Sonatype Nexus Repository 3.89.0 Release Notes
Sonatype Nexus Repository 3.89.0 Release Notes
The Sonatype Nexus Repository 3.89.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!
Ready to Upgrade?
Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.
What's New and Noteworthy in 3.89.1?
Released February 11, 2026
Sonatype Nexus Repository release 3.89.1 fixes the following bugs:
| Issue ID | Description |
|---|---|
| NEXUS-50621 | Metadata generation for hosted APT repositories now correctly includes all applicable package versions in Packages files, ensuring clients receive complete and accurate repository metadata. |
| NEXUS-50490 | The LDAP configuration REST API now properly handles authentication password parameters when creating LDAP server connections. |
| NEXUS-50487 | The LDAP configuration API now correctly handles updates when using URL-encoded connection names in REST API requests. |
| NEXUS-50473 | User access to group repositories now correctly inherits read and browse permissions from member repositories, with consistent enforcement of content selectors across authorization checks and Browse previews. |
| NEXUS-50338 | LDAP configuration updates via REST API now reliably preserve all required fields during credential rotation and server configuration changes. |
| NEXUS-48604 | Enhanced LDAP credential rotation in High Availability clusters to ensure cache synchronization across all nodes when updating bind credentials. |
What’s New and Noteworthy in 3.89.0?
Released February 3, 2026
Support for Swift Proxy Repository Format
Sonatype Nexus Repository now supports the Swift proxy repository format, enabling teams to integrate Swift Package Manager (SPM) into their existing repository management workflows.
Nexus Repository provides a registry-based alternative to SPM’s traditional Git-based dependency resolution, offering an HTTP- and JSON-driven approach to discovering, resolving, and consuming Swift packages. This allows organizations to centralize access to public Swift packages, reduce reliance on external Git hosting services, and improve build performance through caching and reuse of dependencies.
Swift proxy repositories are available in both Pro and Community editions. Teams can apply enterprise controls such as access management and auditing while continuing to support both registry-based dependencies (available with Swift 5.7 and later) and Git-based dependencies.
For full details, see our Swift Repositories help documentation.
Support for Terraform Hosted Repository Format
Sonatype Nexus Repository now extends its Terraform support to include hosted repositories. With hosted Terraform repositories, you can centrally distribute Terraform modules as versioned source archives and platform-specific binaries as well as Terraform providers packaged as .zip files. This enables teams to securely host internally developed Terraform assets and reduce reliance on external sources.
This enhancement also streamlines provider management by automatically generating required provider metadata, checksum files, and GPG signatures, while supporting multiple provider versions and incremental platform uploads. Repository-level permissions allow you to control access to Terraform content, and full REST API support makes it easier to automate repository and artifact management as part of your infrastructure-as-code workflows.
For full details, see our Terraform Repositories help documentation.
Expanded Authentication Options for Terraform
Sonatype Nexus Repository now enables access to Terraform repositories through expanded authentication support.
Terraform repositories can now be accessed using anonymous access when enabled, allowing unauthenticated clients to discover and retrieve provider versions without authorization failures.
In addition, authentication logic now correctly validates Base64-encoded username and password tokens, allowing Terraform clients to authenticate successfully without relying on Pro-only user tokens.
Improved User Interface Performance and Faster Page Loads
This release significantly improves the Sonatype Nexus Repository user interface by reducing initial page load times and making the application more responsive. Improvements include decreased bandwidth usage and improved caching efficiency, resulting in a more scalable, modern UI that performs consistently for users regardless of location or deployment size.
Change in Permissions for Executing Rolling Upgrades
The ability to inspect and execute rolling (i.e., zero-downtime) upgrades is now available to users with the nx-atlas-all privilege. This change simplifies access control by reducing the permissions required to manage rolling upgrades, enabling more teams to perform upgrade operations without expanding administrative privileges while still maintaining a secure deployment model.
Breaking change: SAML login requires SAML2_AUTH_REQUEST cookie
Starting in Sonatype Nexus Repository 3.89.0, SAML authentication requires the SAML2_AUTH_REQUEST cookie to complete the login flow. Environments, infrastructure, or browser configurations that block third-party cookies can prevent this cookie from being set, causing SAML login to fail after upgrade. Before upgrading, ensure that policies or browser settings allow the SAML2_AUTH_REQUEST cookie so that SAML authentication continues to function as expected.
Bug Fixes
This release delivers a wide range of fixes and improvements. For better readability, we’ve organized these improvements into logical sections below.
Repository Storage, Uploads, and Data Integrity
This release includes several important improvements to how repositories handle data at scale, with a focus on stability, performance, and correctness during heavy operations. Changes address memory pressure during large uploads, race conditions during repository lifecycle events, safer execution of repair tasks, and more resilient database migrations and restores. Together, these fixes reduce the risk of outages, unexpected data loss, and failures during upgrades or maintenance in large or high-concurrency environments.
| Issue ID | Description |
|---|---|
| NEXUS-50040 | The REST APIs for Hosted Repository Analysis now evaluate artifacts without returning an HTTP 500 error, preventing a NullPointerException when determining repository scan support. |
| NEXUS-50183 | Uploads to Azure blob stores now apply backpressure to limit in-memory chunk accumulation, preventing OutOfMemoryError during large file proxying and improving stability for high-concurrency environments. |
| NEXUS-50151 & NEXUS-50116 | The Repair – Execute Data Repair Plan task no longer removes unexpected assets during execution. Note that this task is still disabled by default in release 3.89.0. |
| NEXUS-49996 | Improved repository deletion performance and reliability by optimizing role privilege cleanup and addressing race conditions across HA nodes. |
| NEXUS-46095 | Large PostgreSQL migrations no longer fail due to heap exhaustion, as the database migrator now cleans up accumulated component and asset data during and after processing to significantly reduce memory usage. |
| NEXUS-44560 | Made adjustments to safely handle a race condition during repository recreation to prevent failures when uploading content or starting facets after rapidly deleting and recreating a repository with the same name. |
| NEXUS-35758 | Nexus Repository now checks whether an H2 database exists before attempting a restore. |
Formats and Ecosystem-Specific Fixes
A wide range of format-specific fixes improve reliability, performance, and standards compliance across supported ecosystems. Package managers such as APT, NuGet, npm, Maven, Docker, PyPI, Terraform, Conan, and Yum all benefit from targeted updates to metadata handling, search behavior, proxying, and rebuild logic.
Notably, Yum has received several improvements over the last couple of releases, including better metadata rebuild performance, safer handling of invalid group metadata, clearer diagnostics, and more efficient XML merging, resulting in more predictable behavior for large or complex Yum repositories.
| Issue ID | Description |
|---|---|
| NEXUS-50240 | Anonymous access to Terraform proxy repositories now correctly allows unauthenticated users to retrieve provider versions without receiving a 401 response. |
| NEXUS-49970 | Improved performance of delta APT metadata rebuilds for large hosted repositories by optimizing how metadata updates are written to the database. |
| NEXUS-49845 | Corrected a race condition that caused npm group metadata updates to fail when handling non–URL-safe package names. |
| NEXUS-49777 | NuGet V3 search queries now return the correct totalHits value and properly exclude pre-release packages when specified. |
| NEXUS-49744 | NuGet metadata now preserves dot separators in target framework monikers. |
| NEXUS-49489 | npm tarballs are now correctly served from group repositories even when member proxies have differing PCCS waiver configurations. |
| NEXUS-49485 | Requests to APT hosted repositories now block until metadata is available during rebuilds, preventing transient 404 responses and ensuring more reliable package retrieval in high-traffic environments. |
| NEXUS-49371 | NuGet V2 status checks no longer show a misleading warning on HA node startup when no NuGet V2 repositories exist. |
| NEXUS-48975 | Creating new Docker repositories with mixed case names is now blocked to ensure compatibility with path-based routing and align with Docker's lowercase naming requirements. |
| NEXUS-48945 | The Repair - Rebuild npm metadata task now preserves the existing latest tag based on publish order. |
| NEXUS-48531 | PyPI group repositories now serve previously cached metadata when PCCS evaluations time out. |
| NEXUS-47774 | Migrations from Nexus Repository 2 now correctly preserve the fileTypeValidation setting by mapping it to strictContentTypeValidation in Nexus Repository 3. |
| NEXUS-47433 | The npm v1 search now returns accurate and complete results even in large repositories with many assets. |
| NEXUS-47092 | Maven metadata at the group-artifact level is now correctly maintained when artifact and group IDs overlap. |
| NEXUS-46771 | NuGet v2 proxy repositories now proactively prefetch package dependencies. |
| NEXUS-45636 | Conan 2 search in HA deployments now returns up to 10,000 results by default. |
| NEXUS-45299 | Optimized how large XML files are merged to improve Yum group metadata rebuilds. |
| NEXUS-43699 | Nexus Repository now preserves the scripts section from package.json when npm packages are uploaded to a hosted repository via the UI, REST API, or import task. |
| NEXUS-39374 | Cached Docker blob layers can now be deleted from Docker proxy repositories using the same HTTP DELETE requests supported by hosted repositories. |
| NEXUS-38502 | Corrected YUM group metadata handling so repositories with invalid or missing member metadata no longer return an empty repomd.xml, instead rebuilding metadata or returning a 404 to reflect the invalid state accurately. |
| NEXUS-37810 | Strict Content Type Validation now correctly recognizes the MIME type application/x-sharedlib. |
Search, Browse, and Indexing
Search and browse functionality has been refined to be more accurate, predictable, and scalable, particularly in HA and large-repository environments. These changes improve filtering correctness, restore expected matching semantics, eliminate silent result truncation, and harden APIs against invalid requests. Performance optimizations also reduce the likelihood of failures during search rebuild tasks and high-volume query scenarios.
| Issue ID | Description |
|---|---|
| NEXUS-49729 | The Repair - Rebuild repository search task now processes assets in batches, preventing PostgreSQL parameter limits from being exceeded. |
| NEXUS-49265 | Searches in the Namespace, Name, and Version columns in HA environments now return only exact matches unless a wildcard is explicitly included, restoring the expected strict matching behavior. |
| NEXUS-48992 | Search results from the /rest/v1/search/assets API are no longer silently truncated at 10,000 items, as the removal of Elasticsearch eliminates the underlying limitation that caused incomplete responses without indication. |
| NEXUS-46696 | The Search API now correctly filters results by maven.extension and maven.classifier. |
| NEXUS-45786 | The Search Assets API now returns a 400 Bad Request with a clear error message when an invalid sort field is used. |
| NEXUS-45400 | Improved performance of the internal group member cache to reduce delays and failures during search operations. |
| NEXUS-28286 | Browsing behavior now respects content selectors as expected. |
Security, Permissions, and Access Control
Several fixes improve how Nexus Repository evaluates permissions and access rules, both in terms of correctness and performance. Updates ensure that permission checks behave consistently across the UI and APIs, reduce authorization overhead in environments with frequent access checks, and ensure group repositories properly reflect the availability state of their members.
| Issue ID | Description |
|---|---|
| NEXUS-49924 | Reduced overhead during permission checks, resulting in faster performance for environments with frequent authorization lookups. As part of this fix, we created a new cache to manage each user's permissions. This cache is enabled by default, but administrators can disable it with nexus.security.principal.permissions.cache.enabled=false. |
| NEXUS-49758 | Group repositories now correctly honor the offline status of member proxy repositories. |
| NEXUS-49414 | Updated permission checks in the Browse interface. |
High Availability, Clustering, and Operations
HA and clustered deployments benefit from improved coordination, consistency, and operational safety. Fixes address credential synchronization across nodes, reduce migration-related memory issues, and improve the reliability and predictability of Helm-based HA deployments. These changes help ensure smoother upgrades and more stable behavior in multi-node environments.
| Issue ID | Description |
|---|---|
| NEXUS-48147 | The Nexus HA Helm chart now uses a centralized and consistent naming mechanism for StatefulSets, removing the nonfunctional statefulset.name parameter to avoid confusion and ensure predictable resource naming. |
| NEXUS-47679 | Improved synchronization of password changes across HA nodes to ensure updated credentials are recognized immediately. |
| NEXUS-46095 | Large PostgreSQL migrations no longer fail due to heap exhaustion, as the database migrator now cleans up accumulated component and asset data during and after processing to significantly reduce memory usage. |
UI and User Experience
User-facing workflows have been polished to remove friction, prevent common errors, and improve clarity. These updates include safer handling of whitespace in repository configuration, restored or simplified UI controls, and fixes to edge cases that could cause confusing behavior after session timeouts or during repository creation.
| Issue ID | Description |
|---|---|
| NEXUS-49792 | The user interface now automatically trims leading and trailing spaces from proxy repository URLs. |
| NEXUS-49791 | Trailing spaces in proxy repository remote URLs no longer cause errors in startup tasks. |
| NEXUS-49573 | The Upload Component button has been restored in the Browse view for hosted repositories. |
| NEXUS-45425 | Removed the Version Policy, Layout Policy, and Content Disposition fields from the UI for creating Maven group repositories. |
| NEXUS-44432 | After a UI session timeout, the Go Back button on the unsaved changes popup now behaves as expected or no longer appears unnecessarily. |
Logging, Monitoring, and Diagnostics
Logging and diagnostic output has been refined to be more actionable and less noisy. Improvements include clearer upgrade and metadata warnings, better visibility into long-running operations, consolidated request logging, and more informative startup and shutdown messages. These changes make it easier to troubleshoot issues and understand system behavior in production environments.
| Issue ID | Description |
|---|---|
| NEXUS-49069 | Uptime log entries once again include the running Sonatype Nexus Repository version during startup and shutdown, making it easier to identify the source version when investigating upgrade-related support cases. |
| NEXUS-48956 | Added logging to the browse node migration upgrade step to provide visibility into potentially long-running schema changes on large browse_node tables. |
| NEXUS-48881 | Outbound request logs now consolidate all relevant details into a single line, including the HTTP method and response time. |
| NEXUS-46565 | Log messages about duplicate browse nodes are now recorded at the DEBUG level instead of WARN. |
| NEXUS-45291 | Warning logs for group repository metadata generation now include the names of member repositories missing ETag headers, making it easier to identify the source of repeated and expensive metadata rebuilds. |
Tasks, Cleanup, and Maintenance
Maintenance and background tasks are now more resilient and resource-efficient, particularly when operating on large datasets. Enhancements ensure cleanup and repair tasks behave safely when encountering unexpected states, reduce memory usage during intensive operations, and improve overall system stability during scheduled or manual maintenance activities.
| Issue ID | Description |
|---|---|
| NEXUS-50419 | Updated the image scanning process to ensure temporary resources are properly cleaned up, improving system stability and preventing potential memory issues. |
| NEXUS-50183 | Uploads to Azure blob stores now apply backpressure to limit in-memory chunk accumulation, preventing OutOfMemoryError during large file proxying and improving stability for high-concurrency environments. |
| NEXUS-45388 | Improved the Admin - Cleanup Tags task to gracefully handle missing components by skipping over them. |
Documentation and API Fixes
Documentation and API examples have been corrected to better reflect supported behavior and real-world usage. These fixes remove misleading parameters and ensure example requests are accurate and usable, helping users avoid configuration errors and reducing friction when integrating with Nexus Repository programmatically.
| Issue ID | Description |
|---|---|
| NEXUS-41276 | The Component Upload API documentation no longer lists unsupported Docker parameters. |
| NEXUS-30682 | The cURL example for the tasks/{id}/run endpoint in the Swagger UI now includes the correct headers and formatting. |
Coming Soon to Sonatype Nexus Repository
Change to Nexus Repository Docker Image Base and Tagging
As of 3.91.0, the base nexus3 image will be built off of alpine instead of ubi. This should be an invisible change for anyone using our image from dockerhub. If you are building an image off of our image, you will need to update your build process. Effective with 3.94.0, we will no longer publish new versions of the nexus3 image with the -ubi and -alpine suffix.
Known Issues & Upgrade Guidance
This section captures known issues in the 3.89.x line as well as upgrade guidance.
Resolved Known Issues
| Impacted Version(s) | Version in which Issue is Resolved | Description |
|---|---|---|
| 3.83.0 – 3.89.1 | 3.90.0 | There is an issue in Sonatype Nexus Repository 3.83.0 - 3.89.1 where running the Verify and Repair or Data Repair Plan tasks can incorrectly delete valid assets, leading to potential data loss. This issue is fixed in Nexus Repository 3.90.0. Upgrade to version 3.90.0 before running the_Verify and Repair_or Data Repair Plan tasks. |
| 3.89.0 – 3.89.1 | 3.90.0 | Using the Admin - Remove a member from a blob store group task on a blob store group can cause moved blobs to become unreachable. This issue is fixed in Nexus Repository 3.90.0. Upgrade to version 3.90.x before running the Admin - Remove a member from a blob store group task. |
| 3.89.0 | 3.89.1 | Sonatype is aware of an issue in release 3.89.0 that affects APT hosted repositories. Repository metadata may be incomplete or incorrect, even though all packages exist in the repository. This issue is fixed in 3.89.1. |