Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes
Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes
Known Issue in Sonatype Nexus Repository 3.83.0 - 3.89.1
There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the Verify and Repair or Data Repair Plan tasks can incorrectly delete valid assets, leading to potential data loss.
This issue is fixed in version 3.90.0.
Upgrade to version 3.90.0 before running the Verify and Repair or Data Repair Plan tasks.
Possible Need to Rebuild Search Index
Search in High Availability (HA) environments is now case-insensitive for component and asset fields. However, components indexed using earlier versions may not appear in search results if they contain uppercase characters.
To ensure complete and accurate search results, manually run the Repair - Rebuild repository search task for any affected repositories after upgrading.
What's New and Noteworthy in 3.85.1?
Released January 15, 2026
Repair - Execute Data Repair Plan Task Disabled
To prevent potential data loss caused by a known issue impacting Sonatype Nexus Repository 3.83.0 and later, this release disables the Repair - Execute Data Repair Plan task by default.
Attempting to run this task will result in a failure and an error in the logs. The task remains visible in the UI, and any existing instances of this task will not be removed. However, execution is blocked by default.
While it is possible to manually re-enable this task by setting the nexus.reconcile.task.enabled property to true, it is important that you not do so until you are using a release that restores support.
We will announce when it is safe to re-enable this task in a future release note.
What’s New and Noteworthy in 3.85.0?
Released October 7, 2025
Predictable S3 Bucket URLs for Nexus Repository Cloud
Sonatype Nexus Repository Cloud now supports predictable S3 bucket URLs for binary downloads, making it easier for teams to configure and manage outbound traffic rules in their tenants.
This update introduces a standardized URL format that includes region and tenant identifiers. With this structure, you can quickly identify and allow necessary traffic from Nexus Repository Cloud without relying on dynamic URLs. This is especially useful in tightly controlled network environments where pre-approving outbound traffic is required.
For more details, see the Nexus Repository Cloud help documentation.
Firewall API Endpoint Alignment
The Firewall API now consistently uses the /api/v2/firewall/ path for all but the malware defense-specific endpoints. Previously existing /api/v2/malware-defense/ paths remain supported for backward compatibility.
The /api/v2/malware-defense/evaluate API continues to be available and uses malware-defense in its path.
Bug Fixes in 3.85.1
| Issue ID | Description |
|---|---|
| NEXUS-50152 | The blob attribute loading process no longer deletes properties files on transient I/O errors or unhandled exceptions. |
Bug Fixes in 3.85.0
Note
A bug in the UI has been reported where the Upload Component button is missing when browsing repositories. This issue will be fixed in later updates.
| Issue ID | Description |
|---|---|
| NEXUS-17448 | Calls to the Crowd user manager are now skipped when Crowd is not configured. Related log messages have been downgraded from WARN to DEBUG. |
| NEXUS-41430 | Audit log messages for asset update and delete events now include the full path to the corresponding blob within the blobstore. |
| NEXUS-42187 | The Use Nexus truststore checkbox in repository settings is now editable in the UI for users with nx-repository-admin privileges. |
| NEXUS-44626 | The Repository - Import external files task now successfully recognizes network-mounted drive paths when Nexus Repository is running as a Windows service. |
| NEXUS-44791 | The application now uses the HOSTNAME environment variable as the primary source for determining the hostname, preventing unnecessary error logs during startup in containerized HA environments. |
| NEXUS-45297 | APT snapshots for non-flat repositories now include by-hash metadata files generated from stored asset checksums, ensuring full compatibility with Ubuntu 24.04 and allowing functional snapshot usage. |
| NEXUS-45343 | RubyGems uploaded via the UI or REST API are now correctly included in the specs.4.8.gz file. |
| NEXUS-45370 | Improved logs for quarantined npm and PyPI package versions. |
| NEXUS-45788 | The search assets API now correctly supports sorting by the last_updated field. |
| NEXUS-45844 | NuGet V2 proxy repositories no longer throw a java.lang.IllegalStateException: Duplicate key during package restore operations. |
| NEXUS-45943 | Modified how secret mappings are handled in the Helm chart to prevent volume binding failures during deployment. |
| NEXUS-45973 | Re-enabled SHA1 encryption in the Nexus Repository Docker image to restore compatibility with Azure-hosted PostgreSQL instances and other external services that still rely on SHA1-based certificates. |
| NEXUS-46115 | Uploading to a NuGet group repository now correctly returns a 405 response. |
| NEXUS-46127 | Addressed a UI error that could occur after session timeouts, preventing crashes when returning to an inactive tab. |
| NEXUS-46281 | Database migrations now correctly set the id column in the docker_foreign_layers table to an integer type, preventing data conversion errors when retrieving Docker layers after migrating between H2 and PostgreSQL. |
| NEXUS-46487 | The Admin - Change repository blob store task now preserves the original blobCreated timestamp. |
| NEXUS-46507 | The Format field is no longer required when editing Repository Content Selector privileges. |
| NEXUS-46697 | APT staging moves now correctly update metadata in both source and target repositories. |
| NEXUS-46966 | Logger name inputs are now validated to prevent invalid characters or formatting. |
| NEXUS-47019 | Added additional logging to improve visibility into search index purge operations triggered by component deletions. |
| NEXUS-47022 | APT metadata is now automatically updated when components are removed by cleanup policies, ensuring metadata reflects the current state of hosted repositories. |
| NEXUS-47364 | The INSTALL4J_ADD_VM_PARAMS environment variable is now safely quoted during processing to prevent errors when it includes special characters. |
| NEXUS-47406 | Conan search results are now correctly scoped to the specified repository. |
| NEXUS-47446 | Composer proxy repositories now correctly handle packages with missing metadata. |
| NEXUS-47512 | The tagging UI now uses pagination to efficiently load and display tag data. |
| NEXUS-47652 | Selecting the Nexus Repository logo in the UI now correctly redirects to the configured nexus-context-path. |
| NEXUS-47770 | Startup messages about unknown or obsolete capability types are now logged at the INFO level instead of WARN, reducing unnecessary alerts for expected conditions. |
| NEXUS-47851 & NEXUS-48501 | Components removed from Sonatype Nexus Repository by a clean-up policy are now correctly removed from the Sonatype Repository Firewall quarantine list. |
| NEXUS-47948 | The Plan Repair and Execute Repair tasks no longer appear in Nexus Repository Cloud deployments. |
| NEXUS-48106 | YUM group metadata is now properly shared across nodes in an HA cluster after repository membership changes, preventing repeated and unnecessary remerging of repomd.xml during cross-node requests. |
| NEXUS-48162 | HA search is now case-insensitive by default. |
| NEXUS-48509 | Changing the Maximum Connection Pool Size setting no longer puts Nexus Repository into an invalid state, ensuring the application remains available without requiring a restart. |
| NEXUS-48511 | Uploads to hosted repositories backed by group blob stores now defer makeBlobPermanent to member stores, eliminating unnecessary blob copying and improving performance. |
| NEXUS-48564 | The root.level system property is now correctly honored at startup, allowing debug logging to be enabled before Nexus Repository initializes. |
| NEXUS-48573 | Made change to improve the Admin - Compact Blob Store task performance. |
| NEXUS-48595 | Using the nexus.blobstore.get.maxRetries=0 property no longer prevents file uploads by ensuring the blob retrieval logic executes at least once before retry handling begins. |
| NEXUS-48602 | The internal node heartbeat cleanup task no longer fails with SQL syntax errors. |
| NEXUS-48644 | Logging out of the Nexus Repository user interface now correctly ends the session in HA environments. |