Skip to main content

Sonatype Nexus Repository 3.94.0 – 3.94.2 Release Notes

The Sonatype Nexus Repository 3.94.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!

Release Timeline

  • 3.94.0 – July 9, 2026

  • 3.94.1 – July 24, 2026

  • 3.94.2 – August 27, 2026

Check Known Issues Before Upgrading

This version line contains known issues.

Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.

 

What’s New and Noteworthy in This Release?

The Sonatype Nexus Repository 3.94.x release line includes the following new features and enhancements:

Repository Firewall: Support for conda-forge Upstreams

Sonatype Repository Firewall now supports conda-forge as an upstream for conda proxy repositories. You can configure a conda proxy repository to use the conda-forge upstream and apply Repository Firewall policies to packages retrieved from that source, expanding protection to one of the most widely used community-managed conda repositories.

This enhancement gives organizations greater flexibility when adopting conda while maintaining the same security and governance workflows they rely on for other supported package ecosystems. Customers who depend on packages from conda-forge can now confidently proxy that upstream through Repository Firewall and enforce quarantine and policy evaluation before components reach development environments.

Support for Open Container Initiative (OCI) Repositories

Sonatype Nexus Repository now supports native Open Container Initiative (OCI) hosted, proxy, and group repositories, giving you a single solution for managing container images and other OCI artifacts throughout your software supply chain. You can proxy content from external OCI registries, publish and protect internally developed artifacts, and expose multiple repositories through a single endpoint to simplify client configuration and artifact management.

This new repository format supports standard OCI-compatible tools, including Docker, Podman, Helm, ORAS, Cosign, Syft, Crane, and Skopeo, making it easier to adopt OCI workflows without changing existing tooling. In addition to container images, Nexus Repository can store and distribute Helm charts, Software Bills of Materials (SBOMs), signatures, attestations, and other OCI artifacts, helping organizations centralize artifact management while supporting modern software supply chain and container security practices.

For full details, see the OCI Repositories help documentation.

Proxy Private Amazon Elastic Container Registry (ECR) Registries with Docker Repositories

Sonatype Nexus Repository now supports proxying private Amazon ECR registries through Docker proxy repositories. You can configure a Docker proxy repository by providing your AWS account's ECR registry URL along with AWS IAM credentials, allowing Nexus Repository to centrally cache and serve container images stored in private ECR registries.

To simplify authentication, Nexus Repository automatically retrieves and caches the ECR authorization token on the first image pull using your configured AWS credentials. This capability reduces repeated authorization calls to Amazon ECR, lowers data transfer costs, and provides a consistent image source for development and CI/CD environments.

For full details, see the Proxy Repository for Docker help documentation.

PyPI Simple API v1.1 Support for Faster Dependency Resolution

Sonatype Nexus Repository now supports Simple API v1.1 (PEP 700) for PyPI repositories, enabling modern Python clients such as pip and uv to access richer package metadata. With this additional metadata, clients can make more informed dependency resolution decisions, reducing the number of requests and improving overall performance when installing packages.

This enhancement maintains full backward compatibility by preserving existing PEP 503 HTML and Simple API v1.0 behavior. Existing clients continue to function without change, while newer tools benefit from improved efficiency and faster dependency resolution workflows.

Java EE 10 Upgrade for Modernized Platform Infrastructure

Sonatype Nexus Repository now uses Java EE 10, modernizing the underlying servlet infrastructure and aligning core components with current standards. This update includes upgrades to key dependencies such as Jetty, RESTEasy, and OpenAPI 3, improving platform consistency, maintainability, and long-term compatibility with modern Java ecosystems.

Note

As part of this change, custom plugins, integrations, and tooling that rely on javax.servlet APIs must migrate to the corresponding jakarta.servlet APIs before upgrading. This ensures continued compatibility and allows extensions to take full advantage of the updated platform.

Improved Docker Repository Management Experience

Sonatype Nexus Repository now streamlines Docker repository management with guided connector configuration and enhanced usability. The system suggests appropriate ports during setup, reducing configuration errors and helping you get repositories up and running more quickly.

Search results now display richer image metadata, giving you better visibility into available artifacts. Additionally, generated docker pull commands automatically reference your Nexus Repository registry, ensuring accuracy and simplifying the process of retrieving images.

Improved Docker Proxy Repository Performance for Large Image Catalogs

Sonatype Nexus Repository now provides faster, more consistent Docker image pulls through proxy repositories, including repositories that proxy popular public images with large manifest histories. Manifest lookups during image metadata processing are now bounded, which keeps repository database activity efficient as the number of cached manifests grows.

This enhancement helps Docker images download quickly and predictably at scale, supporting more reliable CI/CD pipelines and reducing the risk of delays during image retrieval. The improvement applies automatically and requires no changes to existing repository configuration.

Simplified URL Encoding Configuration for Proxy Repositories

Sonatype Nexus Repository now centralizes URL encoding behavior for proxy repositories through the Preserve Encoded Characters setting. This update removes ambiguity by making the repository-level configuration the single control point, allowing you to manage how encoded characters are handled without relying on additional global properties.

Updated Defaults for Conan Proxy Repositories

Sonatype Nexus Repository now defaults new Conan proxy repositories to Protocol Version V2, aligning with the latest Conan ecosystem standards. This update helps ensure compatibility with modern Conan clients and reduces the need for manual configuration during repository setup.

Enhanced Compatibility for Terraform Proxy Repositories

Terraform proxy repositories now seamlessly proxy content from a wider range of compliant registries, including OpenTofu registries and registry.coder.com. By aligning with each registry’s discovery protocol, Nexus Repository reduces errors and improves reliability when retrieving modules and providers across diverse Terraform ecosystems.

Enhanced Docker Registry Experience

Sonatype Nexus Repository improves the experience of configuring, evaluating, and managing Docker repositories. When you configure a Docker repository, Nexus Repository can suggest an available connector port, reducing trial and error caused by port conflicts. Docker pull commands displayed in the user interface now include the registry hostname and port, helping developers pull images from the intended private registry instead of inadvertently pulling an image with the same name from Docker Hub.

Nexus Repository also provides more Docker image information directly in the user interface, including operating system, architecture, image and layer sizes, environment variables, labels, entrypoint and command information, working directory, exposed ports, creation details, and layer history. This additional context helps you evaluate images without first pulling them.

Immediate Session Invalidation on Password Change

Sonatype Nexus Repository now strengthens account security by immediately invalidating all active sessions when a user’s password is changed. This ensures that any existing sessions across devices or browsers are terminated as soon as new credentials are set.

Stronger API Key Generation with UUID v4

Sonatype Nexus Repository now generates API keys for NuGet, npm, Docker, and Conan formats using UUID v4. This update improves the randomness and uniqueness of generated keys, strengthening the overall security of authentication workflows across supported formats.

Existing API keys remain valid and continue to function without change. However, Sonatype recommends regenerating keys to take advantage of the enhanced security model and ensure alignment with current best practices.

Repository Firewall: New Malware Threat Landscape Dashboard

Sonatype Repository Firewall now includes the Malware Threat Landscape dashboard in Enterprise Reporting, providing organizations with a broader view of malware activity across the open source ecosystem. By surfacing ecosystem-wide malware trends alongside Firewall blocking activity, the dashboard helps security, platform, and engineering teams better understand the evolving threat landscape, assess potential exposure, and demonstrate the value of proactively blocking malicious components before they reach developers.

Untitled - Frame 3 (1).jpg

The dashboard combines high-level metrics with interactive reporting to help teams monitor trends such as newly discovered malware, attack frequency, malware exposure, and Firewall prevention activity. With filtering by ecosystem, threat type, attack vector, and time period, organizations can investigate emerging threats, identify the ecosystems most affected by malware, and use this insight to strengthen software supply chain security strategies and communicate risk more effectively to stakeholders.

For full details, see the Malware Threat Landscape help documentation.

Repository Firewall: Centralized Waiver Request and Management

Sonatype Repository Firewall now includes a complete in-product waiver management workflow that streamlines how policy exceptions are requested, reviewed, approved, and maintained. Developers can submit waiver requests directly from policy violations, while administrators can review, approve, reject, and renew waivers through a centralized Waivers dashboard. This creates a more structured and transparent approval process, reducing manual coordination and helping ensure policy exceptions receive the appropriate level of oversight.

Repository Firewall: Waiver Expiration Email Notifications

Sonatype Repository Firewall can now send configurable email notifications before component waivers expire, helping organizations stay ahead of expiring policy exceptions. Administrators can define multiple reminder thresholds and notify individual recipients or role-based groups, giving teams ample time to review, renew, or remove waivers before they expire.

By proactively alerting the right stakeholders, this enhancement helps reduce the risk of unexpected component quarantines or workflow disruptions caused by expired waivers. It also improves governance by making waiver lifecycles more visible, encouraging regular review of policy exceptions, and helping ensure temporary waivers do not remain in place longer than intended.

For full details, see the Waiver Expiration Notifications help documentation.

Repository Firewall: Expanded Firewall Webhook Events

Sonatype Repository Firewall webhooks now support Violation Alert and Waiver Request events, enabling real-time notifications for repository proxy policies. This enhancement allows organizations to integrate Firewall activity more easily with ticketing systems, messaging platforms, and automated workflows, helping teams respond more quickly to new policy violations and waiver requests while reducing manual monitoring and accelerating security operations.

For full details, see the Firewall Webhooks help documentation.

Repository Firewall: Repository-Scoped Access to the Firewall Dashboard

The Sonatype Repository Firewall dashboard now supports repository-scoped access, allowing users with read permission on individual proxy repositories to view dashboard data automatically limited to only the repositories they are authorized to access. This enhancement extends Firewall reporting to a broader set of users while preserving access controls, enabling development and operations teams to monitor Firewall activity relevant to their own repositories without exposing data from other parts of the organization.

Repository Firewall: Improved Quarantine Timeline Visibility

Repository Results tables in Firewall now separate Evaluation Time and Quarantine Time into dedicated columns, providing clearer insight into the lifecycle of evaluated components. This enhancement makes it easier to interpret repository activity at a glance and reduces ambiguity when reviewing Firewall results.

Bug Fixes

The tables below detail notable bug fixes in each release within this release line.

3.94.2 Bug Fixes

Issue ID

Description

NEXUS-54717

Sonatype Nexus Repository now updates the lastDownloaded timestamp for Docker manifest HEAD requests, preventing actively used images from being incorrectly targeted by cleanup policies.

3.94.1 Bug Fixes

Issue ID

Description

NEXUS-53975

Terraform proxy repositories now support a Preemptive Authentication option that sends Basic credentials on the first outbound request, enabling chained Nexus-to-Nexus Terraform proxy topologies to authenticate successfully without requiring a WWW-Authenticate challenge from the upstream.

NEXUS-53833

Browsing a PyPI hosted repository's simple index no longer writes new blobs to the blob store on each request.

NEXUS-53719

Permission checks for users authenticated through external realms (SAML, LDAP, Crowd, OAuth2) now resolve role-to-permission mappings once per request rather than once per permission.

NEXUS-53486

The Default Role Realm is now preserved across node shutdowns.

FIRE-601

Sonatype Nexus Repository High Availability deployments using Zero Downtime Upgrade now maintain Sonatype Repository Firewall enforcement on the node that runs the deferred database migration by refreshing stale in-memory repository configuration after the upgrade completes.

3.94.0 Bug Fixes

Issue ID

Description

NEXUS-53700

Nexus Repository startup completes successfully with analytics disabled, allowing all internal tasks to initialize without errors or repeated retry failures.

NEXUS-53682

Source RPMs in hosted Yum repositories now carry arch="src" in generated primary.xml metadata, ensuring yum/dnf clients correctly distinguish source packages from binary packages during installation.

Upgrade Impact: Yum repository metadata regeneration is required after upgrading. Source RPMs uploaded to hosted Yum repositories before this fix will need their repodata regenerated to reflect the corrected architecture value.

NEXUS-53492

PyPI group repositories now return the correct package and metadata hashes for locally hosted packages that shadow proxy packages with the same filename, allowing PEP 658/691-aware clients such as pip 26 to install patched packages without hash mismatch errors.

NEXUS-53454

Duplicate repository.search.update tasks are now prevented in High Availability deployments by a singleton guard that blocks a second node from scheduling the task when one already exists in the scheduler.

NEXUS-53449

PyPI group repositories now reflect updated package versions from proxy members automatically once the proxy's metadata cache expires, without requiring manual cache invalidation.

NEXUS-53396

Conda proxy repositories configured with channel-specific upstream URLs now send the correct package path to Sonatype IQ Server, allowing malicious packages to be identified and quarantined as expected.

NEXUS-53395

Docker image layer extraction on Windows now handles paths containing illegal characters (such as *, ?, or :) and paths exceeding 260 characters, allowing Firewall for Docker scans to complete successfully on Windows with the same evaluation results as Linux.

NEXUS-53310

Ansible Galaxy proxy repository metadata now rewrites download URLs dynamically based on the scheme, hostname, and port of each inbound request, ensuring components download successfully regardless of which network address is used to access the instance.

NEXUS-53297

Package index updates in nested PyPI group repositories now propagate automatically through all group levels when new versions are uploaded or cached, without requiring manual cache invalidation.

NEXUS-53266

Sensitive HTTP authentication headers—including Authorization: Bearer, Authorization: Basic, X-Auth-Token, and X-API-Key—are now automatically redacted from log files at write time, ensuring support ZIP bundles never contain plaintext credentials.

NEXUS-53242

Downloading models through a HuggingFace proxy repository now produces complete, non-zero-byte blob files for non-LFS content such as config.json and tokenizer files.

NEXUS-53199

After login, the UI is immediately interactive while permissions load asynchronously in the background, eliminating the blocking "Loading Permissions" screen experienced by users with large role sets.

NEXUS-53184

NuGet V2 FindPackagesById() returns only exact package ID matches, preventing packages like Project-main from appearing in results when querying for Project.

NEXUS-53173

PyPI proxy, hosted, and group repositories now return Simple API v1.1 responses (PEP 700) with size, upload-time, and versions fields when upstream data supports it, while automatically falling back to v1.0 for older clients and mixed-version group members.

NEXUS-53059

Frontend dependencies axios (1.16.0 → 1.17.0) and tar (7.5.13 → 7.5.16) are updated to versions that resolve high and medium severity security vulnerabilities.

NEXUS-53007

Rate-limit buckets for NuGet API key authentication are now isolated per token, so an invalid token from one user cannot trigger HTTP 429 errors for other users sharing the same repository.

NEXUS-52998

Nexus Repository now starts cleanly when a Default Role capability references a role that no longer exists, while still returning HTTP 400 for API requests that attempt to create or update the capability with a nonexistent role.

NEXUS-52973

NuGet v2 proxy repositories now serve cached package results immediately, reducing FindPackagesById response times from ~18 seconds to under one second for warm-cache requests.

NEXUS-52961

Support zip exports now include an oauth2UserExport.json file containing OAuth2 user table data, giving support teams visibility into OAuth user records when troubleshooting authorization issues.

NEXUS-52912

Mandatory Telemetry components load conditionally based on configuration, with threshold comparisons, retry task initialization, and deprecation warnings for nexus.analytics.enabled all behaving correctly across enabled and disabled states.

NEXUS-52859

PyPI proxy, hosted, and group repositories now serve PEP 691/700-compliant JSON responses—including file size, upload timestamps, and complete version lists—to tools that request the modern Simple API format, while continuing to return HTML to legacy clients.

Upgrade Impact: Modern Python tools (pip 23+, uv, Poetry 2.x) will automatically begin receiving JSON responses instead of HTML from PyPI proxy, hosted, and group repositories. Verify that any custom PyPI tooling or scripts in your environment support the PEP 691/700 JSON Simple API format before upgrading.

NEXUS-52856

Keyword-only searches now display the group repository name for users whose access is granted through a group, while administrators continue to see the actual member repository where the component is stored.

NEXUS-52855

The Repair - Rebuild Maven repository metadata task gracefully skips repositories that don't contain the specified groupId/artifactId, completing without errors or spurious log warnings.

NEXUS-52846

Logging out of Nexus instances configured with Okta OIDC now completes successfully, as the required id_token_hint parameter is included in the logout request sent to the identity provider.

NEXUS-52831

Authentication rate limiting now blocks requests before credentials are evaluated, ensuring that users who have exceeded the failed-login threshold receive HTTP 429 regardless of whether the submitted password is correct.

NEXUS-52827

Clicking the Repository column header in Search results now sorts correctly across all repository formats instead of returning an error.

Upgrade Impact: The repositoryName sort alias is now recognized by the search backend, which means any integrations or scripts that previously relied on the error response from repositoryName sort requests will receive successful sorted results instead.

NEXUS-52813

PyPI hosted repositories now correctly reflect newly uploaded packages in the per-package simple index for names containing uppercase letters, underscores, dots, or other characters requiring PEP 503 normalization, without requiring a manual metadata rebuild task.

NEXUS-52799

Downloading macOS universal (fat) binary .exe artifacts through Maven proxy repositories succeeds with strict content type validation enabled, as application/x-mach-o-universal is now recognized as a valid MIME type for .exe files.

NEXUS-52769

Raw proxy repositories with preserveEncodedCharacters enabled now forward upstream redirect URLs byte-for-byte to storage backends, preserving consecutive slashes and encoded characters required by Cloudflare R2 and AWS S3 SigV4-signed URLs.

Upgrade Impact: The preserveEncodedCharacters setting on raw proxy repositories now controls URI normalization behavior. Repositories with this option set to false will continue to have redirect URLs normalized (collapsing // to /), which may affect upstream compatibility.

NEXUS-52759

Upgrade Impact: Groovy scripts now execute under Groovy 5.0.6, which enforces stricter sandbox security semantics. Existing scripts using indirect imports (for example, System.getProperty(...)) will return an error and must be updated to comply with the new SecureASTCustomizer rules.

NEXUS-52625

YUM/RPM repository components with thousands of assets are now partially indexed rather than silently excluded from search when their accumulated file paths approach PostgreSQL's internal tsvector size limit.

NEXUS-52620

Blob store creation and modification through the UI complete successfully when Nexus is accessed via HTTPS.

NEXUS-52580

Data Repair Plan recovery correctly preserves the MODULE_VERSIONS asset kind for Terraform versions.json files, allowing subsequent module uploads to hosted Terraform repositories to complete successfully.

NEXUS-52571

Removing all nexus-managed roles from an LDAP or SAML user now saves cleanly, with the Users list remaining fully functional without requiring a page reload.

NEXUS-52320

Terraform authentication through a context path now correctly extracts user tokens from the request URI, allowing terraform init to complete successfully when "Require User Tokens for Repository Authentication" is enabled.

NEXUS-52117

Uploading components and artifacts to hosted repositories via the Upload sidebar tab now completes successfully without errors.

NEXUS-52107

When startup fails to initialize an HTTP client facet due to a missing or stale secret, log output now includes the affected repository name and configuration area (httpclient.authentication.password) to enable faster diagnosis without requiring database-level investigation.

NEXUS-52050

Clicking the Sonatype logo now navigates correctly to the appropriate landing page in both Cloud and Preview UI environments, replacing the previous blank page behavior.

NEXUS-52006

The lastDownloaded timestamp update now uses a conditional database operation rather than per-node in-memory tracking, preventing orphaned .tmp and .bak blob attribute files from accumulating on NFS and CIFS blob stores.

NEXUS-51920

Terraform hosted repositories now correctly upload and download modules with SemVer pre-release versions containing hyphens, such as 0.0.5-main-20260323 or 1.2.3-feature-branch-42.

NEXUS-51877

Search index rebuild tasks skip empty component batches gracefully, preventing PostgreSQL syntax errors in task and database logs.

NEXUS-51835

Azure blob store initialization failures now log the root cause exception and full stack trace at the default ERROR log level, eliminating the need to enable DEBUG logging before restarting to diagnose the problem.

NEXUS-51662

Multi-term search queries on SQL/PostgreSQL backends now respect term order and position when nexus.search.multi.wildcard.regex.enabled=true is set, returning only components where search terms appear in the specified sequence rather than in any order.

NEXUS-51660

Embedded wildcard patterns such as ubi*-dev and psql*-jdk*-ubi* now return matching components across Name, Tag, Version, and Artifact search fields instead of empty results.

NEXUS-51643

Helm hosted repositories now return a JSON 409 Conflict response when a chart push is rejected, allowing helm cm-push and other ChartMuseum-compatible clients to parse and display the actual rejection reason instead of an unparseable HTML error page.

NEXUS-51593

Content selector privileges created or updated via the REST API now display their correct repository and format values in the UI, and editing a privilege through the UI no longer silently overwrites the configured repository scope.

NEXUS-51522

Mixed-case Docker repository names created before 3.90 are now fully editable via the REST API, with the only restriction being that path-based routing cannot be newly enabled on repositories with non-lowercase names.

NEXUS-51449

The Repository Health Check column is no longer displayed in the Browse view for customers who have Firewall enabled.

NEXUS-50725

Startup log messages for the Job Key Unification task now accurately reflect cluster conditions, omitting misleading "old nodes still running" warnings when all nodes are running the same version.

NEXUS-50701

SSRF validation now defers to the configured global HTTP/HTTPS proxy when direct DNS resolution fails, allowing proxy repository creation and artifact retrieval in locked-down or air-gapped environments where Nexus cannot perform local DNS lookups.

NEXUS-41851

Logger override configurations are now exported to the support zip in High Availability deployments, where this data is stored in the logging_overrides database table rather than logback-overrides.xml.

NEXUS-27554

The NuGet API Token section in user profiles is now hidden when the NuGet API-Key realm is disabled, matching the behavior of other realm-dependent features.

Coming Soon

Groovy Scripting Support Reaches End of Life in December 2026

Groovy scripting support in Sonatype Nexus Repository will reach end of life in December 2026. All capabilities that previously required Groovy scripts are now available through the Nexus Repository UI and REST APIs, providing supported options for configuration and automation. If you still use Groovy scripts, begin planning your migration to the UI or REST APIs before the end-of-life date to ensure a smooth transition.

Blob Store Names Cannot Contain HTML Special Characters

Beginning with self-hosted release 3.95.0 (expected August 2026), blob store names cannot contain HTML special characters. This is to enhance protection against stored XSS vulnerabilities. Existing blob stores with non-conforming names must be renamed before upgrading to 3.95.0.

Nexus One UI as Default

The Nexus One UI will soon become the default interface in Sonatype Nexus Repository, providing a faster, more intuitive experience with streamlined navigation and improved repository search and browsing. Users will still be able to switch back to the Classic UI, making it easy to adopt the new experience at your own pace.

Known Issues & Upgrade Guidance

This section captures known issues in the 3.94.x line as well as upgrade guidance.

Open Known Issues

Impacted Version(s)

Description

Workaround

3.94.0 – 3.96.3

When authentication attempts exceed the configured rate limit in an environment where rate limiting is enabled, Nexus Repository returns an HTTP 429 response with a Retry-After: 30 header. However, authentication may remain blocked for up to 900 seconds.

Further attempts, even with valid credentials, can restart the timeout and extend the lockout, preventing users and automated clients from recovering after a temporary credential failure.

Disable authentication rate limiting by configuring the following property in your $data-dir/etc/nexus.properties file:

nexus.auth.ratelimit.enabled=false

If you cannot disable rate limiting, wait 15 uninterrupted minutes after the last authentication attempt before trying again.

Resolved Known Issues

Impacted Version(s)

Version in which Issue is Resolved

Description

3.94.0 – 3.94.1 &

3.95.0 – 3.95.2

3.94.2 & 3.95.3

HEAD requests to Docker manifests no longer update an asset’s lastDownloaded timestamp.

Because container runtimes may use HEAD requests to check cached manifests, actively used images can appear inactive and become eligible for cleanup policies based on Last Downloaded.

3.94.0 – 3.95.0

3.95.1

NuGet V2 proxy repositories return locally cached results for FindPackagesById() without querying the remote repository. As a result, newly added or restored package versions might not appear, which can cause stale or incomplete dependency resolution.

As a workaround, delete all locally cached versions of the affected package to force the next FindPackagesById() request to query the remote repository.

You can also migrate the affected repository and clients to NuGet V3.

3.94.0 – 3.94.1

3.95.0

In Sonatype Nexus Repository 3.94.0, an optional Symbol Server URL field is visible when creating a NuGet proxy repository. However, this functionality is not currently available. While Nexus Repository may appear to accept and save a value entered into this field, it will not proxy symbol packages or use the configured value.

This is a UI bug only; no workaround is required.

3.94.0

3.94.1

This issue impacts Sonatype Nexus Repository High Availability deployments using Zero Downtime Upgrade (ZDU) with Firewall enabled.

After the database schema upgrade completes, the Nexus Repository node that executes the deferred migration may continue using stale in-memory repository configuration. As a result, Firewall enforcement can be disabled on that node until it is restarted, allowing previously quarantined components to be served. Any components downloaded during this period remain available in the repository cache after Firewall enforcement is restored.

Additionally, pre-upgrade quarantine history is no longer available in the Sonatype IQ Server Firewall UI or repository reports after the upgrade.

This issue affects request-time Firewall enforcement only on the migration-executing node. Other nodes that load the updated repository configuration continue to enforce quarantine as expected.

Partial workaround: Perform a rolling restart of all Nexus Repository HA nodes after completing the ZDU database schema upgrade.

Restarting each node reloads the updated repository configuration and restores Firewall enforcement.

Note that restarting Nexus Repository does not retroactively quarantine or remove components that were downloaded while Firewall enforcement was unavailable. It also does not restore pre-upgrade quarantine history in Sonatype IQ Server or previously deleted repository report data.