Sonatype IQ Server 201 Release Notes

Sonatype IQ Server 201 Release Notes

Released March 5, 2026

The IQ 201 release includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.

Improvements Impacting Multiple Solutions

This release includes the following improvements that impact multiple IQ Server-powered solutions:

Improved Instructions for Advanced Search

In this release, we’ve improved the Advanced Search experience in Sonatype IQ by updating the instructional text to remove Lucene-specific assumptions and provide clearer guidance for constructing queries. We also enhanced error messaging to provide more accurate and actionable feedback when an index is not found.

These changes make it easier for users to understand how to build effective searches without requiring familiarity with underlying search technologies, helping teams find the information they need more efficiently.

Sonatype Lifecycle

This release includes the following changes for Sonatype Lifecycle:

New HeroDevs End-of-Life Components Dashboard Under Enterprise Reporting

Sonatype Lifecycle Enterprise Reporting now includes a HeroDevs End-of-Life Components dashboard, which provides centralized visibility into open-source components that have reached end-of-life (EOL) and are eligible for HeroDevs support. This dashboard helps you quickly understand your organization’s exposure by highlighting affected applications, surfacing the most widely used EOL components, and grouping supported components by ecosystem.

With flexible filters such as Application, Stage, Format, Component Name, and Last Scan Date, you can refine results to match your operational needs and focus on the areas of highest risk. Data refreshes monthly and reflects your selected scan scope, enabling you to make informed decisions about pursuing extended support and reducing security risk across your software supply chain.

Review your exposure and contact Sonatype to explore extended support options.

For full details, see our HeroDevs End-of-Life Components help documentation.

Additional Access Point for React2Shell Impact Report

Sonatype Lifecycle now provides access to the React2Shell Impact Report through an Operational Reporting tab for those who do not have access to Enterprise Reporting. This report helps teams quickly assess potential exposure to React2Shell-related risks and identify affected applications or components.

Sonatype Developer

This release does not include any Developer-specific enhancements.

Sonatype SBOM Manager

This release includes the following changes for Sonatype SBOM Manager:

New Search in_Original BOM_Tab

Sonatype SBOM Manager now includes case-insensitive search within its Original BOM tab. The search scans both keys and values across the entire document, highlights matches, and includes navigation controls so you can quickly move between results. Matching sections automatically expand, making it easier to locate relevant information without manually opening nested fields.

Sonatype Repository Firewall

This release includes the following changes for Sonatype Repository Firewall:

Additional Audit Log Entries for Quarantine

Sonatype Repository Firewall now records firewall.quarantine audit log events when a component is newly quarantined and when a user attempts to download a component that is already quarantined. These additional entries provide greater visibility into quarantine activity, helping security and operations teams better monitor policy enforcement and user interactions.

Bug Fixes

Issue ID Description
NEXUS-49974 Streamlined the ZScaler integration to validate credentials through functional testing rather than requiring super admin access for configuration verification and malware URL management.
NEXUS-49650 Clicking a component row in the Auto Release from Quarantine page now navigates to the detailed component information view.
NEXUS-49174 The Firewall Evaluate API now accepts requests for coordinate-based package formats like Conan and Golang without requiring SHA1 hash values, streamlining integration for formats that use package URL matching.
NEXUS-48816 Removed the non-functional "Review Obligations" button from the Legal tab when viewing Firewall Repository components to provide a clearer user experience.
NEXUS-44853 Enhanced automatic synchronization between Firewall and Artifactory to provide accurate quarantine status messages when component metadata becomes out of sync.
NEXUS-43058 Quarantine summaries now display only compliant versions as alternatives, excluding pre-cached components that contain policy violations.
NEXUS-41977 The Repository Managers navigation item now displays an accurate count of repository managers and expands automatically when selected.
NEXUS-37403 Repository Audit now processes valid components successfully even when individual assets with missing pathnames are encountered in the batch.
NEXUS-49708 IQ Server connection verification now properly validates that the configured user has the required permissions before allowing the configuration to be saved.
NEXUS-47170 NuGet registry index JSON assets are now excluded from Firewall analysis by expanding the ignore pattern to filter all NuGet feed JSON metadata, ensuring repository reports focus only on actual package artifacts such as .nupkg files.
CLM-38540 Applications with more than 1000 reports can now be deleted successfully when using S3 storage.
CLM-38452 EPSS scores now appear consistently in vulnerability lookup and API responses, matching the data displayed in application reports.
CLM-38434 Policy violation "First Reported" dates now remain stable when policy conditions are reordered or modified, ensuring accurate tracking for compliance and SLA reporting.
CLM-38370 Improved license validation handling to ensure requests with valid licenses process successfully without intermittent authorization errors.
CLM-35001 Enhanced the source control API to enforce a minimum value of 60 seconds for pull request monitoring intervals, preventing invalid configurations that could impact server stability.