Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes

Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes

Known Issue in Sonatype Nexus Repository 3.83.0 - 3.89.1

There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the Verify and Repair or Data Repair Plan tasks can incorrectly delete valid assets, leading to potential data loss.

This issue is fixed in version 3.90.0.

Upgrade to version 3.90.0 before running the Verify and Repair or Data Repair Plan tasks.

Possible Need to Rebuild Search Index

Search in High Availability (HA) environments is now case-insensitive for component and asset fields. However, components indexed using earlier versions may not appear in search results if they contain uppercase characters.

To ensure complete and accurate search results, manually run the Repair - Rebuild repository search task for any affected repositories after upgrading.

What's New and Noteworthy in 3.85.1?

Released January 15, 2026

Repair - Execute Data Repair Plan Task Disabled

To prevent potential data loss caused by a known issue impacting Sonatype Nexus Repository 3.83.0 and later, this release disables the Repair - Execute Data Repair Plan task by default.

Attempting to run this task will result in a failure and an error in the logs. The task remains visible in the UI, and any existing instances of this task will not be removed. However, execution is blocked by default.

While it is possible to manually re-enable this task by setting the nexus.reconcile.task.enabled property to true, it is important that you not do so until you are using a release that restores support.

We will announce when it is safe to re-enable this task in a future release note.

What’s New and Noteworthy in 3.85.0?

Released October 7, 2025

Predictable S3 Bucket URLs for Nexus Repository Cloud

Sonatype Nexus Repository Cloud now supports predictable S3 bucket URLs for binary downloads, making it easier for teams to configure and manage outbound traffic rules in their tenants.

This update introduces a standardized URL format that includes region and tenant identifiers. With this structure, you can quickly identify and allow necessary traffic from Nexus Repository Cloud without relying on dynamic URLs. This is especially useful in tightly controlled network environments where pre-approving outbound traffic is required.

For more details, see the Nexus Repository Cloud help documentation.

Firewall API Endpoint Alignment

The Firewall API now consistently uses the /api/v2/firewall/ path for all but the malware defense-specific endpoints. Previously existing /api/v2/malware-defense/ paths remain supported for backward compatibility.

The /api/v2/malware-defense/evaluate API continues to be available and uses malware-defense in its path.

Bug Fixes in 3.85.1

Issue ID Description
NEXUS-50152 The blob attribute loading process no longer deletes properties files on transient I/O errors or unhandled exceptions.

Bug Fixes in 3.85.0

Note

A bug in the UI has been reported where the Upload Component button is missing when browsing repositories. This issue will be fixed in later updates.

Issue ID Description
NEXUS-17448 Calls to the Crowd user manager are now skipped when Crowd is not configured. Related log messages have been downgraded from WARN to DEBUG.
NEXUS-41430 Audit log messages for asset update and delete events now include the full path to the corresponding blob within the blobstore.
NEXUS-42187 The Use Nexus truststore checkbox in repository settings is now editable in the UI for users with nx-repository-admin privileges.
NEXUS-44626 The Repository - Import external files task now successfully recognizes network-mounted drive paths when Nexus Repository is running as a Windows service.
NEXUS-44791 The application now uses the HOSTNAME environment variable as the primary source for determining the hostname, preventing unnecessary error logs during startup in containerized HA environments.
NEXUS-45297 APT snapshots for non-flat repositories now include by-hash metadata files generated from stored asset checksums, ensuring full compatibility with Ubuntu 24.04 and allowing functional snapshot usage.
NEXUS-45343 RubyGems uploaded via the UI or REST API are now correctly included in the specs.4.8.gz file.
NEXUS-45370 Improved logs for quarantined npm and PyPI package versions.
NEXUS-45788 The search assets API now correctly supports sorting by the last_updated field.
NEXUS-45844 NuGet V2 proxy repositories no longer throw a java.lang.IllegalStateException: Duplicate key during package restore operations.
NEXUS-45943 Modified how secret mappings are handled in the Helm chart to prevent volume binding failures during deployment.
NEXUS-45973 Re-enabled SHA1 encryption in the Nexus Repository Docker image to restore compatibility with Azure-hosted PostgreSQL instances and other external services that still rely on SHA1-based certificates.
NEXUS-46115 Uploading to a NuGet group repository now correctly returns a 405 response.
NEXUS-46127 Addressed a UI error that could occur after session timeouts, preventing crashes when returning to an inactive tab.
NEXUS-46281 Database migrations now correctly set the id column in the docker_foreign_layers table to an integer type, preventing data conversion errors when retrieving Docker layers after migrating between H2 and PostgreSQL.
NEXUS-46487 The Admin - Change repository blob store task now preserves the original blobCreated timestamp.
NEXUS-46507 The Format field is no longer required when editing Repository Content Selector privileges.
NEXUS-46697 APT staging moves now correctly update metadata in both source and target repositories.
NEXUS-46966 Logger name inputs are now validated to prevent invalid characters or formatting.
NEXUS-47019 Added additional logging to improve visibility into search index purge operations triggered by component deletions.
NEXUS-47022 APT metadata is now automatically updated when components are removed by cleanup policies, ensuring metadata reflects the current state of hosted repositories.
NEXUS-47364 The INSTALL4J_ADD_VM_PARAMS environment variable is now safely quoted during processing to prevent errors when it includes special characters.
NEXUS-47406 Conan search results are now correctly scoped to the specified repository.
NEXUS-47446 Composer proxy repositories now correctly handle packages with missing metadata.
NEXUS-47512 The tagging UI now uses pagination to efficiently load and display tag data.
NEXUS-47652 Selecting the Nexus Repository logo in the UI now correctly redirects to the configured nexus-context-path.
NEXUS-47770 Startup messages about unknown or obsolete capability types are now logged at the INFO level instead of WARN, reducing unnecessary alerts for expected conditions.
NEXUS-47851 & NEXUS-48501 Components removed from Sonatype Nexus Repository by a clean-up policy are now correctly removed from the Sonatype Repository Firewall quarantine list.
NEXUS-47948 The Plan Repair and Execute Repair tasks no longer appear in Nexus Repository Cloud deployments.
NEXUS-48106 YUM group metadata is now properly shared across nodes in an HA cluster after repository membership changes, preventing repeated and unnecessary remerging of repomd.xml during cross-node requests.
NEXUS-48162 HA search is now case-insensitive by default.
NEXUS-48509 Changing the Maximum Connection Pool Size setting no longer puts Nexus Repository into an invalid state, ensuring the application remains available without requiring a restart.
NEXUS-48511 Uploads to hosted repositories backed by group blob stores now defer makeBlobPermanent to member stores, eliminating unnecessary blob copying and improving performance.
NEXUS-48564 The root.level system property is now correctly honored at startup, allowing debug logging to be enabled before Nexus Repository initializes.
NEXUS-48573 Made change to improve the Admin - Compact Blob Store task performance.
NEXUS-48595 Using the nexus.blobstore.get.maxRetries=0 property no longer prevents file uploads by ensuring the blob retrieval logic executes at least once before retry handling begins.
NEXUS-48602 The internal node heartbeat cleanup task no longer fails with SQL syntax errors.
NEXUS-48644 Logging out of the Nexus Repository user interface now correctly ends the session in HA environments.