Sonatype Nexus Repository 3.93.0 - 3.93.2 Release Notes

Sonatype Nexus Repository 3.93.0 - 3.93.2 Release Notes

The Sonatype Nexus Repository 3.93.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!

Release Timeline

Ready to Upgrade?
Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.

What’s New and Noteworthy in This Release?

The Sonatype Nexus Repository 3.93.x release line includes the following new features and enhancements:

Support for Go Hosted and Group Repositories

Sonatype Nexus Repository now supports Go hosted and group repositories, enabling organizations to manage internal Go modules alongside external dependencies through a centralized repository manager.

With Go hosted repositories, you can securely store and publish internal Go modules, including module ZIP files, directly to Nexus Repository. Go group repositories simplify client configuration by allowing you to combine multiple Go repositories, including hosted and proxy repositories, behind a single URL.

For full details, see the Go repositories help documentation.

Support for Ansible Repository Format

Sonatype Nexus Repository now supports the Ansible Galaxy repository format, enabling teams to centrally manage Ansible collections alongside other development artifacts. By integrating Ansible Galaxy repositories with Nexus Repository, organizations can apply consistent governance, security, and repository management practices across their automation assets and software supply chain.

Nexus Repository supports proxy, hosted, and group repository types for Ansible collections. Teams can cache content from upstream sources such as galaxy.ansible.com, host internally developed collections, and aggregate multiple repositories behind a single endpoint to simplify client configuration.

For full details, see the Ansible repositories help documentation.

Support for Alpine Repository Format

Sonatype Nexus Repository now includes proxy, hosted, and group repository support for Alpine format, allowing teams to manage Alpine Linux packages through the same centralized repository management platform used for other package formats.

Alpine repository support helps teams improve the reliability and security of Alpine-based environments by centralizing package management and reducing reliance on external package sources. Nexus Repository integrates directly with the Alpine apk client, supports repository-specific RSA signing keys to help protect package integrity, and provides flexible access controls through both token-based authentication and anonymous access.

For full details, see the Alpine repositories help documentation.

New nameCode Parameter in User Token API

Sonatype Nexus Repository administrators can now look up user token ownership information by nameCode through the User Token REST API. This enhancement helps administrators quickly identify the user and authentication realm associated with a token during incident response, security investigations, and troubleshooting activities, reducing the time required to investigate token-related events.

The lookup capability supports both active and expired tokens and returns ownership and lifecycle information without exposing token secrets or credential material.

Granular Control of Uploader Metadata Visibility

Sonatype Nexus Repository now provides more granular control over access to uploader metadata associated with repository assets.

A new nexus:uploader-metadata:read permission controls access to uploader metadata across the Browse UI and REST APIs. Users without this permission no longer see uploader information in asset, component, or search results, while administrators retain access through existing administrative privileges.

By limiting access to sensitive metadata based on user responsibilities, this enhancement supports least-privilege security practices and helps organizations better protect internal user and infrastructure information.

Enhanced PyPI Repository Compatibility

Sonatype Nexus Repository now supports PEP 658 inline metadata and the PEP 691 JSON-based Simple API for hosted and proxy PyPI repositories. These standards improve interoperability with modern Python package management tools while preserving compatibility with existing clients that use the traditional PEP 503 HTML-based Simple API.

With more efficient access to package metadata, Python clients can resolve dependencies without downloading unnecessary package artifacts, reducing bandwidth usage and improving performance for developer workflows and CI/CD pipelines. This enhancement helps organizations deliver a PyPI experience that more closely aligns with modern Python ecosystem standards while maintaining support for existing package consumers.

Note that PEP 658 metadata and PEP 691 JSON support are available automatically in Nexus Repository 3.93.0 and later. Compatible Python clients include pip 23.1+, uv 0.1.0+, and Poetry 1.8+.

New Endpoints in Security management: user roles API

Sonatype Nexus Repository now includes additional endpoints in the Security management: user roles API that allow administrators to programmatically view and manage user role assignments in cloud deployments. Administrators can retrieve existing role assignments, replace assigned roles, add new roles, or remove existing roles through the API. These enhancements provide greater flexibility for organizations that automate user provisioning and access management workflows.

IP Allow List

The IP Allow List feature is now available in Sonatype Nexus Repository Pro and Cloud editions. This feature allows administrators to restrict access to Nexus Repository based on source IP addresses and network ranges, providing an additional layer of protection for deployments with network security requirements. Existing IP Allow List configurations are preserved during upgrade.

OAuth2/OIDC Configuration REST API

Sonatype Nexus Repository now provides public API support for managing OAuth2 and OpenID Connect (OIDC) configuration. Administrators can retrieve, update, and remove OAuth2 settings through REST APIs, enabling programmatic management of authentication configuration and reducing the need to perform these tasks through the user interface.

Improved Protection for Proxy Repository Credentials

Sonatype Nexus Repository now applies additional validation when updating proxy repository connection settings. As part of this update, administrators may be prompted to provide authentication credentials when modifying proxy repository connection details. This change strengthens protection for upstream credentials and supports more secure management of authenticated proxy repositories.

Refreshed Artifact Upload User Interface

Sonatype Nexus Repository includes an updated artifact upload UI with improved visual consistency and usability. The refreshed experience introduces a more cohesive layout, addresses several visual presentation issues, and aligns the upload workflow with the design patterns used throughout the application.

Expanded Enterprise Deployment Options for Kubernetes

Sonatype Nexus Repository now supports the enterprise Kubernetes deployment capabilities introduced in Helm chart 93.0.0 and later. These enhancements add support for ephemeral storage for transient log and support files, Horizontal Pod Autoscaler (HPA) for clustered high-availability deployments, and Azure Workload Identity with External Secrets Operator for Azure Key Vault integration.

These capabilities give DevOps and platform teams greater flexibility when deploying Nexus Repository in Kubernetes. They can reduce persistent storage requirements for temporary data, automatically scale clustered deployments based on workload demand, and simplify secure secret management using Azure-native identity services. Ephemeral storage is intended for environments that forward logs externally because transient data is not retained when pods restart or are rescheduled.

Authentication Attempt Rate Limits For Added Protection

Sonatype Nexus Repository now includes authentication rate limiting to help protect against brute force login attempts. After three consecutive failed authentication attempts, login requests to both the user interface and API authentication endpoints are temporarily rate limited, reducing the risk of automated credential-guessing attacks.

Administrators can configure this behavior using the nexus.auth.ratelimit.* properties to align authentication controls with their organization's security requirements.

Bug Fixes

3.93.2 Bug Fixes

Issue ID Description
NEXUS-53512 Users with multi-action application privileges can now access authorized resources correctly, preventing incorrect 403 responses during permission checks.

3.93.1 Bug Fixes

Issue ID Description
NEXUS-53214 Ansible Galaxy hosted repositories configured with Disable RIQ Redeploy now allow publishing new collection versions while continuing to block redeployment of existing versions.
NEXUS-53183 Collection installations from Ansible Galaxy hosted repositories now correctly resolve dependencies and complete successfully.
NEXUS-53062 Chained PyPI proxy repositories now successfully retrieve packages from upstream Nexus Repository instances that redirect artifact requests to S3 presigned URLs by removing the Authorization header before following cross-host redirects.
NEXUS-52551 Chained PyPI proxy repositories now generate correct outbound package download URLs for .whl files without duplicating repository path segments.
NEXUS-53281 Firewall quarantine requests now omit unsupported fields when communicating with IQ Server versions earlier than 204, maintaining compatibility with older releases.
NEXUS-53184 NuGet V2 FindPackagesById() now returns only exact package ID matches, preventing partial-name matches from appearing in search results.

3.93.0 Bug Fixes

Issue ID Description
NEXUS-52536 Docker GC tasks now evaluate all unreferenced blob assets across every page, ensuring unused layers beyond the first 100 are correctly identified and reclaimed during cleanup runs.
NEXUS-52906 PyPI proxy and group repositories now return correctly resolved package download URLs when clients access the PEP 691 JSON Simple API without a trailing slash.
NEXUS-52921 Swift proxy repositories now strip leading "v" and "V" prefixes from Git tags when building the registry version list, so SwiftPM resolves dependencies like 5.3.0 correctly instead of encountering a mismatch with v5.3.0.
NEXUS-52812 Outbound TLS connections in FIPS mode now succeed on Java 21, with the SSL layer explicitly enforcing TLSv1.2 and JKS keystore type to ensure compatibility with the BouncyCastle FIPS provider.
NEXUS-52690 The Google Cloud Storage blobstore now bundles io.opentelemetry:opentelemetry-api version 1.61.0, resolving CVE-2026-45292 (CWE-770, resource allocation without limits).
NEXUS-52659 Anonymous Docker pulls through a group repository now succeed when member repositories have "Allow Anonymous Docker Pulls" disabled, with the group-level anonymous access setting governing requests routed through the group.
NEXUS-52631 UI Branding headers and footers now correctly preserve <style> block rules when the provided HTML uses a full document structure, restoring layout behavior such as flexbox-based horizontal arrangements to match pre-3.92.1 behavior.
NEXUS-52584 npm group repositories now reflect newly published versions in the latest tag immediately, without waiting for the 24-hour metadata cache to expire.
NEXUS-52583 UI login permission checks for users with large role sets now complete in a fraction of the previous time, eliminating the extended "Loading Permissions" screen that blocked access for up to 20 seconds.
NEXUS-52567 Nexus Repository Server startup completes successfully when the malware risk feature flag (nexus.malware.risk.enabled=false) is disabled, with malware components now correctly gated behind the feature flag.
NEXUS-52475 Pre-signed URL generation for S3 blobstores with explicitly configured access key credentials now uses those credentials correctly, rather than falling back to environment-level credentials.
NEXUS-52414 Wildcard name searches containing path separators (such as /EUCLID/*Euclid_Develop*26_99_0*) now return matching components correctly in PostgreSQL-backed deployments.
NEXUS-52412 Swift proxy repositories now successfully fetch package releases through authenticated corporate HTTP proxies, with JGit's lsRemote replaced by a direct Git Smart HTTP implementation that routes through Nexus's existing HTTP client infrastructure.
NEXUS-52384 Swift proxy repositories now fetch the correct version-specific manifest file (Package@swift-X.Y.swift) when a swift-version query parameter is provided, and return an HTTP 303 redirect to the base Package.swift when no version-specific manifest exists upstream.
NEXUS-52382 Azure Blob Store downloads now stream data with bounded backpressure, preventing heap memory exhaustion when clients consume blobs slower than Azure delivers them.
NEXUS-52362 Maven group repositories now respect the minimum metadataMaxAge of their proxy members, ensuring cached merged maven-metadata.xml is revalidated against upstream sources instead of being served indefinitely.
NEXUS-52353 CocoaPods proxy repositories now perform a full recursive git clone for pods declaring "submodules": true, delivering complete archives with all submodule content instead of the incomplete tarballs previously returned by the GitHub archive API.
NEXUS-52333 When a Helm proxy repository's index.yaml cannot be parsed, the error log now includes the full exception stack trace and filename, making the root cause immediately visible without requiring DEBUG-level logging.
NEXUS-52266 The Compact blob store task now honors the rebuildDeletedBlobIndex flag for S3 blob stores, rebuilding the deleted blob index and removing the flag from metadata.properties upon completion.
NEXUS-52224 Nexus Repository startup logs no longer include the full nexus.properties map, preventing database credentials and other sensitive configuration values from appearing in plaintext during bootstrap.
NEXUS-52199 Yum hosted repository metadata rebuild tasks now use a direct indexed key lookup to check RPM registration status, replacing a repeated full-category scan that could cause rebuild operations to run for days on large repositories.
NEXUS-52197 Verbose PE binary parsing diagnostics from the PortEx library are now suppressed during Firewall scanning of Docker proxy repositories, keeping nexus.log free of excessive PELoader INFO entries when pulling Windows-based images.
NEXUS-51975 Cleanup policy asset name regex patterns containing the + quantifier are now preserved correctly during preview and policy creation, returning accurate results without requiring workarounds like [0-9][0-9]*.
NEXUS-51890 H2-to-PostgreSQL database migration now handles Docker foreign layer data correctly, generating new UUIDs during migration to bridge the INTEGER-to-UUID type difference between the two database schemas.
NEXUS-51884 NPM proxy repository ETags now update correctly when quarantined components are released via a Firewall policy waiver, ensuring downstream clients and chained proxy instances receive refreshed metadata rather than stale cached responses.
NEXUS-51880 The "Repair - Recalculate Blob Store Storage" task is no longer visible in Sonatype Repository Firewall SaaS instances, where blob storage is managed automatically by Sonatype.
NEXUS-51700 NuGet v2 Search() requests against group repositories now execute filtering, sorting, and pagination at the database level, eliminating the full asset table scans that caused response times of several minutes under concurrent load.
NEXUS-51672 Heap memory warnings are now triggered only after sustained high usage across multiple consecutive samples, preventing false alarms during normal GC sawtooth activity on busy instances.
NEXUS-51521 Docker push operations to S3-backed hosted repositories complete successfully, with AWS SDK v2 checksum settings now configured programmatically to prevent stream closure errors during multipart uploads.
NEXUS-51514 The S3 compact blob store task now logs a warning and continues processing remaining blobs when an individual blob deletion fails, rather than halting the entire compaction run.
NEXUS-50997 Routing rule updates and deletions made on one High Availability node are now propagated to all other nodes in the cluster immediately, keeping routing behavior consistent across the deployment.
NEXUS-50972 PyPI simple index pages are updated correctly when packages are removed through cleanup policies, preventing stale entries from appearing with broken links.
NEXUS-50965 Proxy repository HTTP connection pools are pre-warmed at startup, so Maven, npm, NuGet, PyPI, Swift, and Terraform asset requests succeed on the first attempt without requiring client-side retries.
NEXUS-50780 PyPI proxy and hosted repository package links resolve correctly whether the simple index URL is requested with or without a trailing slash.
NEXUS-50778 APT snapshots now include i18n/Translation-* metadata files, allowing Debian and Ubuntu clients to run apt update against snapshot repositories without encountering 404 errors.
NEXUS-50731 OAuth2/OIDC configuration is now accessible through a public REST API, allowing developers to retrieve, update, and delete OAuth2 settings programmatically via GET, PUT, and DELETE requests to /service/rest/v1/security/oauth2.
NEXUS-50643 Authentication attempts across all Nexus endpoints are now subject to exponential backoff rate limiting, returning HTTP 429 with a Retry-After header after three consecutive failures, with API and token-based authentication always enforced and UI login rate limiting applied only when SSO is not configured.
NEXUS-48928 PyPI hosted and proxy repositories now serve package metadata inline (PEP 658) and respond to JSON Simple API requests (PEP 691), enabling faster dependency resolution with pip, Poetry, and uv while remaining backward compatible with HTML-based clients.
NEXUS-47909 Maven group repositories now serve archetype-catalog.xml hash files (.sha1, .md5, .sha256, .sha512) successfully instead of returning a 500 error.
NEXUS-39223 RubyGems group repositories now merge duplicate gem entries from hosted and proxy members into a single /versions row with a unified version list and correctly recomputed checksum, allowing Bundler to resolve all available versions without errors.
NEXUS-22160 YUM hosted repositories now support modules.yaml, enabling offline mirroring of RHEL 8+ and CentOS 8+ modular package repositories.

Known Issues & Upgrade Guidance

This section captures known issues in the 3.93.x line as well as upgrade guidance.

Resolved Known Issues

Impacted Version(s) Version in which Issue is Resolved Description
3.93.0 - 3.93.2 3.94.0 Sonatype is aware of an issue impacting users of PyPI group repositories in Sonatype Nexus Repository 3.93.x who override packages from PyPI by uploading a patched package with the same version to a hosted repository.
When a PyPI group repository merges metadata from hosted and proxy repositories, the package hash advertised in the metadata can reference the upstream package instead of the hosted package. pip 26 validates the metadata hash and reports a checksum mismatch, preventing installation of the patched package even though the hosted artifact is served correctly.
This issue is resolved in 3.94.0. However, if you are unable to upgrade to 3.94.0, a partial workaround is to publish the patched package using a new version instead of replacing an existing upstream version.
3.93.0 – 3.93.1 3.93.2 When a role includes an application privilege that grants multiple actions (for example, Create + Read or Update + Read), Nexus Repository may incorrectly deny access to operations that require one of the granted actions.
This issue affects built-in and custom application privileges that combine multiple actions in a single permission and may result in unexpected HTTP 403 responses, even when the user has been assigned the required privilege.
The issue is most likely to affect users assigned roles containing multi-action application privileges, such as User Token settings, security administration, blob store creation, user management, or custom privileges configured with more than one action.
3.93.0 3.93.1 When a NuGet V2 client calls FindPackagesById() with a package ID, Nexus Repository may return packages whose IDs partially match the requested value, even when the request does not include a wildcard. For example, a request for Project may also return packages such as Project-main. This issue is most likely to affect repositories where multiple NuGet packages have IDs that share a common prefix or tokenized package ID.
3.91.x – 3.93.0 3.93.1 When a PyPI proxy repository points to a remote repository that returns relative links for Python wheel files, Nexus Repository may incorrectly resolve those links when constructing the upstream download request. This can result in invalid upstream URLs and HTTP 404 responses returned to Python clients.
This issue is known to affect chained PyPI proxy configurations where one Nexus Repository instance proxies another Nexus Repository instance. PyPI proxy repositories configured to proxy PyPI.org directly are not known to be affected.
3.93.0 and IQ 203.x IQ 204 When Sonatype Nexus Repository 3.93.0 is used with IQ Server 203.x or earlier, Nexus Firewall functionality may not operate correctly. This may result in failed client requests to Firewall-enabled repositories and potential service disruption. To avoid this issue, upgrade IQ Server to version 204 or later before upgrading to Sonatype Nexus Repository 3.93.0.