Sonatype IQ Server 203 - 203.3 Release Notes

Sonatype IQ Server 203 - 203.3 Release Notes

The IQ 203– 203.2 releases includes multiple changes to our IQ-powered solutions. View the details in each solution’s section below.

New Mythos Readiness Enterprise Report
On May 29, 2026, Sonatype introduced a new Mythos Readiness Enterprise Report to help organizations prepare for and respond to privately disclosed vulnerabilities before they receive a CVE identifier. The report provides a complete inventory of components across your applications, along with visibility into available newer versions and designated golden versions. This information helps security and development teams quickly identify potentially affected applications and prioritize remediation efforts.

The report includes filtering capabilities for date range, application, stage, component name, and component version, making it easier to focus on relevant data. For production impact analysis, Sonatype recommends filtering on the Release and Operate stages. Customers managing large application portfolios can export report data and combine it with private vulnerability disclosure information to perform broader impact assessments.

Availability

What's New in Sonatype IQ Server Release 203.4?

Released June 9, 2026

Bug Fixes

IQ Server 203.4 introduces the following additional bug fix:

Issue ID Description
EI-1273 Memory usage remains bounded during audit and remediation collection, preventing excessive memory growth and OutOfMemoryError conditions under large workloads.

What's New in Sonatype IQ Server Release 203.3?

Released June 6, 2026

Bug Fixes

IQ Server 203.3 introduces the following additional bug fix:

Issue ID Description
CLM-40144 Telemetry processing now limits the number of queued telemetry events, preventing unbounded queue growth that could lead to excessive memory consumption and improve Sonatype Lifecycle stability under sustained telemetry load.

What's New in Sonatype IQ Server Release 203.2

Released May 25, 2026

Bug Fixes

IQ Server 203.2 introduces the following additional bug fix:

Issue ID Description
NEXUS-52385 The IQ Server HDS connection pool size is now configurable to support concurrent npm metadata requests in HA deployments and reduce fallback to stale cache when the default connection limit is reached.

What's New in Sonatype IQ Server Release 203.1

Released May 14, 2026

Sonatype SBOM Manager

Release 203.1 includes the following additional enhancement to SBOM Manager:

Legal Visibility and Advanced Search Enhancements in SBOM Manager

Sonatype SBOM Manager now includes a new Legal tab in component details, providing Effective, Declared, and Observed license views aligned with Sonatype Lifecycle and Sonatype Repository Firewall. Customers with Advanced Legal Pack can also review obligations and manage license overrides directly from SBOM Manager, giving legal, security, and governance teams centralized visibility into license compliance and policy-related risks across SBOMs.

Advanced Search also now supports filtering components by legal and policy violation data, making it easier to identify and prioritize compliance risks across applications and SBOMs. Teams can now search for components by effective license, license threat group, license threat level, and policy violation details such as policy name, threat category, threat level, waiver status, and constraint name, helping stakeholders quickly locate components associated with specific legal policies, AI-related policy violations, and other governance requirements.

What's New in Sonatype IQ Server Release 203?

Released May 5, 2026

Improvements Impacting Multiple Solutions

This release includes the following improvements that impact multiple IQ Server-powered solutions:

Optional External Log Aggregation for IQ Server Helm Deployments

We’ve revised the Sonatype IQ Helm chart to make log aggregation optional, moving to a more flexible, log-aggregator-agnostic model. This update also removes the dependency on the deprecated Fluentd project as a bundled subchart.

With this update, you can integrate your preferred logging solution, such as Fluent Bit, Datadog, CloudWatch, or Loki, using standard Helm configuration patterns. The chart remains flexible to support sidecars and external integrations, making it easier to align logging with your existing infrastructure and operational requirements.

Sonatype Lifecycle

This release includes the following changes for Sonatype Lifecycle:

Enhanced filtering and cross-filtering for AI/ML Dashboard reporting

The AI/ML Dashboard in Enterprise Reporting now includes expanded filtering capabilities to help teams analyze AI component usage with greater precision across their organizations. You can now filter dashboard results by date range, organization, sub-organization, application, AI type, subtype, first scan date, and stage. The dashboard also now supports full cross-filtering behavior, ensuring that selections made in any visualization or table automatically update all related charts and data views for a more consistent and intuitive analysis experience. Additionally, the table listing all AI components in your applications now displays organization and sub-organization information, making it easier to identify ownership and reporting context across applications.

.NET Reachability Analysis for NuGet Components

Sonatype Lifecycle now supports reachability analysis for .NET applications and NuGet components. Teams can use reachability analysis to determine whether vulnerable methods in .NET dependencies are reachable from application code, helping prioritize remediation efforts based on actual risk.

.NET reachability analysis is available through Sonatype IQ CLI and the Sonatype Platform Plugin for Jenkins with support in other integrations coming shortly. Reachability results are automatically processed by Sonatype Lifecycle and can be used alongside existing reachability capabilities for Java and JavaScript applications. For full details, see the IQ CLI help documentation.

Improved Performance Across Key Lifecycle Workflows

Sonatype Lifecycle now delivers significantly improved performance for several high-traffic workflows, including when opening application selector drop-down menus, accessing the Priorities page, and loading dashboards. These enhancements reduce response times in real-world scenarios where large datasets and complex permissions previously introduced latency, resulting in a faster and more responsive user experience. By streamlining how data is retrieved and processed, these improvements also increase overall efficiency and scalability, especially in larger environments.

Sonatype Developer

This release includes the following changes for Sonatype Developer:

Golden Version-Only Automated Pull Requests

Sonatype Lifecycle now creates automated remediation pull requests only for Golden Versions by default. These versions are non-breaking and validated across dependencies, helping reduce the risk of introducing new issues.

As Golden Versions are currently only available for the Maven ecosystem, this means that automated pull requests are no longer generated for non-Maven components by default. InnerSource components remain unaffected and continue to receive automated updates.

You can re-enable automatic pull requests for non-Golden versions using the Source Control API.

Sonatype SBOM Manager

This release includes the following changes for Sonatype SBOM Manager:

Enhanced Control for Continuous SBOM Monitoring

For Sonatype SBOM Manager, continuous monitoring now gives you more control over how SBOM versions are processed. You can now prioritize evaluation so that the most recent SBOM versions are analyzed first, ensuring the most up-to-date risk insights are visible within a 24-hour window. This prioritization also improves overall performance, helping you surface meaningful results faster.

SBOM Manager uses a configurable evaluation queue that lets you control how many versions are processed and how workloads are distributed across instances. For full details, see the SBOM Continuous Monitoring help documentation.

Sonatype Repository Firewall

This release includes the following changes for Sonatype Repository Firewall:

Webhook Support for Repository Firewall Events

Sonatype Repository Firewall now supports webhooks, providing real-time notifications when components are blocked or quarantined due to policy violations. This allows you to integrate Firewall events with external systems for faster incident response, alerting, and automation.

Webhook payloads include key details such as policy violations, threat levels, and component identifiers, helping you quickly understand and act on security events. Notifications also distinguish between new quarantines and repeated access attempts, giving you clear and actionable insight into Firewall activity.

For full details, see the Firewall Webhooks help documentation.

Bulk Waivers for Faster Quarantine Management

Sonatype Repository Firewall now supports Bulk Waivers, allowing you to waive multiple policy violations at one time while applying consistent scope, expiration, and context. This reduces manual effort and helps prevent inconsistencies when managing quarantined components across repositories.

Bulk Waivers are available directly from Repository Results or Component Details, making it easier to take action where quarantine status is visible. Built-in safeguards for unknown or unclaimed components help maintain control, while a complete audit trail ensures traceability for all actions.

For full details, see the Firewall Bulk Waivers and Bulk Waivers API help documentation.

Bug Fixes

Issue ID Description
CLM-39913 Policy evaluations no longer deadlock when database connection pools are exhausted, improving reliability under high-load conditions with concurrent ClusterLock and transaction operations.
CLM-39405 Navigating to user and role detail pages works correctly on Repository Firewall-only licensed instances, with clicks from the Configure Users and Configure Roles lists opening the expected detail views instead of redirecting to the Firewall dashboard.
CLM-39199 SAML group attribute values are now correctly passed through to IQ Server when the configured groups attribute name matches a SAML role attribute, regardless of whether RoleAttributeNames are specified in the deployment configuration.
CLM-39124 Bitbucket Cloud integration now discovers repositories through workspace-scoped APIs, maintaining full compatibility with source control operations following Bitbucket's removal of cross-workspace endpoints.
CLM-39030 CycloneDX SBOM import and export operations across all supported versions (1.1–1.6 XML and 1.2–1.6 JSON) now produce valid, policy-compliant SBOMs following the upgrade to cyclonedx-core-java 12.1.0.
CLM-38947 Reachability markers from manual CLI scans are now preserved when Continuous Monitoring re-evaluates an application, keeping auto-waivers with "Not Reachable" scope active across CM cycles.
CLM-38934 Vulnerability Lookup searches for CVE identifiers now return KEV and EPSS data regardless of the letter casing used.
CLM-38699 Policies combining a DependencyType condition with other conditions now correctly evaluate and trigger violations for Python packages scanned via requirements.txt.
CLM-38690 License data supplied in CycloneDX SBOMs is now retained across Re-Evaluate operations, keeping Effective, Declared, and Observed license fields accurate on subsequent evaluations.
CLM-38674 AI Content policy violation details are now included in the raw report API response (/api/v2/applications/{applicationPublicId}/reports/{scanId}/raw).
CLM-38633 Support zip files now include OAuth 2.0, OIDC, and Crowd configuration data (with secrets obfuscated), giving support teams immediate visibility into authentication settings without requiring manual API queries.
CLM-38555 CycloneDX SBOM scans containing newer SPDX license identifiers such as SMAIL-GPL now complete successfully and generate policy reports.
CLM-38424 OIDC token exchange requests now route through the HTTP proxy server configured via IQ Server's REST API (/api/v2/config/httpProxyServer), ensuring proxy settings are consistently honored during authentication.
CLM-37981 Advanced Search CSV export completes successfully when requests arrive via HTTP/1.0 connections, including those from nginx reverse proxies using default settings.
CLM-37414 H2-to-PostgreSQL database migration no longer requires superuser privileges — the dump file no longer includes SET session_replication_role, meaning imports run successfully for database owners on managed PostgreSQL services and restricted environments.
CLM-37113 Applications with approved waiver requests can now be deleted successfully, with associated policy waiver data handled automatically in the background.
CLM-36995 The Dependency Tree REST API, CycloneDX exports, and SPDX exports now include all components visible in the UI dependency tree, including those with unknown match states.
CLM-36831 Package URL encoding behavior has changed. PURLs containing special characters are now stored and processed using their original percent-encoded form, preserving correct representation in SBOM imports.

Coming Soon to Sonatype IQ

Java 25 Required as of IQ Server 204 (June 2026)

Starting with version 204 (June 2026), Sonatype IQ Server will require Java 25. This update ensures continued alignment with supported Java versions and enables access to the latest performance improvements and security enhancements provided by the Java platform.