Firewall Dashboard
The Sonatype Repository Firewall dashboard now supports repository-scoped access, allowing users with read permission on individual proxy repositories to view dashboard data automatically limited to only the repositories they are authorized to access. This enhancement extends Firewall reporting to a broader set of users while preserving access controls, enabling development and operations teams to monitor Firewall activity relevant to their own repositories without exposing data from other parts of the organization.
Repository Firewall: Improved Quarantine Timeline Visibility
Repository Results tables in Firewall now separate Evaluation Time and Quarantine Time into dedicated columns, providing clearer insight into the lifecycle of evaluated components. This enhancement makes it easier to interpret repository activity at a glance and reduces ambiguity when reviewing Firewall results.
Bug Fixes
The tables below detail notable bug fixes in each release within this release line.
3.94.2 Bug Fixes
Issue ID | Description |
|---|---|
NEXUS-54717 | Sonatype Nexus Repository now updates the lastDownloaded timestamp for Docker manifest HEAD requests, preventing actively used images from being incorrectly targeted by cleanup policies. |
3.94.1 Bug Fixes
Issue ID | Description |
|---|---|
NEXUS-53975 | Terraform proxy repositories now support a Preemptive Authentication option that sends Basic credentials on the first outbound request, enabling chained Nexus-to-Nexus Terraform proxy topologies to authenticate successfully without requiring a WWW-Authenticate challenge from the upstream. |
NEXUS-53833 | Browsing a PyPI hosted repository's simple index no longer writes new blobs to the blob store on each request. |
NEXUS-53719 | Permission checks for users authenticated through external realms (SAML, LDAP, Crowd, OAuth2) now resolve role-to-permission mappings once per request rather than once per permission. |
NEXUS-53486 | The Default Role Realm is now preserved across node shutdowns. |
FIRE-601 | Sonatype Nexus Repository High Availability deployments using Zero Downtime Upgrade now maintain Sonatype Repository Firewall enforcement on the node that runs the deferred database migration by refreshing stale in-memory repository configuration after the upgrade completes. |
3.94.0 Bug Fixes
Issue ID | Description |
|---|---|
NEXUS-53700 | Nexus Repository startup completes successfully with analytics disabled, allowing all internal tasks to initialize without errors or repeated retry failures. |
NEXUS-53682 | Source RPMs in hosted Yum repositories now carry Upgrade Impact: Yum repository metadata regeneration is required after upgrading. Source RPMs uploaded to hosted Yum repositories before this fix will need their repodata regenerated to reflect the corrected architecture value. |
NEXUS-53492 | PyPI group repositories now return the correct package and metadata hashes for locally hosted packages that shadow proxy packages with the same filename, allowing PEP 658/691-aware clients such as pip 26 to install patched packages without hash mismatch errors. |
NEXUS-53454 | Duplicate |
NEXUS-53449 | PyPI group repositories now reflect updated package versions from proxy members automatically once the proxy's metadata cache expires, without requiring manual cache invalidation. |
NEXUS-53396 | Conda proxy repositories configured with channel-specific upstream URLs now send the correct package path to Sonatype IQ Server, allowing malicious packages to be identified and quarantined as expected. |
NEXUS-53395 | Docker image layer extraction on Windows now handles paths containing illegal characters (such as |
NEXUS-53310 | Ansible Galaxy proxy repository metadata now rewrites download URLs dynamically based on the scheme, hostname, and port of each inbound request, ensuring components download successfully regardless of which network address is used to access the instance. |
NEXUS-53297 | Package index updates in nested PyPI group repositories now propagate automatically through all group levels when new versions are uploaded or cached, without requiring manual cache invalidation. |
NEXUS-53266 | Sensitive HTTP authentication headers—including |
NEXUS-53242 | Downloading models through a HuggingFace proxy repository now produces complete, non-zero-byte blob files for non-LFS content such as |
NEXUS-53199 | After login, the UI is immediately interactive while permissions load asynchronously in the background, eliminating the blocking "Loading Permissions" screen experienced by users with large role sets. |
NEXUS-53184 | NuGet V2 |
NEXUS-53173 | PyPI proxy, hosted, and group repositories now return Simple API v1.1 responses (PEP 700) with |
NEXUS-53059 | Frontend dependencies axios (1.16.0 → 1.17.0) and tar (7.5.13 → 7.5.16) are updated to versions that resolve high and medium severity security vulnerabilities. |
NEXUS-53007 | Rate-limit buckets for NuGet API key authentication are now isolated per token, so an invalid token from one user cannot trigger HTTP 429 errors for other users sharing the same repository. |
NEXUS-52998 | Nexus Repository now starts cleanly when a Default Role capability references a role that no longer exists, while still returning HTTP 400 for API requests that attempt to create or update the capability with a nonexistent role. |
NEXUS-52973 | NuGet v2 proxy repositories now serve cached package results immediately, reducing |
NEXUS-52961 | Support zip exports now include an |
NEXUS-52912 | Mandatory Telemetry components load conditionally based on configuration, with threshold comparisons, retry task initialization, and deprecation warnings for |
NEXUS-52859 | PyPI proxy, hosted, and group repositories now serve PEP 691/700-compliant JSON responses—including file size, upload timestamps, and complete version lists—to tools that request the modern Simple API format, while continuing to return HTML to legacy clients. Upgrade Impact: Modern Python tools (pip 23+, uv, Poetry 2.x) will automatically begin receiving JSON responses instead of HTML from PyPI proxy, hosted, and group repositories. Verify that any custom PyPI tooling or scripts in your environment support the PEP 691/700 JSON Simple API format before upgrading. |
NEXUS-52856 | Keyword-only searches now display the group repository name for users whose access is granted through a group, while administrators continue to see the actual member repository where the component is stored. |
NEXUS-52855 | The Repair - Rebuild Maven repository metadata task gracefully skips repositories that don't contain the specified groupId/artifactId, completing without errors or spurious log warnings. |
NEXUS-52846 | Logging out of Nexus instances configured with Okta OIDC now completes successfully, as the required |
NEXUS-52831 | Authentication rate limiting now blocks requests before credentials are evaluated, ensuring that users who have exceeded the failed-login threshold receive HTTP 429 regardless of whether the submitted password is correct. |
NEXUS-52827 | Clicking the Repository column header in Search results now sorts correctly across all repository formats instead of returning an error. Upgrade Impact: The |
NEXUS-52813 | PyPI hosted repositories now correctly reflect newly uploaded packages in the per-package simple index for names containing uppercase letters, underscores, dots, or other characters requiring PEP 503 normalization, without requiring a manual metadata rebuild task. |
NEXUS-52799 | Downloading macOS universal (fat) binary |
NEXUS-52769 | Raw proxy repositories with Upgrade Impact: The |
NEXUS-52759 | Upgrade Impact: Groovy scripts now execute under Groovy 5.0.6, which enforces stricter sandbox security semantics. Existing scripts using indirect imports (for example, |
NEXUS-52625 | YUM/RPM repository components with thousands of assets are now partially indexed rather than silently excluded from search when their accumulated file paths approach PostgreSQL's internal |
NEXUS-52620 | Blob store creation and modification through the UI complete successfully when Nexus is accessed via HTTPS. |
NEXUS-52580 | Data Repair Plan recovery correctly preserves the |
NEXUS-52571 | Removing all nexus-managed roles from an LDAP or SAML user now saves cleanly, with the Users list remaining fully functional without requiring a page reload. |
NEXUS-52320 | Terraform authentication through a context path now correctly extracts user tokens from the request URI, allowing |
NEXUS-52117 | Uploading components and artifacts to hosted repositories via the Upload sidebar tab now completes successfully without errors. |
NEXUS-52107 | When startup fails to initialize an HTTP client facet due to a missing or stale secret, log output now includes the affected repository name and configuration area ( |
NEXUS-52050 | Clicking the Sonatype logo now navigates correctly to the appropriate landing page in both Cloud and Preview UI environments, replacing the previous blank page behavior. |
NEXUS-52006 | The |
NEXUS-51920 | Terraform hosted repositories now correctly upload and download modules with SemVer pre-release versions containing hyphens, such as |
NEXUS-51877 | Search index rebuild tasks skip empty component batches gracefully, preventing PostgreSQL syntax errors in task and database logs. |
NEXUS-51835 | Azure blob store initialization failures now log the root cause exception and full stack trace at the default ERROR log level, eliminating the need to enable DEBUG logging before restarting to diagnose the problem. |
NEXUS-51662 | Multi-term search queries on SQL/PostgreSQL backends now respect term order and position when |
NEXUS-51660 | Embedded wildcard patterns such as |
NEXUS-51643 | Helm hosted repositories now return a JSON 409 Conflict response when a chart push is rejected, allowing |
NEXUS-51593 | Content selector privileges created or updated via the REST API now display their correct repository and format values in the UI, and editing a privilege through the UI no longer silently overwrites the configured repository scope. |
NEXUS-51522 | Mixed-case Docker repository names created before 3.90 are now fully editable via the REST API, with the only restriction being that path-based routing cannot be newly enabled on repositories with non-lowercase names. |
NEXUS-51449 | The Repository Health Check column is no longer displayed in the Browse view for customers who have Firewall enabled. |
NEXUS-50725 | Startup log messages for the Job Key Unification task now accurately reflect cluster conditions, omitting misleading "old nodes still running" warnings when all nodes are running the same version. |
NEXUS-50701 | SSRF validation now defers to the configured global HTTP/HTTPS proxy when direct DNS resolution fails, allowing proxy repository creation and artifact retrieval in locked-down or air-gapped environments where Nexus cannot perform local DNS lookups. |
NEXUS-41851 | Logger override configurations are now exported to the support zip in High Availability deployments, where this data is stored in the |
NEXUS-27554 | The NuGet API Token section in user profiles is now hidden when the NuGet API-Key realm is disabled, matching the behavior of other realm-dependent features. |
Coming Soon
Groovy Scripting Support Reaches End of Life in December 2026
Groovy scripting support in Sonatype Nexus Repository will reach end of life in December 2026. All capabilities that previously required Groovy scripts are now available through the Nexus Repository UI and REST APIs, providing supported options for configuration and automation. If you still use Groovy scripts, begin planning your migration to the UI or REST APIs before the end-of-life date to ensure a smooth transition.
Blob Store Names Cannot Contain HTML Special Characters
Beginning with self-hosted release 3.95.0 (expected August 2026), blob store names cannot contain HTML special characters. This is to enhance protection against stored XSS vulnerabilities. Existing blob stores with non-conforming names must be renamed before upgrading to 3.95.0.
Nexus One UI as Default
The Nexus One UI will soon become the default interface in Sonatype Nexus Repository, providing a faster, more intuitive experience with streamlined navigation and improved repository search and browsing. Users will still be able to switch back to the Classic UI, making it easy to adopt the new experience at your own pace.
Known Issues & Upgrade Guidance
This section captures known issues in the 3.94.x line as well as upgrade guidance.
Open Known Issues
Impacted Version(s) | Description | Workaround |
|---|---|---|
3.94.0 – 3.96.3 | When authentication attempts exceed the configured rate limit in an environment where rate limiting is enabled, Nexus Repository returns an HTTP 429 response with a Further attempts, even with valid credentials, can restart the timeout and extend the lockout, preventing users and automated clients from recovering after a temporary credential failure. | Disable authentication rate limiting by configuring the following property in your
If you cannot disable rate limiting, wait 15 uninterrupted minutes after the last authentication attempt before trying again. |
Resolved Known Issues
Impacted Version(s) | Version in which Issue is Resolved | Description |
|---|---|---|
3.94.0 – 3.94.1 & 3.95.0 – 3.95.2 | 3.94.2 & 3.95.3 |
Because container runtimes may use |
3.94.0 – 3.95.0 | 3.95.1 | NuGet V2 proxy repositories return locally cached results for As a workaround, delete all locally cached versions of the affected package to force the next You can also migrate the affected repository and clients to NuGet V3. |
3.94.0 – 3.94.1 | 3.95.0 | In Sonatype Nexus Repository 3.94.0, an optional Symbol Server URL field is visible when creating a NuGet proxy repository. However, this functionality is not currently available. While Nexus Repository may appear to accept and save a value entered into this field, it will not proxy symbol packages or use the configured value. This is a UI bug only; no workaround is required. |
3.94.0 | 3.94.1 | This issue impacts Sonatype Nexus Repository High Availability deployments using Zero Downtime Upgrade (ZDU) with Firewall enabled. After the database schema upgrade completes, the Nexus Repository node that executes the deferred migration may continue using stale in-memory repository configuration. As a result, Firewall enforcement can be disabled on that node until it is restarted, allowing previously quarantined components to be served. Any components downloaded during this period remain available in the repository cache after Firewall enforcement is restored. Additionally, pre-upgrade quarantine history is no longer available in the Sonatype IQ Server Firewall UI or repository reports after the upgrade. This issue affects request-time Firewall enforcement only on the migration-executing node. Other nodes that load the updated repository configuration continue to enforce quarantine as expected. Partial workaround: Perform a rolling restart of all Nexus Repository HA nodes after completing the ZDU database schema upgrade. Restarting each node reloads the updated repository configuration and restores Firewall enforcement. Note that restarting Nexus Repository does not retroactively quarantine or remove components that were downloaded while Firewall enforcement was unavailable. It also does not restore pre-upgrade quarantine history in Sonatype IQ Server or previously deleted repository report data. |
