# Sonatype Nexus Repository 3.81.0 - 3.81.1 Release Notes

## What's New in Nexus Repository 3.81.1?

**Released June 11, 2025**

**Known Issue in 3.81.1: Quarantine Messages Missing from 403 Responses**

Sonatype is aware of an issue in Nexus Repository 3.81.1 that prevents all quarantine messages—both default and custom—from appearing in HTTP responses when components are blocked by Repository Firewall. Affected requests return only a generic "403 Forbidden" status with no explanatory message or link to the component report. This may impact environments that depend on these messages to inform users about quarantine reasons.

This release fixes an issue that caused `dotnet restore` commands to fail due to NuGet v3 content requests returning 404 errors.

### Switch Metrics Servlets to use JAX-RS

The REST API endpoints for metrics have changed. Redirects have been added, but not all scripts will follow redirects.

| Original Endpoint                        | New Endpoint                           |
|-----------------------------------------|---------------------------------------|
| `/service/metrics/prometheus`          | `/service/rest/metrics/prometheus`    |
| `/service/metrics/data`                | `/service/rest/metrics/data`          |
| `/service/metrics/ping`                | `/service/rest/metrics/ping`          |
| `/service/metrics/threads`             | `/service/rest/metrics/threads`       |
| `/service/metrics/healthcheck`         | `/service/rest/v1/status/check`       |

## What’s New in Nexus Repository 3.81.0?

**Released June 10, 2025**

### Egress Information Available in Licensing Usage Tab

Sonatype Nexus Repository now provides egress information for on-prem instances; administrators can find this information in the _Usage_ tab under _Settings_ > _System_ > _Licensing_. This new feature helps you understand your data transfer patterns, making it easier to plan for a potential cloud migration. By seeing your egress data upfront, you can better estimate costs and resource needs in a cloud environment.

Note that _Total Egress_ is calculated at the application level. This might differ from network transfer measurements from your cloud provider. Our testing indicates approximately 15% more traffic when estimating total egress in cloud environments.

For full details, see [the License Management help documentation](https://help.sonatype.com/en/license-management.html "License Management").

### Enhanced Security and Performance with Jetty 12

This release upgrades Sonatype Nexus Repository from Jetty 9 to Jetty 12, bringing enhanced security and performance to your instance. This upgrade ensures that Sonatype Nexus Repository operates on a supported and modern server technology.

If your Sonatype Nexus Repository instance uses a customized Jetty configuration, serves HTTPS directly through Sonatype Nexus Repository, or has a customized request log, plan to update your configurations accordingly.

Note that Dropwizard metrics are impacted by this upgrade. Specifically, there is no `org_eclipse_jetty_webapp_WebAppContext_2xx_responses_total` in the newer version. The replacement for these metric keys is as follows:

```
org_eclipse_jetty_ee8_nested_ContextHandler_CoreContextHandler_2xx_responses_total
org_eclipse_jetty_ee8_nested_ContextHandler_CoreContextHandler_requests_count
```

### Performance Improvements for Change Repository Blobstore in Google Cloud Environments

This release includes performance improvements for the [Change Repository Blob Store task](https://help.sonatype.com/en/change-repository-blob-store.html "Change Repository Blob Store") when moving from one Google Cloud Storage (GCP) bucket to another. Previously, this operation took considerably longer than other blob store migration types. This enhancement greatly improves the efficiency of managing your Google Cloud Storage-backed repositories.

### Integrate Sonatype Repository Firewall with Zscaler for Enhanced Malware Protection

Sonatype Repository Firewall now integrates with Zscaler, a cloud-native cybersecurity platform, to provide an additional layer of defense against actively verified malware components. This integration automatically blocks malicious components from being downloaded directly from public repositories, protecting your organization from malware found in "shadow downloads."

For details on how to enable this protection, see [our Zscaler integration help documentation](https://help.sonatype.com/en/zscaler.html "Integrate Firewall with Zscaler").

## Bug Fixes

| **Issue ID**  | **Description**                                                                                       |
|---------------|-------------------------------------------------------------------------------------------------------|
| NEXUS-47610   | **(3.81.1)** This release fixes an issue that caused `dotnet restore` commands to fail due to NuGet v3 content requests returning 404 errors. |
| NEXUS-47222   | The `nexus.log` no longer generates `ERROR` and `WARN` entries related to an unavailable `reconcile/list` resource when administrators open the _Administration_ > _System_ > _Tasks_ page. |
| NEXUS-47217   | Sonatype Nexus Repository's `cargo-group` functionality now correctly handles `features2` when building projects, preventing build failures that previously occurred. |
| NEXUS-47197   | Custom branding changes made through the UI branding capability now correctly appear in the application's user interface. |
| NEXUS-47020   | Made performance improvements so that newly uploaded components and staging move results now appear in search results more quickly. |
| NEXUS-46899   | Sonatype Nexus Repository now immediately reflects changes to user data from Crowd in the UI. |
| NEXUS-46508   | In Sonatype Nexus Repository HA instances, the Disassociate Tag API now correctly disassociates components from a tag and no longer returns an unrelated list of components. |
| NEXUS-46264   | Resolved various issues with 3.77.1 Alpine image.                                                  |
| NEXUS-46033   | The _Number of versions_ option in the cleanup policy for `maven2` and `docker` repositories no longer unexpectedly hides or reveals itself when other cleanup policy options are selected. |
| NEXUS-45866   | After enabling HA in Sonatype Nexus Repository, the _Support_ > _Status_ and _System_ > _Nodes_ pages now display consistent information. |
| NEXUS-45113   | The cleanup policy and cleanup service tasks now correctly remove empty directories.                   |
| NEXUS-44548   | `npm audit` commands work as expected when `npm` package name aliases are present.                     |
| NEXUS-29739   | NuGet v3 group repositories display the correct path in the browse UI. The download link for assets within these repositories also now functions as expected. |

## Coming Soon

Here’s what’s coming soon for Sonatype Nexus Repository:

### Sonatype Nexus Repository Cloud

Sonatype Nexus Repository will soon be available as a Sonatype Cloud solution! This will provide all the powerful artifact management capabilities you rely on, delivered and managed by Sonatype in the cloud.

### Path-Based Repository Support for Docker

Sonatype Nexus Repository will soon provide path-based repository support for Docker, allowing you to host multiple Docker registries under a single hostname using different URL subpaths. This eliminates the need for multiple ports or wildcard TLS certificates, simplifying enterprise deployments.

### Firewall Support for Containers

Sonatype Repository Firewall will soon introduce support for containers, enabling you to proactively block the download of container images violating your organization's policy configurations before they enter your container ecosystem.
