# Sonatype Nexus Repository 3.84.0 - 3.84.2 Release Notes

## What's New and Noteworthy in 3.84.2

**Released January 15, 2026**

### _Repair - Execute Data Repair Plan_ Task Disabled

To prevent potential data loss caused by a known issue impacting Sonatype Nexus Repository 3.83.0 and later, this release disables the _Repair - Execute Data Repair Plan_ task by default.

Attempting to run this task will result in a failure and an error in the logs. The task remains visible in the UI, and any existing instances of this task will not be removed. However, execution is blocked by default.

While it is possible to manually re-enable this task by setting the `nexus.reconcile.task.enabled` property to `true`, it is important that you not do so until you are using a release that restores support.

We will announce when it is safe to re-enable this task in a future release note.

**Known Issue in Sonatype Nexus Repository 3.83.0 - 3.89.1**

There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the _Verify and Repair_ or _Data Repair Plan_ tasks can incorrectly delete valid assets, leading to potential data loss.

**This issue is fixed in version 3.90.0.**

Upgrade to version 3.90.0 before running the _Verify and Repair_ or _Data Repair Plan_ tasks.

## What's New and Noteworthy in 3.84.1?

**Released September 17, 2025**

This release fixes multiple bugs impacting release 3.84.0. See the [bug fixes section below](https://help.sonatype.com/en/sonatype-nexus-repository-3-84-0-release-notes.html#bug-fixes-in-3-84-1 "Bug Fixes in 3.84.1") for details.

## What’s New and Noteworthy in 3.84.0?

**Released September 9, 2025**

### Support for OCI Image Manifest Specification and RPM Packages in Container Scanning

Sonatype Repository Firewall now supports container images that use the OCI Image Manifest Specification and Linux distributions that use the RPM package format. This enhancement extends compatibility beyond existing support for Docker Manifest List Schema V2.

With this update, customers scanning container images can expect consistent analysis across OCI-compliant manifests and improved visibility into vulnerabilities and license risks within RPM-based layers.

For more information, see the [Firewall for Docker help documentation](https://help.sonatype.com/en/firewall-for-docker.html "Firewall for Docker").

### Improved Stability for Concurrent Requests in Highly Available Deployments

This release enhances Sonatype Nexus Repository high availability (HA) deployment stability by improving how the system handles simultaneous requests for the same asset across multiple nodes. Nexus Repository can now better manage transient read failures when accessing blob attributes, reducing the likelihood of request failures during periods of high concurrency.

Customers running HA deployments will see more consistent performance and fewer interruptions when multiple users or systems request the same file at the same time.

### Updated Task Names for Data Repair Consistency

To align with standard task naming conventions in Sonatype Nexus Repository, we have updated the names of two recently introduced tasks:

- _Verify and Repair Data Consistency_ is now _Repair - Data Repair Plan_

- _Execute Plan Data Repair_ is now _Repair - Execute Data Repair Plan_

These changes do not affect task functionality and only bring the naming into better alignment with our task naming conventions.

### Dependency Updates

This release includes the following dependency updates:

- tika-core version upgraded from 1.28.4 to 3.2.2
- bouncycastle version upgraded from 1.78.1 to 1.81
- azure-identity version upgraded from 1.16.2 to 1.17.0

## Bug Fixes in 3.84.2

| Issue ID | Description |
| --- | --- |
| NEXUS-50152 | The blob attribute loading process no longer deletes properties files on transient I/O errors or unhandled exceptions. |

## Bug Fixes in 3.84.1

| Issue ID | Description |
| --- | --- |
| NEXUS-48666 | Resolved an issue that prevented licenses ending with specific characters from being successfully installed in Nexus Repository. |
| NEXUS-48591 | IQ Server certificates stored in the Nexus Repository truststore work as expected after restarting Nexus Repository. |

## Bug Fixes in 3.84.0

| **Issue ID** | **Description** |
| --- | --- |
| NEXUS-29075 | Components can be downloaded as expected through a proxy repository in audit mode even when Sonatype Lifecycle is unreachable. |
| NEXUS-44970 | Docker-specific attributes are now reliably saved during Docker asset creation. |
| NEXUS-45134 | The Docker Garbage Collection task now skips and removes invalid BLOB assets missing a `content_digest`. |
| NEXUS-46276 | The Tasks API now accepts "*" as a valid value for `repositoryName`. |
| NEXUS-46450 | Cargo proxy repositories can now be successfully chained. |
| NEXUS-46734 | The startup script now uses POSIX-compliant `[ ]` conditionals instead of bash-specific `[[ ]]` syntax. |
| NEXUS-47252 | Uploads to instances migrated from H2 now complete successfully without duplicate key errors during blob operations. |
| NEXUS-47788 | Users assigned repository-specific admin privileges can now access and manage the configuration page for their assigned repositories as expected. |
| NEXUS-48050 | The global header search behavior now redirects to the correct search results page. |
| NEXUS-48149 | Docker proxy repositories now correctly handle manifests retrieved via pre-signed URLs. |
| NEXUS-48177 | Cleanup policies using the Asset Name Matcher criteria now function correctly for npm hosted repositories when using the H2 database. |
| NEXUS-48396 | Removed the `purl` query parameter from the documentation for the `api/v2/reports/components/quarantined` endpoint, as it is not supported. Note that you can use the supported filtering options provided in the [Components in Quarantine API documentation](https://help.sonatype.com/en/firewall-apis.html#UUID-d516f5b1-1573-aae2-7261-107d95f5fb67_bridgehead-idm234858643592914 "Components in Quarantine") to retrieve specific quarantined components. |
| NEXUS-48422 | Docker Firewall scanning now safely handles null values in image metadata. |
| NEXUS-48568 & NEXUS-48200 | The Capabilities API now returns the expected responses and appears correctly in the UI.
