# 2025 Release Notes

This page contains a list of 2025 IQ Server releases, links to each release's release notes, and a brief list of major changes per release.

**Note**

While we strive to fully document new features before releasing them to our Cloud environments, there may be occasional delays. In such instances, we will update this page with links to the relevant help documentation as soon as it becomes available.

## Summary of Major Changes in 2025

The following table lists major changes in 2025 that should be considered when upgrading to a new version.

Features and fixes are added to Sonatype Cloud-based deployments on a **weekly** basis. The same features and fixes are made available to self-hosted deployments on a **monthly** basis.

| Features and Changes | Cloud Release Date | Included in Self-Hosted Version |
| --- | --- | --- |
| Maintenance Release | December 24, 2025 | 200 (Coming February 2026) |
| Maintenance Release | December 17, 2025 | 200 (Coming February 2026) |
| On December 16, 2025, Sonatype made improvements that enhanced our JavaScript analysis capabilities so that we can now detect previously obscured JavaScript dependencies. More details are available in [our Knowledgebase article](https://support.sonatype.com/hc/en-us/articles/47423166321555).  If you upgraded to 199 before December 16, you do not need to take any additional upgrade or installation steps. These improvements are available immediately. | December 16, 2025 | [199](https://help.sonatype.com/en/sonatype-iq-server-199-release-notes.html "Sonatype IQ Server 199 Release Notes") (December 12, 2025) |
| - **New React2Shell Impact Report** – To help organizations respond quickly to the [critical React2Shell vulnerability](https://help.sonatype.com/en/find-and-fix-react2shell.html "Find and Fix React2Shell") (CVE-2025-55182, CVE-2025-66478), Sonatype has released a _React2Shell Impact Report_ that helps you assess which of your components and applications are impacted based on implicated files.  
  - IQ now defaults the admin HTTP connector (port 8071) to bind only to localhost (127.0.0.1).  
  - Sonatype IQ user tokens can now be configured to expire after a defined number of days.  
  - Sonatype Repository Firewall now supports policy enforcement based on Exploit Prediction Scoring System (EPSS) scores and Known Exploited Vulnerabilities (KEV) catalog data.  
  - Bug Fixes:  
  - **NEXUS-49342** – Firewall now honors policies that include EPSS and KEV policy constraints.  
  - **CLM-37987** – Upgraded the `semver4j` library to version 5.3.0 to prevent `NumberFormatException` errors during policy evaluations when encountering complex pre-release version strings.  
  - **CLM-37982** – Updated the SBOM Manager API to check for file existence before attempting to delete temporary binary SBOM files, preventing 500 errors when deleting non-existent BINARY-type SBOMs. | December 11, 2025 | [199](https://help.sonatype.com/en/sonatype-iq-server-199-release-notes.html "Sonatype IQ Server 199 Release Notes") (December 12, 2025) |
| - **In case you missed it**: Sonatype introduced a _React2Shell Impact_ Filter in [the _Security Risk Breakdown_ Dashboard](https://help.sonatype.com/en/security-risk-breakdown.html "Security Risk Breakdown"). This filter is already available in SaaS and self-hosted deployments that leverage Enterprise Reporting.  
  - Bug Fixes:  
  - **NEXUS-49289** – Repository manager–level policy waivers now appear in the policy waiver dashboard alongside repository-level waivers when filtering by repositories. | December 10, 2025 | [199](https://help.sonatype.com/en/sonatype-iq-server-199-release-notes.html "Sonatype IQ Server 199 Release Notes") (December 12, 2025) |
| - Sonatype Repository Firewall now supports policies based on EPSS or KEV scores.  
  - User token expiration configuration.  
  - Bug Fixes  
  - **NEXUS-43056** – Policy deletion behavior has been updated to prevent automatic unquarantining of components and loss of waivers.  
  - **CLM-37582** – Support zips now include the public data source configuration setting.  
  - **CLM-37109** – Pull request comments and annotations for Bitbucket are now truncated to stay within the 32 KB limit, preventing failures when posting scan results that exceed the allowable size.  
  - **CLM-26943** – The OpenAPI specification at `/api/v2/endpoints/public` now includes `securitySchemes` and global security definitions.  
  - **CLM-19259** – Administrative API endpoints on port 8071 are now bound to localhost by default. | December 3, 2025 | [199](https://help.sonatype.com/en/sonatype-iq-server-199-release-notes.html "Sonatype IQ Server 199 Release Notes") (December 12, 2025) |
| - Added support to automatically close pull requests in BitBucket when they have not been merged or closed within a configured number of days.  
  - Firewall release integrity support for NuGet.  
  - Bug Fixes  
  - **NEXUS-49579** – Firewall now automatically distributes URLs across multiple Zscaler categories when the 25,000 URL per-category limit is reached. When new categories are created, you will need to manually add them to your SSL inspection configuration to ensure SSL inspection policies continue applying correctly. | November 26, 2025 | [198](https://help.sonatype.com/en/sonatype-iq-server-198-release-notes.html "Sonatype IQ Server 198 Release Notes") (December 2, 2025) |
| - New role management API allows administrators to create, view, update, and delete custom roles, including retrieving a role template.  
  - (Self-hosted only; already supported in Sonatype Cloud) OIDC/OAuth2 authentication support for self-hosted IQ Server.  
  - Bug Fixes  
  - **CLM-37572** – Improved performance of the `/api/v2/reports/metrics` API by optimizing database queries. | November 19, 2025 | [198](https://help.sonatype.com/en/sonatype-iq-server-198-release-notes.html "Sonatype IQ Server 198 Release Notes") (December 2, 2025) |
| - New role membership mapping API enables administrators to assign, unassign, and retrieve role memberships for users and groups across global and scoped contexts, with support for both bulk replacement and individual member operations.  
  - Bug Fixes  
  - **CLM-37170** – Updated the default Fluentd image repository to `bitnamilegacy/fluentd` to align with Bitnami’s deprecation of the original image source.  
  - **CLM-35694** – Restored generation of Bitbucket Code Insight Reports for new pull request commits without dependency changes.  
  - **CLM-35285** – Updated the _Target Branch_display in manual pull request creation to always show the default branch.  
  - **CLM-33974** – Added optional validation to the role membership API to check if a user or group exists before assigning a role. | November 12, 2025 | [198](https://help.sonatype.com/en/sonatype-iq-server-198-release-notes.html "Sonatype IQ Server 198 Release Notes") (December 2, 2025) |
| Maintenance Release | November 5, 2025 | [198](https://help.sonatype.com/en/sonatype-iq-server-198-release-notes.html "Sonatype IQ Server 198 Release Notes") (December 2, 2025) |
| - You can now [create bulk waivers](https://help.sonatype.com/en/bulk-waivers.html "Bulk Waivers") (simultaneous waivers for multiple policy violations) through the user interface.  
  - Sonatype Lifecycle now supports GPG-based commit signing for both native Git and jGit, helping teams enforce commit integrity as part of their policy evaluation workflows.  
  - PDF reports now include a _Waived_ column in the policy violations table to provide insight into waiver status.  
  - Added a `sonatype:original_purl` property in exported [CycloneDX SBOMs](https://help.sonatype.com/en/cyclonedx.html#sonatype-properties-in-sboms "Sonatype properties in SBOMs") to preserve original package URLs from ingested SBOMs and improve cross-tool component tracking.  
  - Bug fixes:  
  - **CLM-37095** – SBOM Manager now uses both component identifiers and hashes to accurately deduplicate components during SBOM import, improving performance for SBOMs containing large embedded license data.  
  - **CLM-37027** – SBOM ingestion in both Sonatype Lifecycle and SBOM Manager now correctly imports all components when multiple entries share the same coordinates but have different SHA1 hashes.  
  - **CLM-35775** – Support zip generation now enforces a cluster-wide lock to prevent concurrent requests from overlapping, ensuring reliable archive creation and avoiding file access conflicts.  
  - **CLM-35279** – IQ Server no longer requires the `Server` response header to validate Nexus Repository connections in InnerSource Repository configuration, allowing support for environments that restrict HTTP header exposure through reverse proxies.  
  - **NEXUS-47655** – (Requires IQ 197 and Nexus Repository 3.86.0) Firewall for Docker now uses the HTTP configuration defined in Nexus Repository (i.e., proxy settings, authentication, timeouts, and SSL certificates) when downloading image content for scanning, improving compatibility with restricted or customized network environments. | October 29, 2025 | [197](https://help.sonatype.com/en/sonatype-iq-server-197-release-notes.html "Sonatype IQ Server 197 Release Notes") (November 5, 2025) |
| - A new `integrationsSupportedVersionCount` system configuration property allows organizations to enforce a minimum version range for IQ Server Integrations that have scanning functionality. This ensures that scans only proceed when using one of the latest approved versions and ensures consistent access to key features (e.g., AI model identification).  
  - Waiver configurations now reset automatically when selection criteria are modified, ensuring accurate alignment with the updated scope.  
  - Bug Fixes:  
  - **CLM-35775** – Support zip generation now enforces a cluster-wide lock to prevent concurrent requests, avoiding collisions and file access errors during zip creation. | October 22, 2025 | [197](https://help.sonatype.com/en/sonatype-iq-server-197-release-notes.html "Sonatype IQ Server 197 Release Notes") (November 5, 2025) |
| - Bug Fixes  
  - **NEXUS-49025** – Firewall report links using the legacy /malware-defense path now redirect correctly, with full backward compatibility implemented to ensure both /malware-defense and /firewall URLs load without errors.  
  - **NEXUS-48987** – InnerSource repository connections to Sonatype Nexus Repository cloud tenants now succeed without requiring the Server response header, enabling compatibility with Nexus Repository Cloud in IQ Server.  
  - **NEXUS-45459** – The _Vulnerability Lookup_ page is now available again for customers with a Repository Firewall-only license, and the login page link correctly directs to it. | October 15, 2025 | [197](https://help.sonatype.com/en/sonatype-iq-server-197-release-notes.html "Sonatype IQ Server 197 Release Notes") (November 5, 2025) |
| - Bug Fixes  
  - **CLM-35845** – The IQ Operator Helm chart now supports specifying CPU limits for pods, enabling deployment in environments with enforced resource quotas. | October 8, 2025 | [196](https://help.sonatype.com/en/sonatype-iq-server-196-release-notes.html "Sonatype IQ Server 196 Release Notes") (October 8, 2025) |
| - Support for Java 25 bytecode fingerprinting.  
  - Implemented a user activity overview feature that, when enabled, provides system administrators visibility into login and usage patterns to support audit and compliance needs. This feature is disabled by default.  
  - Bug Fixes  
  - **NEXUS-48563** – Policy action overrides for the Proxy stage now correctly apply at the repository level for Firewall for Docker, ensuring that repository-specific configurations are honored during image scans.  
  - **CLM-36272** – Loading the _Build Stage Risk Monitoring Summary_ in the Developer UI now executes significantly fewer SQL queries on PostgreSQL databases, reducing page load times.  
  - **CLM-35813** – Users with appropriate permissions can now successfully delete applications from Sonatype Lifecycle as expected and without a 500 error. | October 1, 2025 | [196](https://help.sonatype.com/en/sonatype-iq-server-196-release-notes.html "Sonatype IQ Server 196 Release Notes") (October 8, 2025) |
| - Various design enhancements for dark mode.  
  - _System_ is now the default display theme until a user selects a specific option.  
  - Bug Fixes:  
  - **NEXUS-48520** – Reduced metadata evaluation latency for PyPI components under Policy Compliant Component Selection.  
  - **CLM-36031** – Improved memory management during asynchronous license processing.  
  - **CLM-35667** – Optimized authorization filtering logic to improve performance of the _Orgs and Policies_ page and related APIs. | September 25, 2025 | [196](https://help.sonatype.com/en/sonatype-iq-server-196-release-notes.html "Sonatype IQ Server 196 Release Notes") (October 8, 2025) |
| - New Bulk Waivers API | September 18, 2025 | [196](https://help.sonatype.com/en/sonatype-iq-server-196-release-notes.html "Sonatype IQ Server 196 Release Notes") (October 8, 2025) |
| - [New Management options for Automated Remediation](https://help.sonatype.com/en/iq-server-configuration.html "IQ Server Configuration") with GoldenPRsTM for GitLab using Sonatype for SCM  
  - New [_Golden Fixes_ dashboard](https://help.sonatype.com/en/golden-fixes-dashboard.html "Golden Fixes Dashboard")  
  - New Bulk Vulnerability Details API  
  - Bug Fixes:  
  - **CLM-36122** – The PR commenting feature works as expected.  
  - **CLM-35964** – Webhook signatures are now generated using explicit UTF-8 encoding, ensuring consistent and verifiable HMAC SHA1 values for all payloads, including those with special or non-ASCII characters.  
  - **CLM-35271** – Made change to ensure exported SQL from the `export-embedded-db` task is always valid to prevent import errors when migrating from H2 to PostgreSQL. | September 10, 2025 | [196](https://help.sonatype.com/en/sonatype-iq-server-196-release-notes.html "Sonatype IQ Server 196 Release Notes") (October 8, 2025) |
| - New _Display Theme_ option under _Manage User Account_ – Users now have the ability to use Lifecycle, SBOM Manager, Developer, and Firewall in light or dark mode.  
  - New Management options for _Automated Remediation with GoldenPRsTM_ for GitHub using Sonatype for SCM. See the [Sonatype for SCM configuration help documentation](https://help.sonatype.com/en/iq-server-configuration.html#configure-iq-server-with-your-scm-system "Configure IQ Server With Your SCM System").  
  - Bug Fixes  
  - **CLM-35272** – Proprietary component matching no longer applies to the scanned file’s name or path during third-party analysis. | September 3, 2025 | [195](https://help.sonatype.com/en/sonatype-iq-server-195-release-notes.html "Sonatype IQ Server 195 Release Notes") (September 9, 2025) |
| - New side and top navigation design across Lifecycle, Developer, SBOM Manager, and Firewall.  
  - IQ Server and the IQ CLI Scanner now support Java 23 and 24 bytecode fingerprinting.  
  - Redesigned _Enterprise Reporting_ landing page to group reports that go together under a single card with a drop-down menu, allowing you to select the specific report view you need.  
  - Bug Fixes  
  - **CLM-35753** – The `/api/v2/securityOverrides` REST API now handles cases where component identifiers are null. | August 20, 2025 | [195](https://help.sonatype.com/en/sonatype-iq-server-195-release-notes.html "Sonatype IQ Server 195 Release Notes") (September 9, 2025) |
| - **New Insight**: [Legal Risk Trends](https://help.sonatype.com/en/legal-risk-trends.html "Legal Risk Trends") dashboard tracks policy compliance and remediation performance.  
  - Sonatype’s data catalog now includes Exploit Prediction Scoring System (EPSS) data.  
  - You can now create policy constraints using a new _EPSS Score (percentage)_ condition.  
  - Firewall for Containers (Requires Nexus Repository 3.83.0). | August 6, 2025 | [194](https://help.sonatype.com/en/sonatype-iq-server-194-release-notes.html "Sonatype IQ Server 194 Release Notes") (August 12, 2025) |
| - Maintenance release; no notable changes.  
  - Bug Fixes  
  - **CLM-26944** – The OpenAPI spec at `/api/v2/endpoints/public` now correctly shows the response format for the `GET /api/v2/applications` endpoint. It also properly lists the `publicId` and `includeCategories` query parameters. | July 30, 2025 | [194](https://help.sonatype.com/en/sonatype-iq-server-194-release-notes.html "Sonatype IQ Server 194 Release Notes") (August 12, 2025) |
| The Dashboard landing page now displays an informative note if the Dashboard feature is disabled by an administrator. | July 16, 2025 | [194](https://help.sonatype.com/en/sonatype-iq-server-194-release-notes.html "Sonatype IQ Server 194 Release Notes") (August 12, 2025) |
| - Maintenance release; no notable changes.  
  - Bug Fixes:  
  - **CLM-35315** – When scanning a binary first without `-ra` and then again with `-ra`, the second scan now correctly includes reachability data in the report. | July 9, 2025 | [194](https://help.sonatype.com/en/sonatype-iq-server-194-release-notes.html "Sonatype IQ Server 194 Release Notes") (August 12, 2025) |
| - Common Platform Enumeration (CPE)–based vulnerability matching for C/C++ components.  
  - Sonatype SBOM Manager now uses Common Platform Enumeration (CPE)–based matching to detect vulnerabilities across a broader catalog of technologies, including third-party applications, operating systems, firmware, and embedded hardware.  
  - Bug Fixes  
  - **CLM-30371** – The licensing screen no longer displays duplicate entries for Sonatype Repository Firewall or lists “Lifecycle Cloud” for self-hosted licenses.  
  - **CLM-30594** – Added more detailed logging to data retention processes to improve visibility into report purging behavior.  
  - **CLM-31557** – When IQ Server is started, stopped, and started again in quick succession, the system now correctly detects and prevents multiple IQ instances from running at the same time.  
  - **CLM-34705** – Added additional debug logging to the Auto Pull Request process to capture detailed reasons when remediations cannot be applied. | July 2, 2025 | [193](https://help.sonatype.com/en/sonatype-iq-server-193-release-notes.html "Sonatype IQ Server 193 Release Notes") (July 9, 2025) |
| - Sonatype's vulnerability catalog now includes Known Exploited Vulnerabilities (KEV) data to help you identify vulnerabilities under known exploitation. [KEV status appears in the UI](https://help.sonatype.com/en/component-details-page.html#vulnerability-details-162365 "Vulnerability Details") and [Vulnerability Details REST API](https://help.sonatype.com/en/vulnerability-details-rest-api.html#vulnerability-details-with-kev-data "Vulnerability Details with KEV data"); you can also create policy constraints around KEV status.  
  - Sonatype’s vulnerability catalog now skips Java similar matching on nested components when the outer artifact is an exact match. This improves scan performance while preserving accuracy. | June 25, 2025 | [193](https://help.sonatype.com/en/sonatype-iq-server-193-release-notes.html "Sonatype IQ Server 193 Release Notes") (July 9, 2025) |
| - New _Security Vulnerability Detection Type_ policy constraint to allow for more granular insight into how vulnerabilities are discovered.  
  - The latest IQ OpenShift operator image (192) is now available in the [Red Hat catalog](https://catalog.redhat.com/software/container-stacks/detail/61d7053e2c1e1379c8e0022f#overview).  
  - Bug Fixes  
  - CLM-24916 - The _Components reviewed_ value on the main ALP dashboard now accurately reflects the _Review status_ listed on the _Application Obligations_ page.  
  - NEXUS-47507 - Accessing the _Orgs and Policies_ and _Repository Manager_ sections within the Sonatype Lifecycle UI now loads significantly faster. | June 19, 2025 | [193](https://help.sonatype.com/en/sonatype-iq-server-193-release-notes.html "Sonatype IQ Server 193 Release Notes") (July 9, 2025) |
| - The [Automatic Role Assignment feature](https://help.sonatype.com/en/source-control-rest-api.html#automatic-role-assignment--github- "Automatic Role Assignment (GitHub)") now supports matching for both SAML (for self-hosted deployments) or OAuth2 (for Multi-Tenant IQ (MTIQ) deployments). | June 10, 2025 | [192](https://help.sonatype.com/en/sonatype-iq-server-192-release-notes.html "Sonatype IQ Server 192 Release Notes") (June 11, 2025) |
| - New _AI Content_ policy condition to [identify objectionable AI models](https://help.sonatype.com/en/threats-in-ai-ml-models.html#objectionable-ai-detection-343504 "Objectionable AI Detection") from Hugging Face  
  - The _Security_ tab on the _Component Details page_ now includes _Identification Source_ and _Confidence_ columns for identified vulnerabilities.  
  - The component details drawer now displays _Vulnerability Detection Type_, _Identification Source_, and _Confidence_, and the pill at the top of the drawer displays the security research type (e.g., fast track, deep dive) associated with the vulnerability.  
  - Enhanced the [Component Claim REST API](https://help.sonatype.com/en/component-claim-rest-api.html "Component Claim REST API") by adding two new properties: `claimerId` and `claimerName`.  
  - Bug Fixes  
  - **CLM-34990** - Sonatype Lifecycle now avoids generating filenames over 1000 characters during SBOM export, which allows for successful SBOM scanning and policy evaluation. | June 5, 2025 | [192](https://help.sonatype.com/en/sonatype-iq-server-192-release-notes.html "Sonatype IQ Server 192 Release Notes") (June 11, 2025) |
| - New workflow for requesting and approving/rejecting waivers, with updated dashboard and views to surface waiver status across personas  
  - Support for [SPDX 2.2 SBOM ingestion](https://help.sonatype.com/en/spdx-application-analysis.html "SPDX Application Analysis") alongside existing SPDX 2.3 support  
  - [SBOM Manager Legal View](https://help.sonatype.com/en/sbom-legal.html "SBOM Manager Legal View") now provides full license management capabilities with ALP integration (requires ALP, Lifecycle, and SBOM Manager licenses)  
  - Waiver status visibility and expiry indicators in [Priorities view](https://help.sonatype.com/en/view-waivers-from-the-priorities-view.html "View Waivers from the Priorities View")  
  - Bug Fixes  
  - **CLM-34858** - The Dashboard now loads as expected when the application count exceeds 65,000 in Sonatype Lifecycle using PostgreSQL | May 28, 2025 | [192](https://help.sonatype.com/en/sonatype-iq-server-192-release-notes.html "Sonatype IQ Server 192 Release Notes") (June 11, 2025) |
| - _[Waivers Explorer](https://help.sonatype.com/en/waivers-explorer.html "Waivers Explorer")_ dashboard for IQ releases 189+ (Lifecycle)  
  - [Manually create pull requests](https://help.sonatype.com/en/create-prs-from-priorities-view.html "Create PRs from Priorities View") from the _Priorities_ page (Lifecycle)  
  - [Integrate Repository Firewall with Zscaler](https://help.sonatype.com/en/zscaler.html "Integrate Firewall with Zscaler") (Firewall)  
  - Repository type (hosted, proxy) and format included in title and breadcrumbs for a given repository's summary page (Firewall) | May 21, 2025 | [192](https://help.sonatype.com/en/sonatype-iq-server-192-release-notes.html "Sonatype IQ Server 192 Release Notes") (June 11, 2025) |
| - Replaced _Security Risk Analysis_ dashboard with _[Security Risk Trends](https://help.sonatype.com/en/security-risk-trends.html "Security Risk Trends")_ and _[Security Risk Breakdown](https://help.sonatype.com/en/security-risk-breakdown.html "Security Risk Breakdown")_ dashboards | May 14, 2025 | [192](https://help.sonatype.com/en/sonatype-iq-server-192-release-notes.html "Sonatype IQ Server 192 Release Notes") (June 11, 2025) |
| - Hugging Face Support for Repository Firewall (Requires Nexus Repository 3.80.0+) | May 7, 2025 | [191](https://help.sonatype.com/en/sonatype-iq-server-191-release-notes.html "Sonatype IQ Server 191 Release Notes") (May 6, 2025) |
| - Automated waivers for non-reachable methods (Developer)  
  - Support for multiple auto-waivers (Developer)  
  - Doc notification that Cocoapods approaching end-of-life | April 30, 2025 | [191](https://help.sonatype.com/en/sonatype-iq-server-191-release-notes.html "Sonatype IQ Server 191 Release Notes") (May 6, 2025) |
| - Data Insights Enhancement: Enhanced Security Risk Analysis Dashboard | April 23, 2025 | [191](https://help.sonatype.com/en/sonatype-iq-server-191-release-notes.html "Sonatype IQ Server 191 Release Notes") (May 6, 2025) |
| - Added support for Dart and Flutter analysis  
  - Data Insights is now Enterprise Reporting | April 16, 2025 | [191](https://help.sonatype.com/en/sonatype-iq-server-191-release-notes.html "Sonatype IQ Server 191 Release Notes") (May 6, 2025) |
| - Change to License Overrides REST API Naming (`licenseOverride` changes to `licenseOverrides`) | April 9, 2025 | [191](https://help.sonatype.com/en/sonatype-iq-server-191-release-notes.html "Sonatype IQ Server 191 Release Notes") (May 6, 2025) |
| - Release 190 fixes multiple bugs impacting the 189 release.  
  - Data Insights is now Enterprise Reporting with a newly redesigned landing page. | April 8, 2025 (self-hosted release date) | [190](https://help.sonatype.com/en/sonatype-iq-server-190-release-notes.html "Sonatype IQ Server 190 Release Notes") |
| - Improved browser tab identification across solutions  
  - Policy conditions for derivative AI models  
  - Support for scanning LFS files for AI/ML  
  - Coordinate constraint supports all formats; this release adds the following formats:  
  - Conda  
  - Cran  
  - Gem  
  - Golang  
  - NuGet  
  - Pub  
  - RPM  
  - SWID  
  - Swift  
  - Re-evaluation now uses latest HDS data  
  - New License Override REST API  
  - Display CLI/Plugin version in latest evaluations  
  - When merging multiple SBOMs, SBOM manager now merges associated licenses and vulnerabilities for duplicate components  
  - New Malware Defense Evaluation REST API  
  - New Firewall REST API to protect against Namespace Confusion attacks.  
  - Swagger now uses malware-defense instead of firewall; this does not impact functionality and 'firewall' will still work  
  - UI URL for Firewall uses malware-defense; 'firewall' will not work in the UI  
  - New Firewall for Artifactory Plugin supporting latest Artifactory versions  
  - Firewall Classic sunsetting April 9 | April 1, 2025 (self-hosted release date) | [189](https://help.sonatype.com/en/sonatype-iq-server-189-release-notes.html "Sonatype IQ Server 189 Release Notes") |
| - API documentation, powered by Swagger and OpenAPI, is now available in the user interface for all IQ-powered solutions (i.e., Lifecycle, Developer, SBOM Manager, Firewall, and Advanced Legal Pack).  
  - Update existing waivers with the Policy Waivers REST API.  
  - Policy Violations REST API now returns waived, legacy, and auto-waived violations.  
  - Report REST API policy violations now returns `openTime`.  
  - Success Metrics Enterprise Dashboard displays remediation status chart.  
  - Enhanced Security Risk Analysis Dashboard.  
  **Breaking Changes with JFrog Artifactory 7.104**  
  JFrog Artifactory 7.104 is the latest and is incompatible with the Repository Firewall plugin. JFrog Artifactory has introduced a newer version of `groovy-core` that is not backward compatible with the version the Repository Firewall plugin is compiled against.  
  We recommend not upgrading to Artifactory 7.104 as doing so causes an interruption with the Repository Firewall service and exposes you to malware entering the environment. | March 4, 2025 (self-hosted release date) | [188](https://help.sonatype.com/en/sonatype-iq-server-188-release-notes.html "Sonatype IQ Server 188 Release Notes") |
| **Upgrade Impact**  
  After upgrading a Lifecycle instance using a PostgreSQL database from IQ 182 or earlier to IQ 183 or later, you may temporarily see an internal error when accessing the violations dashboard and find a NullPointerException (NPE) in the logs. This is due to an internal job running in the background; the dashboard will load as expected after the job completes. We will improve this experience in a future release.  
  - Hugging Face declared and observed license detection  
  - _View Latest Evaluations_ option in Lifecycle  
  - Improvements to Security Risk Analysis dashboard  
  - Specify SBOM application version during import  
  - Easily view SBOM release status  
  - Support for Python pipfile.lock  
  - Branch name displays in _Priorities_ view  
  - Sonatype Developer: Auto-waivers for policy violations on components with no path forward  
  - Options like _Vulnerability Lookup_ and _Advanced Search_ no longer display in the standalone Firewall user interface available via [Solution Switcher](https://help.sonatype.com/en/sonatype-solution-switcher.html "Sonatype Solution Switcher"). You can find these items by switching to the _Lifecycle_ option via [Solution Switcher](https://help.sonatype.com/en/sonatype-solution-switcher.html "Sonatype Solution Switcher"). | February 4, 2025 (self-hosted release date) | [187](https://help.sonatype.com/en/sonatype-iq-server-187-release-notes.html "Sonatype IQ Server 187 Release Notes") |
| **Upgrade Impact**  
  After upgrading a Lifecycle instance using a PostgreSQL database from IQ 182 or earlier to IQ 183 or later, you may temporarily see an internal error when accessing the violations dashboard and find a NullPointerException (NPE) in the logs. This is due to an internal job running in the background; the dashboard will load as expected after the job completes. We will improve this experience in a future release.  
  - Lifecycle Changes  
   - Lifecycle dashboard performance improvements (includes UI changes)  
   - Total count no longer displays on each tab  
   - Removed sorting by component name  
   - Applications filter displays up to 500 apps with type-ahead filter to refine list  
   - Pagination change to only include back/forward buttons within page numbers to select  
  - Easier onboarding with automatic role assignment  
  - Waiver reasons in API responses for the Applicable Waivers, Similar Waivers, Component Waivers, and Stale Waivers REST APIs as well as the UI  
  - Dependency tree visualization for Cargo  
  - Improved matching process for SBOM scans (impacts Lifecycle and SBOM Manager)  
  - New _AI Model Usage_ Data Insight  
- Sonatype Developer Changes  
   - All integrations now listed on homepage tabs  
   - Avoid recommending milestone versions  
- SBOM Manager Changes  
   - Sort components by name on BOM page  
   - Leverage Sonatype Container Security for SBOM Manager container scans  
   - Policy violations visible in UI  
   - Skip validation support for CycloneDX and SPDX  
   - Search by license  
   - Original binary filename visible in BOM page  
   - Improved matching process for SBOM scans (impacts Lifecycle and SBOM Manager)  
- Repository Firewall Changes  
   - Access Firewall via Solution Switcher  
- Notable Integrations Changes  
   - IQ CLI is now a standalone solution (i.e., IQ CLI 2.0), which means it is a separate download and is no longer included in the bundled IQ download  
   - IQ CLI 2.0 supports Python pipfile.lock  
   - IQ CLI 2.0 dependency tree visualization for Cargo  
   - This release fixes an issue in release 185 that could cause deadlocking to occur under heavy usage causing the application to become unresponsive. | January 8, 2025 (self-hosted release date) | [186](https://help.sonatype.com/en/sonatype-iq-server-186-release-notes.html "Sonatype IQ Server 186 Release Notes") |
