# Sonatype IQ Server 200 Release Notes

**Released February 4, 2026**  
The IQ 200 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.

##  Sonatype Lifecycle

This release includes the following changes for Sonatype Lifecycle:

**New _HeroDevs End-of-Life Components_ Dashboard Under Enterprise Reporting**  
Sonatype Lifecycle Enterprise Reporting now includes a _HeroDevs End-of-Life Components_ dashboard, which provides centralized visibility into open-source components that have reached end-of-life (EOL) and are eligible for HeroDevs support. This dashboard helps you quickly understand your organization’s exposure by highlighting affected applications, surfacing the most widely used EOL components, and grouping supported components by ecosystem.

With flexible filters such as _Application_, _Stage_, _Format_, _Component Name_, and _Last Scan Date_, you can refine results to match your operational needs and focus on the areas of highest risk. Data refreshes monthly and reflects your selected scan scope, enabling you to make informed decisions about pursuing extended support and reducing security risk across your software supply chain.

Review your exposure and [contact Sonatype](/content/sonatype-lifecycle/herodevs-eol-support/contact/index.html) to explore extended support options.

For full details, see [our _HeroDevs End-of-Life Components_ help documentation](https://help.sonatype.com/en/herodevs-end-of-life-components.html "HeroDevs End of Life Components").

### Expanded React2Shell Impact Report with In-Product Insights

Sonatype Lifecycle now provides an enhanced _React2Shell Impact Report_ within a new _Rapid Response Reports_ section under _Enterprise Reporting_. This update makes it easier to quickly access time-sensitive vulnerability insights from a centralized location, helping teams respond faster during critical security events.

In addition to the existing CSV download, the report now includes an _Impact Summary_ section directly in the UI. This summary highlights key information such as the impacted applications, components, versions, and files, along with recommended next actions, waiver and evaluation status, and clear visibility into when an issue was first identified and when it was fixed.

Bringing these insights into the product supports faster, more confident decision-making during incident response.

##  Sonatype Developer

This release does not include significant changes to Sonatype Developer.

##  Sonatype SBOM Manager

This release includes the following changes for Sonatype SBOM Manager:

### View Original BOM Details in User Interface

Sonatype SBOM Manager now includes an _Original BOM_ tab on the SBOM detail page. This tab lets you view the SBOM exactly as it was uploaded, helping you validate and reference the original source of truth.

JSON-based SBOMs are displayed in an interactive tree viewer for easier exploration, while XML-based SBOMs are shown as formatted text. The _Original BOM_ tab supports both CycloneDX and SPDX formats, making it easier to review and audit SBOMs without leaving the product.

##  Sonatype Repository Firewall

This release includes the following changes for Sonatype Repository Firewall:

### Automatic Re-Evaluation for Age-Based Policy Constraints

Components quarantined by age-based policy constraints are now automatically re-evaluated and released once they exceed the defined age threshold, reducing manual intervention and improving development workflow efficiency.

## Bug Fixes

| **Issue ID** | **Description** |
| --- | --- |
| NEXUS-49569 | Docker policy violations marked as legacy no longer bypass quarantine enforcement when _Allow violations of this policy to be granted legacy status_ is enabled at the root organization level. |
| NEXUS-47285 | The malware remediation task now skips components with empty or null hashes in NuGet proxy repositories, allowing the evaluation batch to continue running without interruption. (Will require Nexus Repository 3.88.0+ to be fully resolved.) |
| NEXUS-47170 | NuGet registry index JSON assets beyond index.json are now excluded from analysis to prevent unnecessary Component-Unknown entries in repository reports. |
| NEXUS-47131 | Long repository names in the Repository Firewall left-hand navigation now display correctly, and the back button from component details reliably returns users to the appropriate prior context in Repository Firewall. |
| NEXUS-44585 | Users with repository-level access now see only authorized information without encountering 403 errors on the Firewall landing page or Repository Manager screen. |
| CLM-38159 | Reduced query volume and improved component metadata evaluation performance for large component sets when performing policy evaluations for PCCS. |
| CLM-34494 | IQ Server now provides a clearer error message when database connection fails due to incorrect PostgreSQL credentials. |

## Coming Soon

### Upgrade Posture and Rolling Recap Enterprise Reports to be Sunset

Data for the _Upgrade Posture_ and _Rolling Recap_ Enterprise Reporting dashboards will no longer be refreshed after **January 2026**. These dashboards will be sunset and removed from Sonatype IQ on **February 23, 2026**.

Customers are advised to review their usage of these dashboards and plan accordingly. Additional guidance is provided in the [Sonatype IQ Server Feature Status](https://help.sonatype.com/en/sonatype-iq-server-200-release-notes.html) section.
