Sonatype for IDEA
Sonatype for IDEA
IntelliJ IDEA is a fully-featured integrated development environment (IDE) used for Java development. WebStorm is an IDE for the JavaScript ecosystem.
The Sonatype for IDEA integration is available on the JetBrains Marketplace.
Supported JetBrains IDEs for Lifecycle Component Analysis
| Development Environment | Java (maven) | Node.js (npm) |
|---|---|---|
| IDEA Ultimate | ||
| IDEA Community | ||
| Android Studio | ||
| WebStorm |
Release Notes
nexus-iq-idea-plugin | Nexus IQ integration for Intellij IDEA
nexus-iq-idea-plugin
Changelog
Version 4.18.1 (July 15, 2026)
- Improved compatibility with newer IDEA versions
Version 4.18.0 (June 01, 2026)
- Added search functionality to the Application list
Version 4.17.1 (February 11, 2026)
- Added support for anonymous Proxy Configurations
Version 4.17.0 (September 22, 2025)
- Added support for evaluating Java 25 bytecode
Version 4.16.0 (September 09, 2025)
- Removed Python component analysis to restore compatibility with the latest IntelliJ version
Version 4.15.0 (July 21, 2025)
- Replaced usages of deprecated APIs, which makes the plugin compatible with IDEA 2025.1 and newer
- Added support for evaluating Java 23 and 24 bytecode
Version 4.14.0 (November 19, 2024)
- Minimum supported IntelliJ IDEA version is now 2024.2
Version 4.13.0 (October 21, 2024)
- Added support for Golden Versions, the non-breaking upgrade resolving policy violations for the component and its dependencies
- Updated plugin and tool window icons in both light and dark modes
Version 4.12.0 (July 30, 2024)
- Added support for Android Studio 2023.1 and newer
Version 4.11.0 (May 23, 2024)
- Replaced usages of deprecated APIs, which makes the plugin compatible with IDEA 2023.1 and newer
Version 4.10.1 (May 01, 2024)
- Bug fix: IQ Server URL works with or without trailing slashes
Version 4.10.0 (Sep 01, 2023)
- Added support for a new migration scenario for maven projects
Version 4.9.1 (Jul 10, 2023)
- Bug fix: Removed obsolete dependency
Version 4.9.0 (Jun 05, 2023)
- Added support for evaluating Java 19 and 20 bytecode
Version 4.8.1 (Feb 28, 2023)
- Better user experience when Nexus IQ Server is unreachable
- Bug fix: ‘Migrate to Selected’ feature is available for transitive dependencies as well
Version 4.8.0 (Jan 11, 2023)
- Redesigned plugin UI
Version 4.7.3
- Improved the detection of Node modules
Version 4.7.2
- Minor bug fix: UI content created on wrong thread
Version 4.7.1
- Improved the detection of Node package managers
Version 4.7.0
- Added support for evaluating Java 18 bytecode
Version 4.6.0
- List unresolved NPM dependencies in the component list
Version 4.5.0
- List unresolved Maven dependencies in the component list
Version 4.4.1
- Forward to Nexus IQ for CVE details
Version 4.4.0
- Replaced usages of removed APIs, which makes the plugin compatible with IDEA 2022.1
- Minor bug fixes
Version 4.3.0
- Better inform users about SSL certificate errors
- Added Maven and Node.js code policy violation linked inspections
- Minor bug fixes
Version 4.2.0
- Replaced usages of deprecated scheduled for removal APIs, which makes the plugin compatible with IDEA 2022.1
Version 4.1.1
- Handle non-empty web context in Nexus IQ Server URL
Version 4.1.0
- Added support for evaluating Python components and PyCharm integration
Version 4.0.0
- Added support for evaluating Java 17 bytecode
- Added support for the upcoming IDEA 2021.3
- Dropped support for IDEA 2020.2
Version 3.5.1
- Removed duplicates in pnpm component evaluation
- Minor UI improvements
Version 3.5.0
- Improved support for evaluating Node components
Version 3.4.0
- Added support for evaluating Node components
Version 3.3.1
- Fixed plugin configuration UI freeze when IQ server is unreachable
Version 3.3.0
- Added support for evaluating Java 16 bytecode
Version 3.2.0
- Upgraded plugin architecture i.e. use light services
Version 3.1.1
- Fixed missing credentials issue is IDEA 2020.3.1 or newer
Version 3.1.0
- Added support for evaluating Java 14 and 15 bytecode
Version 3.0.0
- Added support for IDEA 2020.2
Version 2.9.0
- Removed JSR 305
Version 2.8.0
- Honor exceptions in Java FX browser
- Obfuscate headers in idea.log
- Correct check for updates when using a proxy
- Correct CIP navigation issues
Version 2.7.0
- Improved Components tab performance
Version 2.6.1
- Fixed Idea proxy usage in web based components (e.g. Component Information Panel)
- Upgraded apache commons-compress dependency to a non-vulnerable version
Version 2.6
- New Feature: Automatically Migrate Dependencies for Maven projects from within the Nexus Component Info View (requires Nexus IQ Server 68+)
Version 2.5.1
- Fixed an error that occurred when no component is selected
- Fixed an error that occurred with broken Maven projects
- Simpler storage in 2018.2
- Better compatibility with Java 11
- Fixed bug with Find Usages
Version 2.5
- Added support for scanning dependencies with Java 12
Version 2.4
- Updated to latest scanners with Java 11
- Fixes for HTTP proxies
Version 2.3
- Load Assets from Nexus IQ Server more reliably
Version 2.2
- New Feature: Support proprietary components
- Fix compatibility for IDEA 15+
Version 2.1
- Updated to latest scanners
Version 2.0
- Fixed bug with Find Usages in IDEA 2018
- Dropped support for IDEA 14
Version 1.0
- Initial release
Compatibility
nexus-iq-idea-plugin | Nexus IQ integration for Intellij IDEA
nexus-iq-idea-plugin
Compatibility
| Plugin Version | Development Environment | Version | IQ Server Version | Java Runtime |
|---|---|---|---|---|
| 4.19 or later | IDEA Ultimate, IDEA Community, Android Studio, WebStorm | 2025.1 or higher | 129 or higher | JBRSDK 21 |
| 4.15 - 4.18 | IDEA Ultimate, IDEA Community, Android Studio, WebStorm | 2025.1 or higher | 129 or higher | JBRSDK 17 |
| 4.14 | IDEA Ultimate, IDEA Community, Android Studio, WebStorm, PyCharm Professional, PyCharm Community | 2024.2 to 2025.3.x | 129 or higher | JBRSDK 17 |
| 4.12 - 4.13 | IDEA Ultimate, IDEA Community, Android Studio, WebStorm, PyCharm Professional, PyCharm Community | 2023.1 to 2024.1 | 129 or higher | JBRSDK 17 |
| 4.11 | IDEA Ultimate, IDEA Community, WebStorm, PyCharm Professional, PyCharm Community | 2023.1 to 2024.1 | 129 or higher | JBRSDK 17 |
| 4.4 - 4.10 | IDEA Ultimate, IDEA Community, WebStorm, PyCharm Professional, PyCharm Community | 2022.x | 129 or higher | JBRSDK 11, JBRSDK 17 |
| 4.2 - 4.3 | IDEA Ultimate, IDEA Community, WebStorm, PyCharm Professional, PyCharm Community | 2021.2 to 2021.3.x | 129 or higher | JBRSDK 11 |
| 4.1 | IDEA Ultimate, IDEA Community, WebStorm, PyCharm Professional, PyCharm Community | 2020.3 to 2021.3.x | 129 or higher | JBRSDK 11 |
| 4.0 | IDEA Ultimate, IDEA Community, WebStorm | 2020.3 to 2021.3.x | 67 or higher | JBRSDK 11 |
| 3.x | IDEA Ultimate, IDEA Community, WebStorm | 2020.2.x | 67 or higher | Oracle JDK 8, JBRSDK 8, JBRSDK 11 |
| 2.x | IDEA Ultimate, IDEA Community | 2016.2 to 2020.1.x | 67 or higher | Oracle JDK 8, JBRSDK 8, JBRSDK 11 |
| 1.x | IDEA Ultimate, IDEA Community | 14.1.x to 15.0.3 | 66 or higher | Oracle JDK 8, JBRSDK 8 |
Installing Sonatype for IDEA
Python analysis removed
Starting in version 4.16.0-01, the Sonatype for IDEA plugin no longer supports Python (PyPI) analysis due to incompatibilities with recent IntelliJ platform releases.
If you require Python analysis, use the last plugin version that supports it: 4.14.0-01 — download nexus-iq-idea-plugin-4.14.0-01.zip.
Download latest version:
Sonatype for IDEA supports installation via a zip file. Installation is performed using the Settings/Preferences dialog. Select Plugins from the left-hand pane to open the option to install the plugin from disk. From there, browse to the plugin zip file and select it.
Configuring Sonatype for IDEA
After the installation, the plugin needs to be configured to connect to your Lifecycle server. From a project view, click the Nexus IQ icon on the Tool Windows menu, and then click on the gear icon to configure the integration with your Sonatype Lifecycle credentials.
Server URL: Enter the base URL of your IQ Server including a trailing slash. Eg. https://iq.cloud.sonatype.com/
Authentication Method:
- PKI Authentication: Delegate authentication to the JVM.
- User Authentication: Enter your credentials or user token for the Lifecycle server.
Note
You will be prompted for your IDEA Master Password when saving the Preferences/Settings. This allows IDEA to store your Lifecycle credentials securely.
Once the connection information is provided, select Connect to verify the connection to the Lifecycle server. When connected, select an application from the dropdown. The policies scoped to this application are used when evaluating your IDE project.
Using the Component Info View
The Sonatype for IDEA tool window can be accessed by clicking the IQ Tab on the bottom tool strip of IDEA. This is also available in View > Tool Windows.
Once configured and the component analysis is completed, a component view is populated with all open source components and their metadata. The list of components reflect an analysis of the project’s dependencies. For Java projects, that include all project libraries. For JavaScript projects, it includes all dependent Node modules. Mixed projects, contain a mix of Java and JavaScript dependencies.
By default, all project dependencies are included in the component list. Scope filters can be applied to adjust which components are visible.
The following scopes are available:
- Java components: Compile, Test, Runtime, and Provided;
- JavaScript/Node components: Production, and Development;
Right-clicking on any component will bring up a menu of actions. All components allow for the following actions: View Details and Find Usages. Maven-based Java components show an extra action: Open Maven POM.
- View Details will open the details screen providing more context to the component.
- Find Usages will bring up a list of every module the component is used in. Clicking on a module will display the location where the component is declared, which is either a Maven POM file or a package.json file.
- Open Maven POM will open the Maven POM of the component selected.
Multi-Language Projects
The Sonatype for IDEA plugin detects and analyzes components written in different programming languages, within a single project. The project is organized to follow the JetBrains recommended project structure.
IntelliJ IDEA project structure consists of projects and modules. A project can contain source code, tests, libraries in use, build instructions, and configuration files. It may contain one or more modules. When no modules are defined for the project, the project itself is considered a module.
New Modules
At the time of new module creation, select a language and an optional build system. IntelliJ IDEA uses this language selection to determine the features of the IDE that are available for this module. This is a 1:1 association and works only for a single language.
Modules of existing projects
When an existing project is imported into IntelliJ IDEA, the IDE detects all the modules it contains and assigns a language to each module. You can modify the module detection and structuring after import by navigating to File > Project Structure.
Note
To maximize the results of component detection in multi-language projects, ensure that each module contains files specific to a single language.
Example:
A web application has Node.js frontend and a Maven/Java backend. The project should be organized into at least one Node.js module and at least one Maven/Java module. No module should contain both Java and JavaScript files.
The plugin detects both Java and JavaScript components.
NOTE: IntelliJ IDEA associates one language with a module, even if the module contains files of different languages. The plugin follows this association and detects the components of that language only.
When IntelliJ IDEA has associated Java with a module that contains both Java and JavaScript files, the plugin detects Java components only.
Troubleshooting Load Components
Java Projects
In Maven or Gradle-based projects, when a project is first opened in the IDE, it is possible that it was not imported for the project type (maven or gradle). The symptom for this condition is an empty External Libraries folder in the Project view:
The project (i.e. its manifest files) must be imported to get the list of External Libraries to appear. For Maven projects, locate the root pom.xml file, right-click, then select Maven → Reload project, or Add as Maven Project, depending on your version of IntelliJ IDEA.
NOTE: For Gradle projects locate the build.gradle file, right-click, then select Reload from disk.
This will convert the project to its proper type which will load the External Libraries:
Now, you can click on the Evaluate Components button and the analyzed components will load in the component view. The evaluation results will look something like this:
JavaScript Projects
JavaScript projects must be set up in the IDE as Node projects. This can be configured by navigating to File → Settings → Language & Frameworks → Node.js and NPM. The paths to the Node interpreter and the package manager must be valid (see below).
Migrating to Different Component Versions
Note
For Java projects, this feature relies on the project being Maven-based. Gradle-based Java projects can be analyzed, but the Migrate to Selected feature is not available for Gradle-based projects. For JavaScript projects, this feature expects that the project is properly set up in the IDE as a Node project and that a package manager is available (i.e. npm, yarn, or pnpm).
If you determine that a component upgrade is required to avoid a security or license issue or a policy violation, after reviewing your component usage, the plugin can be used to assist you in the necessary refactoring.
The first step to start the migration is to select a newer version for the component in the visualization chart, or by selecting the recommended version.
A version of a dependency with no policy violations and no breaking changes for the same component and its dependencies will be presented as a Golden Version, which means that the migration can be done with minimal effort.
Alternate versions might also be available so you can migrate to them in case there is no Golden Version available.
For supported project types, once you have selected a different version than the one currently used, the Migrate to Selected button will become active. Selecting the button migrates from the current component version to the selected component version, by updating the component version in the manifest file.
For Maven-based Java projects, the migration process is able to detect circumstances such as the component being a transitive dependency or versions managed in a property. For JavaScript projects, only direct dependencies can be migrated.
For Gradle-based Java projects, the plugin can identify components and recommended versions, but dependency version changes must be made manually in the Gradle build file.
After the migration is completed, the component list will be updated and a component scan will be initiated. You should perform a full build, as well as a thorough test, to determine that you can proceed with the new version in your development.
Typically, smaller version changes will have a higher chance of working without any major refactorings, or adaptations, of your codebase and projects, while larger version changes potentially give you more new features or bug fixes.
Your release cycle, customer demands, production issues, and other influencing factors will determine your version upgrade choices. You might decide on a multi-step approach, where you do a small version upgrade immediately to resolve current issues and then work on the larger upgrade subsequently to get the benefits of using a newer version. Or, you might be okay with doing an upgrade to the latest available version straight away. Potentially, a combination of approaches in different branches of your source code management system is used to figure out the best way of going forward with the upgrade.
Code Inspections
New in version 4.3.0, custom code inspections are provided for pom.xml and package.json files. If a component, declared in those files, has critical, severe or moderate policy violations, it gets a code inspection maker attached to it, describing the severity of the violation and providing a link to its corresponding entry in the Component Info view.
Upgrading to IntelliJ IDEA 2020.2
When upgrading to a newer version of IntelliJ IDEA from version 2020.1.x and below, you will need to install the latest version of the plugin. The Sonatype for IDEA plugin does not automatically upgrade itself when upgrading IntelliJ. We recommend uninstalling the plugin and reinstalling the latest plugin once the upgrade is complete.
You might see a message like this when you start the IntelliJ IDEA 2020.2.x upgrade: