Download and Compatibility

Download and Compatibility

View the Sonatype IQ Server Release Notes for a description of the latest features and improvements.

IQ and IQ CLI version 179 were the last to support Java 8 and 11, and are now in Extended Maintenance as defined in our Sunsetting documentation. Upgrade to Java 17 before upgrading to version 180+.

For the latest features and full support, switch to the cross-platform IQ CLI with bundled JDK, available below.

Sonatype IQ Server

Latest version: Sonatype IQ Server identifies security vulnerabilities, license risks, and quality issues in your components, providing actionable insights and automated enforcement across your software development lifecycle (SDLC).
Application Download Links
Sonatype IQ Server with bundled JDK MUSL Linux (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512)
Linux (AArch64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512)
Linux (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512)
Windows (x86-64) release 1.205.0-03 ( MD5, SHA1, SHA256, SHA512)
Sonatype IQ Server Docker Image Nexus IQ Server Docker Image on DockerHub

Sonatype IQ CLI

Beginning with release 186 (January 2025), IQ CLI is a standalone product and will no longer be included in the IQ Server bundle.

Latest version: Sonatype IQ Command Line Interface (CLI) is the multi-tool for performing a Lifecycle Analysis. Evaluations of your applications are either run manually or automatically using the CLI in many environments.
Application Download Links
IQ CLI - Cross-platform (Java) nexus-iq-cli-latest.jar ( ASC, SHA1)
Requires the Java Virtual Machine.
IQ CLI with bundled JDK The Linux CLI can be installed on distributions supporting Deb or RPM packages.
Alternatively, you can use Homebrew.
IQ CLI - Docker Docker Hub

For the latest features and full support, switch to the cross-platform IQ CLI with bundled JDK, available above.

Sonatype IQ CLI Compatibility

iq-cli

iq-cli

Compatibility

CLI Version IQ Server Version Java Runtime
1.180.0 to latest 87 to latest JDK 17 to latest
1.87.0 to 1.179.0 87 to latest JDK 8 to JDK 11

Note

For detailed information on feature availability in each CLI version, please review the IQ CLI Release Notes. This will help you determine the precise CLI version required for your desired functionality.

CI Integrations

Integration Version Download links
##### Maven This plugin is automatically downloaded when invoked through Maven
Release notes are available on the Sonatype CLM for Maven page.
##### Bamboo Release notes are available on the Sonatype for Bamboo Data Center page.
##### Jenkins Installation through the Jenkins UI
Installation through the Jenkins Plugin Manager
Release notes are available on the Sonatype Platform Plugin for Jenkins page.
##### Azure DevOps Installation instructions and release notes are available on the Sonatype for Azure DevOps page.
##### GitLab CI Configuration instructions and release notes are available on the Sonatype for GitLab CI page.
##### GitHub Actions Usage instructions and release notes are available on the GitHub Actions page.

IDE Integrations

Integration Version Download Links
##### Eclipse Eclipse Update Site:
<br>https://download.sonatype.com/clm/eclipse/releases<br>
This update site is not directly browsable. Copy the URL and paste it into the list of update sites in Eclipse under Help-> Preferences -> Install/Update -> Available Software Update Sites.
The plugin zip can be installed into Eclipse by using "Help -> Install New Software ->Add... -> Archive...".
- IBM Rational Application Developer (RAD) is not tested but should work.

- The plugin requires Eclipse 4.25 and higher; RAD versions based on older Eclipse releases may not be compatible.

Release notes are available on the IQ for Eclipse page.
##### IDEA Release notes are available on the Sonatype for IDEA page.
##### VS Code The "Sonatype for VS Code" extension is installable from within VS Code using the Extensions tool window.
Release notes are available on the Sonatype for VS Code page.
##### Visual Studio 2022 The "Sonatype Visual Studio Extension" is installable from within Visual Studio using the Extensions and Updates dialog box.
Release notes are available on the Sonatype for Visual Studio 2022 page.

Reporting Integrations

Integration Version More Information
##### Jira Data Center Release notes are available on the Sonatype for Jira Data Center page.
##### Jira Cloud Release notes are available on the Sonatype for Jira Cloud page.

Sonatype Repository Firewall for Artifactory

The plugin binaries support alternate versions of JFrog Artifactory as of the 7.104.5 version. Review the Firewall for Artifactory compatibility information below before downloading one of the below plugin versions.

Integration Download Link
Firewall for Artifactory
2.7.2
nexus-iq-artifactory-plugin-2.7.2.zip ( ASC, SHA1)
Firewall for Artifactory
2.7.1
nexus-iq-artifactory-plugin-2.7.1.zip ( ASC, SHA1)
Firewall for Artifactory
2.6.1
nexus-iq-artifactory-plugin-2.6.1.zip ( ASC, SHA1).
##### Firewall for Artifactory
2.6.0
nexus-iq-artifactory-plugin-2.6.0.zip ( ASC, SHA1).
##### Firewall for Artifactory
2.4.13
nexus-iq-artifactory-plugin-2.4.13.zip ( ASC, SHA1).

Release notes are available on the Firewall for Artifactory Release Notes page.

Compatibility with Integrations

Sonatype encourages using an IQ Server release no older than six months. Contact the Support Team for assistance updating older versions of IQ Server or any associated integration.

Compatibility information for specific Sonatype integrations can be found on their respective pages.

Sonatype Nexus Repository 3 compatibility with IQ Server

Review the Repository Firewall documentation for details on feature compatibility between the IQ server and the Nexus Repository.

Sonatype Lifecycle for Nexus Repository Pro

Sonatype Lifecycle for Nexus Repository Pro does not require the installation of any specialized components. We recommend staying up to date on the latest version of both products.

Firewall for Artifactory

Plugin Version IQ Server Version Artifactory Version
2.5.0 and higher Supports JFrog Artifactory 7.104.5 and later
2.2.0 to 2.4.13 119 and higher
Tested on multi-node clusters
Tested on JFrog Artifactory Enterprise 7.2.6
Supports up to JFrog Artifactory 7.98.15
1.* to 2.0 Updating requires IQ 119 and data migration

Sonatype Lifecycle for SCM

Feature \ SCM Azure DevOps Bitbucket Cloud Bitbucket Server GitHub GitLab
Automated Commit Feedback IQ 122 IQ 90 IQ 90 IQ 67 IQ 71
Automated Pull Requests IQ 122 IQ 90 IQ 90 IQ 79 IQ 97
Pull Request Commenting IQ 122 IQ 95 IQ 88 IQ 98
Pull Request Line Commenting IQ 95 IQ 95 IQ 99
Bitbucket Code Insights N/A IQ 95 N/A N/A