# 2021 Release Notes

## Summary of Major Changes in 2021

The following table lists major changes in 2021 that should be considered when upgrading to a new version. Select a release for more information.

| Release | Release Date | Major Changes |
| --- | --- | --- |
| [3.37.0 - 3.37.3](https://help.sonatype.com/en/nexus-repository-3-37-0---3-37-3-release-notes.html "Nexus Repository 3.37.0 - 3.37.3 Release Notes") | - November 24, 2021 (3.37.0)<br>  <br>- December 17, 2021 (3.37.1)<br>  <br>- December 28, 2021 (3.37.2)<br>  <br>- December 29, 2021 (3.37.3) | - Introduced Log4j Visualizer and a subsequent wording update; see the [Log4j Visualizer documentation](https://help.sonatype.com/document/preview/116909#UUID-745f561b-5753-eec3-83a4-fcfaa090cc7b). (3.37.2 & 3.37.3)Log4j Visualizer<br>  <br>- Update to logback library version. (3.37.1)<br>  <br>- Repository replication now supports the NuGet and PyPI formats. PRO<br>  <br>- Improved SQL INSERT performance into format specific browse_node tables to improve performance for those migrating to Nexus Repository 3 with an external PostgreSQL database. PRO<br>  <br>- Made the `node id` persistent in the event of a node failover PRO<br>  <br>- Modified the _Repair - Rebuild repository search_ task for rebuilding the Elastic Search (ES) index when a Kubernetes node starts up to only rebuild the ES index if it is not present on the node. PRO<br>  <br>- New _Repair - Rebuild npm metadata_ task.<br>  <br>- _Repair - rebuild Maven repository metadata_ task now recreates hosted metadata files when it encounters one that is an invalid blob reference.<br>  <br>- When migrating from Nexus Repository version 2 to version 3, Nexus Repository now retains information about when assets from that Nexus Repository 2 instance were created and who created them.<br>  <br>- We reworked our implementation to avoid copy operations while uploading components so as to improve S3 storage performance. |
| [3.36.0](https://help.sonatype.com/en/nexus-repository-3-36-0-release-notes.html "Nexus Repository 3.36.0 Release Notes") | October 27, 2021 | - **This release includes a security fix for an incorrect access control. See the [CVE-2021-42568](https://support.sonatype.com/hc/en-us/articles/4408801690515) for full details.**<br>  <br>- **This release includes a security fix for a server side request forgery vulnerability. See****[CVE-2021-43293](https://support.sonatype.com/hc/en-us/articles/4409326330003) for full details.**<br>  <br>- Replication Improvement: You can now use Truststore certificates for replication connections PRO<br>  <br>- Added OrientDB health check and repair to database migration PRO<br>  <br>- Added an automated Nexus Repository database version check for H2 and PostgreSQL databases to prevent using an H2 or PostgreSQL database version that is newer than your Nexus Repository version PRO<br>  <br>- Added a new [single-node cloud resilient deployment example using Azure](https://help.sonatype.com/en/single-node-cloud-resilient-deployment-example-using-azure.html "Single-Node Cloud Resilient Deployment Using Azure") to our help documentation. PRO<br>  <br>- Changed how Yum metadata is handled so that stale metadata is temporarily retained after rebuilding Yum metadata in order to support clients with an update metadata operation already in progress.<br>  <br>- In order to make migration from Nexus Repository 2 to 3 faster, we've removed building search indexes and browse nodes from the upgrade process. |
| [3.35.0](https://help.sonatype.com/en/nexus-repository-3-35-0-release-notes.html "Nexus Repository 3.35.0 Release Notes") | October 12, 2021 | - Replication support for Docker and npm formats PRO<br>  <br>- Replicator runs continuously by default PRO<br>  <br>- New Replicator Administrator role PRO<br>  <br>- Updated Database Migrator for easier migration between PostgreSQL and H2 Databases PRO<br>  <br>- Conan hosted support for PostgreSQL and H2 databases; not supported for OrientDB. PRO<br>  <br>- Firewall integration improvement: [policy-compliant component selection for npm](https://help.sonatype.com/en/policy-compliant-component-selection-for-npm.html "Policy-Compliant Component Selection for npm")<br>  <br>- Hardlink support for Docker, npm, NuGet, PyPI, RubyGems, and Yum |
| [3.34.0 - 3.34.1](https://help.sonatype.com/en/nexus-repository-3-34-0---3-34-1-release-notes.html "Nexus Repository 3.34.0 - 3.34.1 Release Notes") | - September 1, 2021 (3.34.0)<br>  <br>- September 23, 2021 (3.34.1) | - **Includes a security fix for an HTTP header injection. See the [CVE-2021-40143](https://support.sonatype.com/hc/en-us/articles/4405941762579?_ga=2.144777012.1655145303.1630329522-734262072.1623073293) advisory for details**<br>  <br>- Repository replication now available for all Pro customers PRO<br>  <br>- Added Cocoapods, RubyGems, p2, and Go formats for PostgreSQL database for H2 and PostgreSQL databases PRO<br>  <br>- Improvements to Nexus Repository 2 to Nexus Repository 3 migration<br>  <br>- Changed default location for storing import task metadata |
| [3.33.0-3.33.1](https://help.sonatype.com/en/nexus-repository-3-33-0---3-33-1-release-notes.html "Nexus Repository 3.33.0 - 3.33.1 Release Notes") | - August 4, 2021 (3.33.0)<br>  <br>- August 17, 2021 (3.33.1) | - Critical fix for those migrating to a PostgreSQL database that prevents moving over privilegs for formats not yet supported in the PostgreSQL solution<br>  <br>- Upgrade Eclipse Jetty to version 9.4.43.v20210629<br>  <br>- Changes to Single-Node cloud resilient deployment example to remove the dependency on Amazon Elastic File System (EFS) PRO<br>  <br>- Added npm, Conan, Conda, Git LFS, and R formats for PostgreSQL database PRO<br>  <br>- New pro trial landing page |
| [3.32.0-3.32.1](https://help.sonatype.com/en/nexus-repository-3-32-0---3-32-1-release-notes.html "Nexus Repository 3.32.0 - 3.32.1 Release Notes") | - July 8, 2021 (3.32.0)<br>  <br>- December 20, 2021 (3.32.1) | - Introduction of repository replication product preview PRO<br>  <br>- Added APT format for PostgreSQL database<br>  <br>- Fix for known Docker issue NEXUW-28247<br>  <br>- Updated logback library from version 1.2.3 to version 1.2.9. |
| [3.31.0-3.31.1](https://help.sonatype.com/en/nexus-repository-3-31-0---3-31-1-release-notes.html "Nexus Repository 3.31.0 - 3.31.1 Release Notes") | - June 16, 2021 (3.31.0)<br>  <br>- June 23, 2021 (3.31.1) | - **Includes a security fix for an Information Disclosure CVE. See the [CVE-2021-34553](https://support.sonatype.com/hc/en-us/articles/4402433828371) advisory for details**<br>  <br>- Nexus Repository Pro can now use an externalized PostgreSQL database instead of OrientDB. PRO<br>  <br>  <br>  <br>  - Formats supported include Maven, Docker, NuGet V3, PyPI, Helm, Raw, and Yum<br>    <br>- Upgrade Eclipse Jetty to 9.4.42.v20210604<br>  <br>- Fix for NEXUS-28078 - _Docker - Delete unused manifests and images_ task may delete referenced layers if the database query to select components encounters limits |
| [3.30.0-3.30.1](https://help.sonatype.com/en/nexus-repository-3-30-0---3-30-1-release-notes.html "Nexus Repository 3.30.0 - 3.30.1 Release Notes") | - March 4, 2021 (3.30.0)<br>  <br>- April 22, 2021 (3.30.1) | - **Includes a security fix for an Information Disclosure CVE. See the [CVE-2021-30635](https://support.sonatype.com/hc/en-us/articles/1500006879561) advisory for details**<br>  <br>- **Includes a security fix for an XSS vulnerability. See [CVE-2021-29159](https://support.sonatype.com/hc/en-us/articles/1500005031082) advisory for details**<br>  <br>- **Includes a security fix for a Sensitive Information Disclosure CVE. See the [CVE-2021-29158](https://support.sonatype.com/hc/en-us/articles/1500006126462) advisory for details**<br>  <br>- **Known Docker issue in 3.30.0 (NEXUS-28247); This is fixed in 3.32.0**<br>  <br>- Upgrade Eclipse Jetty to 9.4.40.v20210413<br>  <br>- Azure blob store support PRO<br>  <br>- Protection against namespace confusion<br>  <br>- GPG for Yum repositories<br>  <br>- Logjam attack prevention |
| [3.29.0-3.29.2](https://help.sonatype.com/en/nexus-repository-3-29-0---3-29-2-release-notes.html "Nexus Repository 3.29.0 - 3.29.2 Release Notes") | - December 4, 2020 (3.29.0)<br>  <br>- December 24, 2020 (3.29.1)<br>  <br>- January 6, 2021 (3.29.2) | - #### Includes Security Fix for XML External Entity CVE. See the CVE-2020-29436 advisory for details.<br>  <br>- 3.29.2 contains a fix for a _Cleanup Policies_ bug found in 3.29.1<br>  <br>- Filtering npm package root metadata<br>  <br>- Deprecated /service/metrics/healthcheck<br>  <br>- Support for Maven and Gradle SHA256/SHA512 hashing<br>  <br>- Remote URL of nuget.org-proxy defaults to V3 for new installs<br>  <br>- More secure direct inbound HTTPS connection ciphers and TLS protocols |
