# 2023 Release Notes

## Summary of Major Changes in 2023

The following table lists major changes in 2023 that should be considered when upgrading to a new version. Select a release for more information.

| Release | Release Date | Major Changes |
| --- | --- | --- |
| [3.63.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-63-0-release-notes.html "Sonatype Nexus Repository 3.63.0 Release Notes") | December 5, 2023 | - Changes to HA Helm Chart<br>  <br>  <br>  <br>  - Removed version numbers from Kubernetes objects that the Helm chart creates<br>    <br>  - Added custom labels and selectors<br>    <br>  - Added ability to use existing volumes and volume mounts<br>    <br>- Additional Audit logging<br>  <br>  <br>  <br>  - For SAML, we now log user login, logout, and config-changed events<br>    <br>  - For local authentication, LDAP, and Crowd, we now log user login and logout events<br>    <br>- Filter _Repositories_ table by blob store name<br>  <br>- org.apache.santuario updated from version 2.3.0 to 2.3.4<br>  <br>- org.json : json : updated to 20231013 |
| [3.62.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-62-0-release-notes.html "Sonatype Nexus Repository 3.62.0 Release Notes") | November 7, 2023 | - New Cleanup Preview Experience for Pro Customers Using PostgreSQL<br>  <br>- New Combined Helm Chart for AWS, Azure, or On-Premises High Availability Deployments<br>  <br>- Azure HA Performance Data<br>  <br>- Support Zip Improvements<br>  <br>  <br>  <br>  - Generate zip for all nodes<br>    <br>  - Download link persists<br>    <br>- Expanded Audit Logging<br>  <br>  <br>  <br>  - Include records for "Clear Cache" and "Change (server) order" LDAP events.<br>    <br>  - Added logging for when you create, update, or delete a routing rule.<br>    <br>- Upgraded Jetty from version 9.4.51.v20230217 to version 9.4.53.v20231009<br>  <br>- Upgraded goodies from version 2.3.5 to version 2.3.6<br>  <br>- Upgraded eclipse-sisu from version 0.3.4 to version 0.3.5<br>  <br>- Upgraded guice from version 5.0.1 to version 6.0.0<br>  <br>- HA-C Now in Extended Maintenance<br>  <br>- Resolved an important database migrator issue that could cause components and assets to be migrated in the wrong order.<br>  <br>Resolved an important database migrator issue that was causing the Database Migrator to import components and assets in the wrong order. |
| [3.61.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-61-0-release-notes.html "Sonatype Nexus Repository 3.61.0 Release Notes") | October 4, 2023 | - New OpenShift Operator for PostreSQL and High Availability Deployments<br>  <br>- Change Repository Blobstore Task Supports Proxy Repositories<br>  <br>- Policy-Compliant Component Selection for PyPI<br>  <br>- Sonatype Nexus Repository Usage Metrics<br>  <br>- Reworked our implementation to avoid copy operations while uploading components so as to improve Azure blob store performance<br>  <br>- Bug fixes, including a fix for the known issue in 3.60 and 3.59 impacting deployments using OrientDB with LDAP and SAML users that have the exact same User ID. |
| [3.60.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-60-0-release-notes.html "Sonatype Nexus Repository 3.60.0 Release Notes") | September 7, 2023 | **Warning**<br>There is a known issue in Sonatype Nexus Repository 3.59.0 & 3.60.0 impacting deployments using OrientDB and configured to have LDAP and SAML users that have the exact same User ID. If you are using OrientDB and have migrated authentication from LDAP to SAML you are advised not to upgrade to Nexus Repo 3.59.0 or 3.60.0.<br>- Fix for the _Repair - Reconcile component database from blob store_task issue noted in the [3.59.0 Release Notes](https://help.sonatype.com/en/sonatype-nexus-repository-3-59-0-release-notes.html "Sonatype Nexus Repository 3.59.0 Release Notes")<br>  <br>- Improved Performance for Deployments Using Crowd<br>  <br>- Support for Cocoapods Stored on Google Open Source<br>  <br>- Removed Local Authorizing Realm from User Interface and API |
| [3.59.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-59-0-release-notes.html "Sonatype Nexus Repository 3.59.0 Release Notes") | August 15, 2023 | **Warning**<br>There is a known issue impacting Sonatype Nexus Repository Pro users who meet **all** of the following criteria:<br>- Were previously on OrientDB and migrated to PostgreSQL<br>  <br>- Have RubyGems, P2, or NuGet v2 assets that were migrated from OrientDB to PostgreSQL<br>  <br>- Have run the _Repair - Reconcile component database from blob store_ task with the _Integrity Check_ option enabled (this option is enabled by default)<br>  <br>The issue causes the task tosoft-delete the blob .properties and .bytes files for NuGet v2 proxy and hosted repositories.<br>The task also will not restore the desired content for RubyGems, NuGet v2 (proxy or hosted), or P2 repositories; however, there is no soft deletion associated with RubyGems or P2 repositories.<br>If you have migrated to PostgreSQL and have RubyGems, P2, or NuGet v2 assets, do not run the _Repair - Reconcile component database from blob store_ task against blobstores containing any of the impacted formats.<br>We will release a fix for this issue in the upcoming 3.60.0 release.<br>**Warning**<br>There is a known issue in Sonatype Nexus Repository 3.59.0 impacting deployments using OrientDB and configured to have LDAP and SAML users with the same ID. If you are using OrientDB and have migrated authentication from LDAP to SAML you are advised not to upgrade to Nexus Repo 3.59.0 or 3.60.0.<br>**Note**<br>****Common Vulnerabilities and Exposures Fix for Apache Shiro****<br>This release upgrades Apahe shiro from 1.10.0 to 1.12.0 to mitigate [CVE-2023-34478](https://nvd.nist.gov/vuln/detail/CVE-2023-34478).<br>**Note**<br>**Common Vulnerabilities and Exposures Fix for SnakeYaml**<br>This release upgrades SnakeYaml from 1.33 to 2.0 to mitigate [CVE-2022-1471](https://nvd.nist.gov/vuln/detail/CVE-2022-1471).<br>- Added support for password encoders like SHA-256, SHA-384, and SHA-512 for LDAP authentication.<br>  <br>- Added outbound request log.<br>  <br>- Added audit logging for content selectors.<br>  <br>- The `blobCreated` date is now preserved when migrating to PostgreSQL.<br>  <br>- Various security fixes for those using user tokens for authentication. |
| [3.58.0 - 3.58.1](https://help.sonatype.com/en/sonatype-nexus-repository-3-58-0---3-58-1-release-notes.html "Sonatype Nexus Repository 3.58.0 - 3.58.1 Release Notes") | July 21, 2023 (3.58.1)<br>July 17, 2023 (3.58.0) | **Warning**<br>3.58.1 fixes a critical bug that could allow users to unintentionally download quarantined components. The bug impacts **3.57.0** and **3.58.0** Sonatype Nexus Repository deployments using Sonatype Repository Firewall.<br>- Restore _Admin - Change repository blob store_ task for deployments using PostgreSQL or H2<br>  <br>  <br>  <br>  - Note that some other tasks now conflict with running this task; read the [Change repository blob store](https://help.sonatype.com/en/change-repository-blob-store.html "Change Repository Blob Store") documentation for full information<br>    <br>- Bug fixes<br>  <br>**Note**<br>**Notable Compatibility Change**: Sonatype Nexus Repository 3.58.0+ is only compatible with IQ Server versions 138+. |
| [3.57.0 - 3.57.1](https://help.sonatype.com/en/sonatype-nexus-repository-3-57-0---3-57-1-release-notes.html "Sonatype Nexus Repository 3.57.0 - 3.57.1 Release Notes") | July 21, 2023 (3.57.1)<br>July 5, 2023 (3.57.0) | **Warning**<br>3.57.1 fixes a critical bug that could allow users to unintentionally download quarantined components. The bug impacts **3.57.0** and **3.58.0** Sonatype Nexus Repository deployments using Sonatype Repository Firewall.<br>- Added an alert to the _Roles_ screen that will inform users if the _Default Role_ capability is enabled and what role is used as the default<br>  <br>- Added a _Blob Store_ column to _Manage repositories_ table<br>  <br>- Added _Last Updated_ column to component search results table<br>  <br>- Modified the policy-compliant component selection checkbox so that it is disabled until and unless both the _Firewall -__Audit and Quarantine_capability is enabled and the _Enable Quarantine_ checkbox that appears within that capability is checked<br>  <br>- Renamed the _Component IQ_ and _IQ Application_ fields in the component browse view to _Sonatype Lifecycle Component_ and _Application_ respectively.<br>  <br>- Bug fixes<br>  <br>  <br>  <br>  - **Notable Search API Functionality Change**<br>    <br>    Made enhancements to the Search APIs to improve the behavior for query parameters on fields that accept empty values. An empty value for most fields is now treated as “specifically empty" instead of the former behavior of treating it like a wildcard. However, note that the repository and format parameters should not be empty as every component is both stored in a repository and has a format. |
| [3.56.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-56-0-release-notes.html "Sonatype Nexus Repository 3.56.0 Release Notes") | June 19, 2023 | - Added a 1-minute timeout for cleanup policy preview<br>  <br>- Search changes for those in HA environments<br>  <br>- Bug fixes |
| [3.55.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-55-0-release-notes.html "Sonatype Nexus Repository 3.55.0 Release Notes") | June 5, 2023 | - Updated [Helm chart for a resilient Sonatype Nexus Repository deployment in AWS](https://github.com/sonatype/nxrm3-helm-repository/tree/main/nxrm-aws-resiliency) to make the following configurations optional:<br>  <br>  <br>  <br>  - Fluentbit<br>    <br>  - External DNS<br>    <br>  - Docker Ingress and service<br>    <br>- Implemented the `/v2/users/authenticate` Conan endpoint for hosted Conan repositories<br>  <br>- Removed references to Repository Health Check from those instances integrated with Sonatype Repository Firewall<br>  <br>  <br>  <br>  - This impacts the _Health Check_ column in tables for browsing and managing repositories as well as the _Health Check: Configuration_ capability<br>    <br>- Bug fixes |
| [3.54.0 - 3.54.1](https://help.sonatype.com/en/sonatype-nexus-repository-3-54-0---3-54-1-release-notes.html "Sonatype Nexus Repository 3.54.0 - 3.54.1 Release Notes") | May 22, 2023 (3.54.1)<br>May 18, 2023 (3.54.0) | Sonatype Nexus Repository 3.54.0 was never officially released and was found to contain a bug that we fixed in 3.54.1. Please use 3.54.1 and do not upgrade to 3.54.0.<br>- Refreshed outreach page<br>  <br>- Export unused assets<br>  <br>- Renamed some IQ Server- and Firewall-related capabilities<br>  <br>- Hid IQ Server Configuration capability from _Capabilities_ screen; you will still configure this connection via the _IQ Server_ tab<br>  <br>- Bug fixes |
| [3.53.0 - 3.53.1](https://help.sonatype.com/en/sonatype-nexus-repository-3-53-0---3-53-1-release-notes.html "Sonatype Nexus Repository 3.53.0 - 3.53.1 Release Notes") | May 12, 2023 (3.53.1)<br>May 2, 2023 (3.53.0) | **Warning**<br>There is a known issue in Sonatype Nexus Repository 3.53.0 impacting those using community or custom plugins. These plugins will not load from the typical install directory and, in some cases, this may prevent Sonatype Nexus Repository from starting.<br>If you are using community or custom plugins and wish to upgrade, remove the plugin before doing so. Otherwise, wait to upgrade until we release a fix for this issue.<br>If you are not using community or custom plugins, there is no impact.<br>**3.53.1**<br>Sonatype Nexus Repository 3.53.1 includes critical bug fixes impacting those using RubyGems who upgraded to Sonatype Nexus Repository 3.53.0.<br>**3.53.0**<br>- Change in Database Property Evaluation Priority when Using PostgreSQL<br>  <br>  <br>  <br>  - Order of priority reversed<br>    <br>  - System Properties and Environment Variables no longer written to file<br>    <br>  - All required configurations must be provided through the same mechanism<br>    <br>- Fix for RubyGems dependency API deprecation<br>  <br>  <br>  <br>  - If you are using RubyGems, you must upgrade to Sonatype Nexus Repository 3.53.0 by May 10 to avoid encountering errors caused by the dependency API deprecation<br>    <br>- _IQ Server configuration_ in API page becomes _Sonatype Repository Firewall configuration; t_he API URL is not affected and remains the same<br>  <br>- _IQ Policy Violation_ column that appears when browsing repositories becomes _Firewall Report_<br>  <br>- Upgraded `org.apache.karaf.jaas:org.apache.karaf.jaas.modules` package from 4.3.6 to 4.3.9 |
| [3.52.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-52-0-release-notes.html "Sonatype Nexus Repository 3.52.0 Release Notes") | April 18, 2023 | - Various bug fixes |
| [3.51.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-51-0-release-notes.html "Sonatype Nexus Repository 3.51.0 Release Notes") | April 4, 2023 | - Automatically Rebuild Search Indexes for New High Availability (HA) Deployments<br>  <br>- Various bug fixes |
| [3.50.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-50-0-release-notes.html "Sonatype Nexus Repository 3.50.0 Release Notes") | March 27, 2023 | - High Availability for PostgreSQL deployments<br>  <br>- Conan revisions support for hosted repositories on PostgreSQL and H2 deployments |
| [3.49.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-49-0-release-notes.html "Sonatype Nexus Repository 3.49.0 Release Notes") | March 6, 2023 | - The _Admin - Cleanup unused asset blobs_ task now uses batch delete by default.<br>  <br>- This release primarily focuses on improving Sonatype Nexus Repository quality by resolving bugs.<br>  <br>- Upgrade Impact - If you are using an H2 or PostgreSQL database, after upgrading to version 3.49.0+, you will need to run an _Apt - Rebuild Apt metadata_ task for each existing Apt repository in order to rebuild their metadata. |
| [3.48.0](https://help.sonatype.com/en/sonatype-nexus-repository-3-48-0-release-notes.html "Sonatype Nexus Repository 3.48.0 Release Notes") | February 27, 2023 | - Content Replication - In this release, we introduce a simpler, more straightforward way to make your artifacts readily available across distributed teams: content replication. With content replication, you can manage what binaries are copied from one instance and pre-emptively pulled via HTTP to other instances.<br>  <br>- Pagination performance improvements for NuGet v2 repositories on deployments using a PostgreSQL database.<br>  <br>- Upgrade Impact - If you are using an H2 or PostgreSQL database, after upgrading to version 3.48.0+, you will need to run a task for each existing Helm and Yum repository in order to rebuild their metadata:<br>  <br>  <br>  <br>  - _Helm - Rebuild Helm metadata_for each Helm repository<br>    <br>  - _Repair - Rebuild Yum rebuild metadata (repodata)_ for each Yum repository |
| [3.47.0 - 3.47.1](https://help.sonatype.com/en/nexus-repository-3-47-0---3-47-1-release-notes.html "Nexus Repository 3.47.0 - 3.47.1 Release Notes") | February 9, 2023 (3.47.1)<br>February 7, 2023 (3.47.0) | **Warning**<br>Release 3.47.1 fixes an issue that was causing missing blob exceptions for those upgrading to 3.47.0. If you have not upgraded to 3.47.0, upgrade to 3.47.1 instead. If you have already upgraded to 3.47.0, upgrade to 3.47.1 as soon as possible.<br>- Nexus Repository now migrates multiple deletion index files for those migrating to a SQL database<br>  <br>- Bug fixes |
| [3.46.0](https://help.sonatype.com/en/nexus-repository-3-46-0-release-notes.html "Nexus Repository 3.46.0 Release Notes") | January 30, 2023 | - Removed _Space Remaining_ Soft Quota Option for Cloud Blob Stores<br>  <br>- Bug fixes |
