# Sonatype Nexus Repository 3.85.0 - 3.85.1 Release Notes

**Known Issue in Sonatype Nexus Repository 3.83.0 - 3.89.1**

There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the _Verify and Repair_ or _Data Repair Plan_ tasks can incorrectly delete valid assets, leading to potential data loss.

**This issue is fixed in version 3.90.0.**

Upgrade to version 3.90.0 before running the _Verify and Repair_ or _Data Repair Plan_ tasks.

**Possible Need to Rebuild Search Index**

Search in High Availability (HA) environments is now case-insensitive for component and asset fields. However, components indexed using earlier versions may not appear in search results if they contain uppercase characters.

To ensure complete and accurate search results, manually run the _Repair - Rebuild repository search_ task for any affected repositories after upgrading.

## What's New and Noteworthy in 3.85.1?

**Released January 15, 2026**

### _Repair - Execute Data Repair Plan_ Task Disabled

To prevent potential data loss caused by a known issue impacting Sonatype Nexus Repository 3.83.0 and later, this release disables the _Repair - Execute Data Repair Plan_ task by default.

Attempting to run this task will result in a failure and an error in the logs. The task remains visible in the UI, and any existing instances of this task will not be removed. However, execution is blocked by default.

While it is possible to manually re-enable this task by setting the `nexus.reconcile.task.enabled` property to `true`, it is important that you not do so until you are using a release that restores support.

We will announce when it is safe to re-enable this task in a future release note.

## What’s New and Noteworthy in 3.85.0?

**Released October 7, 2025**

### Predictable S3 Bucket URLs for Nexus Repository Cloud

Sonatype Nexus Repository Cloud now supports predictable S3 bucket URLs for binary downloads, making it easier for teams to configure and manage outbound traffic rules in their tenants.

This update introduces a standardized URL format that includes region and tenant identifiers. With this structure, you can quickly identify and allow necessary traffic from Nexus Repository Cloud without relying on dynamic URLs. This is especially useful in tightly controlled network environments where pre-approving outbound traffic is required.

For more details, see the [Nexus Repository Cloud help documentation](https://help.sonatype.com/en/predictable-s3-bucket-urls.html "Predictable S3 Bucket URLs for Nexus Repository Cloud").

### Firewall API Endpoint Alignment

The Firewall API now consistently uses the `/api/v2/firewall/` path for all but the malware defense-specific endpoints. Previously existing `/api/v2/malware-defense/` paths remain supported for backward compatibility.

The `/api/v2/malware-defense/evaluate` API continues to be available and uses `malware-defense` in its path.

## Bug Fixes in 3.85.1

| Issue ID | Description |
| --- | --- |
| NEXUS-50152 | The blob attribute loading process no longer deletes properties files on transient I/O errors or unhandled exceptions. |

## Bug Fixes in 3.85.0

**Note**

A bug in the UI has been reported where the Upload Component button is missing when browsing repositories. This issue will be fixed in later updates.

| **Issue ID** | **Description** |
| --- | --- |
| NEXUS-17448 | Calls to the Crowd user manager are now skipped when Crowd is not configured. Related log messages have been downgraded from `WARN` to `DEBUG`. |
| NEXUS-41430 | Audit log messages for asset update and delete events now include the full path to the corresponding blob within the blobstore. |
| NEXUS-42187 | The _Use Nexus truststore_ checkbox in repository settings is now editable in the UI for users with _nx-repository-admin_ privileges. |
| NEXUS-44626 | The _Repository - Import external files_ task now successfully recognizes network-mounted drive paths when Nexus Repository is running as a Windows service. |
| NEXUS-44791 | The application now uses the `HOSTNAME` environment variable as the primary source for determining the hostname, preventing unnecessary error logs during startup in containerized HA environments. |
| NEXUS-45297 | APT snapshots for non-flat repositories now include `by-hash` metadata files generated from stored asset checksums, ensuring full compatibility with Ubuntu 24.04 and allowing functional snapshot usage. |
| NEXUS-45343 | RubyGems uploaded via the UI or REST API are now correctly included in the `specs.4.8.gz` file. |
| NEXUS-45370 | Improved logs for quarantined npm and PyPI package versions. |
| NEXUS-45788 | The search assets API now correctly supports sorting by the `last_updated` field. |
| NEXUS-45844 | NuGet V2 proxy repositories no longer throw a `java.lang.IllegalStateException: Duplicate key` during package restore operations. |
| NEXUS-45943 | Modified how secret mappings are handled in the Helm chart to prevent volume binding failures during deployment. |
| NEXUS-45973 | Re-enabled SHA1 encryption in the Nexus Repository Docker image to restore compatibility with Azure-hosted PostgreSQL instances and other external services that still rely on SHA1-based certificates. |
| NEXUS-46115 | Uploading to a NuGet group repository now correctly returns a 405 response. |
| NEXUS-46127 | Addressed a UI error that could occur after session timeouts, preventing crashes when returning to an inactive tab. |
| NEXUS-46281 | Database migrations now correctly set the `id` column in the `docker_foreign_layers` table to an integer type, preventing data conversion errors when retrieving Docker layers after migrating between H2 and PostgreSQL. |
| NEXUS-46487 | The _Admin - Change repository blob store_ task now preserves the original `blobCreated` timestamp. |
| NEXUS-46507 | The _Format_ field is no longer required when editing Repository Content Selector privileges. |
| NEXUS-46697 | APT staging moves now correctly update metadata in both source and target repositories. |
| NEXUS-46966 | Logger name inputs are now validated to prevent invalid characters or formatting. |
| NEXUS-47019 | Added additional logging to improve visibility into search index purge operations triggered by component deletions. |
| NEXUS-47022 | APT metadata is now automatically updated when components are removed by cleanup policies, ensuring metadata reflects the current state of hosted repositories. |
| NEXUS-47364 | The `INSTALL4J_ADD_VM_PARAMS` environment variable is now safely quoted during processing to prevent errors when it includes special characters. |
| NEXUS-47406 | Conan search results are now correctly scoped to the specified repository. |
| NEXUS-47446 | Composer proxy repositories now correctly handle packages with missing metadata. |
| NEXUS-47512 | The tagging UI now uses pagination to efficiently load and display tag data. |
| NEXUS-47652 | Selecting the Nexus Repository logo in the UI now correctly redirects to the configured `nexus-context-path`. |
| NEXUS-47770 | Startup messages about unknown or obsolete capability types are now logged at the `INFO` level instead of `WARN`, reducing unnecessary alerts for expected conditions. |
| NEXUS-47851 & NEXUS-48501 | Components removed from Sonatype Nexus Repository by a clean-up policy are now correctly removed from the Sonatype Repository Firewall quarantine list. |
| NEXUS-47948 | The _Plan Repair_ and _Execute Repair_ tasks no longer appear in Nexus Repository Cloud deployments. |
| NEXUS-48106 | YUM group metadata is now properly shared across nodes in an HA cluster after repository membership changes, preventing repeated and unnecessary remerging of `repomd.xml` during cross-node requests. |
| NEXUS-48162 | HA search is now case-insensitive by default. |
| NEXUS-48509 | Changing the _Maximum Connection Pool Size_ setting no longer puts Nexus Repository into an invalid state, ensuring the application remains available without requiring a restart. |
| NEXUS-48511 | Uploads to hosted repositories backed by group blob stores now defer `makeBlobPermanent` to member stores, eliminating unnecessary blob copying and improving performance. |
| NEXUS-48564 | The `root.level` system property is now correctly honored at startup, allowing debug logging to be enabled before Nexus Repository initializes. |
| NEXUS-48573 | Made change to improve the _Admin - Compact Blob Store_ task performance. |
| NEXUS-48595 | Using the `nexus.blobstore.get.maxRetries=0` property no longer prevents file uploads by ensuring the blob retrieval logic executes at least once before retry handling begins. |
| NEXUS-48602 | The internal node heartbeat cleanup task no longer fails with SQL syntax errors. |
| NEXUS-48644 | Logging out of the Nexus Repository user interface now correctly ends the session in HA environments.
