Download and Compatibility
Download and Compatibility
View the Sonatype IQ Server Release Notes for a description of the latest features and improvements.
IQ and IQ CLI version 179 were the last to support Java 8 and 11, and are now in Extended Maintenance as defined in our Sunsetting documentation. Upgrade to Java 17 before upgrading to version 180+.
For the latest features and full support, switch to the cross-platform IQ CLI with bundled JDK, available below.
Sonatype IQ Server
| Latest version: | Sonatype IQ Server identifies security vulnerabilities, license risks, and quality issues in your components, providing actionable insights and automated enforcement across your software development lifecycle (SDLC). |
| Application | Download Links |
|---|---|
| Sonatype IQ Server with bundled JDK | MUSL Linux (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512) Linux (AArch64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512) Linux (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512) Windows (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512) |
| Sonatype IQ Server Docker Image | Nexus IQ Server Docker Image on DockerHub |
Sonatype IQ CLI
Beginning with release 186 (January 2025), IQ CLI is a standalone product and will no longer be included in the IQ Server bundle.
| Latest version: | Sonatype IQ Command Line Interface (CLI) is the multi-tool for performing a Lifecycle Analysis. Evaluations of your applications are either run manually or automatically using the CLI in many environments. |
| Application | Download Links |
|---|---|
| IQ CLI - Cross-platform (Java) | nexus-iq-cli-latest.jar ( ASC, SHA1) Requires the Java Virtual Machine. |
| IQ CLI with bundled JDK | The Linux CLI can be installed on distributions supporting Deb or RPM packages. Alternatively, you can use Homebrew. |
| IQ CLI - Docker | Docker Hub |
The native IQ CLI - Mac OSX has been sunset. It received only critical bug and security fixes through June 10, 2025, and is no longer supported.
The native IQ CLI - Linux and IQ CLI - Windows has been sunset. It received only critical bug and security fixes through September 14, 2025, and is no longer supported.
For the latest features and full support, switch to the cross-platform IQ CLI with bundled JDK, available above.
Sonatype IQ CLI Compatibility
iq-cli
iq-cli
Compatibility
| CLI Version | IQ Server Version | Java Runtime |
|---|---|---|
| 1.180.0 to latest | 87 to latest | JDK 17 to latest |
| 1.87.0 to 1.179.0 | 87 to latest | JDK 8 to JDK 11 |
Note
For detailed information on feature availability in each CLI version, please review the IQ CLI Release Notes. This will help you determine the precise CLI version required for your desired functionality.
CI Integrations
| Integration | Version | Download links |
|---|---|---|
| ##### Maven | This plugin is automatically downloaded when invoked through Maven Release notes are available on the Sonatype CLM for Maven page. |
|
| ##### Bamboo | Release notes are available on the Sonatype for Bamboo Data Center page. | |
| ##### Jenkins | Installation through the Jenkins UI Installation through the Jenkins Plugin Manager Release notes are available on the Sonatype Platform Plugin for Jenkins page. |
|
| ##### Azure DevOps | Installation instructions and release notes are available on the Sonatype for Azure DevOps page. | |
| ##### GitLab CI | Configuration instructions and release notes are available on the Sonatype for GitLab CI page. | |
| ##### GitHub Actions | Usage instructions and release notes are available on the GitHub Actions page. |
IDE Integrations
| Integration | Version | Download Links |
|---|---|---|
| ##### Eclipse | Eclipse Update Site:<br>https://download.sonatype.com/clm/eclipse/releases<br>This update site is not directly browsable. Copy the URL and paste it into the list of update sites in Eclipse under Help-> Preferences -> Install/Update -> Available Software Update Sites. The plugin zip can be installed into Eclipse by using "Help -> Install New Software ->Add... -> Archive...". - IBM Rational Application Developer (RAD) is not tested but should work. - The plugin requires Eclipse 4.25 and higher; RAD versions based on older Eclipse releases may not be compatible. Release notes are available on the IQ for Eclipse page. |
|
| ##### IDEA | Release notes are available on the Sonatype for IDEA page. | |
| ##### VS Code | The "Sonatype for VS Code" extension is installable from within VS Code using the Extensions tool window. Release notes are available on the Sonatype for VS Code page. |
|
| ##### Visual Studio 2022 | The "Sonatype Visual Studio Extension" is installable from within Visual Studio using the Extensions and Updates dialog box. Release notes are available on the Sonatype for Visual Studio 2022 page. |
Reporting Integrations
| Integration | Version | More Information |
|---|---|---|
| ##### Jira Data Center | Release notes are available on the Sonatype for Jira Data Center page. | |
| ##### Jira Cloud | Release notes are available on the Sonatype for Jira Cloud page. |
Sonatype Repository Firewall for Artifactory
The plugin binaries support alternate versions of JFrog Artifactory as of the 7.104.5 version. Review the Firewall for Artifactory compatibility information below before downloading one of the below plugin versions.
| Integration | Download Link |
|---|---|
| Firewall for Artifactory 2.7.2 |
nexus-iq-artifactory-plugin-2.7.2.zip ( ASC, SHA1) |
| Firewall for Artifactory 2.7.1 |
nexus-iq-artifactory-plugin-2.7.1.zip ( ASC, SHA1) |
| Firewall for Artifactory 2.6.1 |
nexus-iq-artifactory-plugin-2.6.1.zip ( ASC, SHA1). |
| ##### Firewall for Artifactory 2.6.0 |
nexus-iq-artifactory-plugin-2.6.0.zip ( ASC, SHA1). |
| ##### Firewall for Artifactory 2.4.13 |
nexus-iq-artifactory-plugin-2.4.13.zip ( ASC, SHA1). |
Release notes are available on the Firewall for Artifactory Release Notes page.
Compatibility with Integrations
Sonatype encourages using an IQ Server release no older than six months. Contact the Support Team for assistance updating older versions of IQ Server or any associated integration.
Compatibility information for specific Sonatype integrations can be found on their respective pages.
Sonatype Nexus Repository 3 compatibility with IQ Server
Review the Repository Firewall documentation for details on feature compatibility between the IQ server and the Nexus Repository.
Sonatype Lifecycle for Nexus Repository Pro
Sonatype Lifecycle for Nexus Repository Pro does not require the installation of any specialized components. We recommend staying up to date on the latest version of both products.
Firewall for Artifactory
| Plugin Version | IQ Server Version | Artifactory Version |
|---|---|---|
| 2.5.0 and higher | Supports JFrog Artifactory 7.104.5 and later | |
| 2.2.0 to 2.4.13 | 119 and higher Tested on multi-node clusters |
Tested on JFrog Artifactory Enterprise 7.2.6 Supports up to JFrog Artifactory 7.98.15 |
| 1.* to 2.0 | Updating requires IQ 119 and data migration |
Sonatype Lifecycle for SCM
| Feature \ SCM | Azure DevOps | Bitbucket Cloud | Bitbucket Server | GitHub | GitLab |
|---|---|---|---|---|---|
| Automated Commit Feedback | IQ 122 | IQ 90 | IQ 90 | IQ 67 | IQ 71 |
| Automated Pull Requests | IQ 122 | IQ 90 | IQ 90 | IQ 79 | IQ 97 |
| Pull Request Commenting | IQ 122 | IQ 95 | IQ 88 | IQ 98 | |
| Pull Request Line Commenting | IQ 95 | IQ 95 | IQ 99 | ||
| Bitbucket Code Insights | N/A | IQ 95 | N/A | N/A |