Sonatype Nexus Repository 3.93.0 - 3.93.2 Release Notes
Sonatype Nexus Repository 3.93.0 - 3.93.2 Release Notes
The Sonatype Nexus Repository 3.93.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!
Release Timeline
- 3.93.0 – June 4, 2026
- 3.93.1 – June 19, 2026
- 3.93.2 – June 25, 2026
Ready to Upgrade?
Before upgrading, see the Known Issues & Upgrade Guidance section at the end of these release notes to determine whether any known issues or upgrade recommendations apply to your environment.
What’s New and Noteworthy in This Release?
The Sonatype Nexus Repository 3.93.x release line includes the following new features and enhancements:
Support for Go Hosted and Group Repositories
Sonatype Nexus Repository now supports Go hosted and group repositories, enabling organizations to manage internal Go modules alongside external dependencies through a centralized repository manager.
With Go hosted repositories, you can securely store and publish internal Go modules, including module ZIP files, directly to Nexus Repository. Go group repositories simplify client configuration by allowing you to combine multiple Go repositories, including hosted and proxy repositories, behind a single URL.
For full details, see the Go repositories help documentation.
Support for Ansible Repository Format
Sonatype Nexus Repository now supports the Ansible Galaxy repository format, enabling teams to centrally manage Ansible collections alongside other development artifacts. By integrating Ansible Galaxy repositories with Nexus Repository, organizations can apply consistent governance, security, and repository management practices across their automation assets and software supply chain.
Nexus Repository supports proxy, hosted, and group repository types for Ansible collections. Teams can cache content from upstream sources such as galaxy.ansible.com, host internally developed collections, and aggregate multiple repositories behind a single endpoint to simplify client configuration.
For full details, see the Ansible repositories help documentation.
Support for Alpine Repository Format
Sonatype Nexus Repository now includes proxy, hosted, and group repository support for Alpine format, allowing teams to manage Alpine Linux packages through the same centralized repository management platform used for other package formats.
Alpine repository support helps teams improve the reliability and security of Alpine-based environments by centralizing package management and reducing reliance on external package sources. Nexus Repository integrates directly with the Alpine apk client, supports repository-specific RSA signing keys to help protect package integrity, and provides flexible access controls through both token-based authentication and anonymous access.
For full details, see the Alpine repositories help documentation.
New nameCode Parameter in User Token API
Sonatype Nexus Repository administrators can now look up user token ownership information by nameCode through the User Token REST API. This enhancement helps administrators quickly identify the user and authentication realm associated with a token during incident response, security investigations, and troubleshooting activities, reducing the time required to investigate token-related events.
The lookup capability supports both active and expired tokens and returns ownership and lifecycle information without exposing token secrets or credential material.
Granular Control of Uploader Metadata Visibility
Sonatype Nexus Repository now provides more granular control over access to uploader metadata associated with repository assets.
A new nexus:uploader-metadata:read permission controls access to uploader metadata across the Browse UI and REST APIs. Users without this permission no longer see uploader information in asset, component, or search results, while administrators retain access through existing administrative privileges.
By limiting access to sensitive metadata based on user responsibilities, this enhancement supports least-privilege security practices and helps organizations better protect internal user and infrastructure information.
Enhanced PyPI Repository Compatibility
Sonatype Nexus Repository now supports PEP 658 inline metadata and the PEP 691 JSON-based Simple API for hosted and proxy PyPI repositories. These standards improve interoperability with modern Python package management tools while preserving compatibility with existing clients that use the traditional PEP 503 HTML-based Simple API.
With more efficient access to package metadata, Python clients can resolve dependencies without downloading unnecessary package artifacts, reducing bandwidth usage and improving performance for developer workflows and CI/CD pipelines. This enhancement helps organizations deliver a PyPI experience that more closely aligns with modern Python ecosystem standards while maintaining support for existing package consumers.
Note that PEP 658 metadata and PEP 691 JSON support are available automatically in Nexus Repository 3.93.0 and later. Compatible Python clients include pip 23.1+, uv 0.1.0+, and Poetry 1.8+.
New Endpoints in Security management: user roles API
Sonatype Nexus Repository now includes additional endpoints in the Security management: user roles API that allow administrators to programmatically view and manage user role assignments in cloud deployments. Administrators can retrieve existing role assignments, replace assigned roles, add new roles, or remove existing roles through the API. These enhancements provide greater flexibility for organizations that automate user provisioning and access management workflows.
IP Allow List
The IP Allow List feature is now available in Sonatype Nexus Repository Pro and Cloud editions. This feature allows administrators to restrict access to Nexus Repository based on source IP addresses and network ranges, providing an additional layer of protection for deployments with network security requirements. Existing IP Allow List configurations are preserved during upgrade.
OAuth2/OIDC Configuration REST API
Sonatype Nexus Repository now provides public API support for managing OAuth2 and OpenID Connect (OIDC) configuration. Administrators can retrieve, update, and remove OAuth2 settings through REST APIs, enabling programmatic management of authentication configuration and reducing the need to perform these tasks through the user interface.
Improved Protection for Proxy Repository Credentials
Sonatype Nexus Repository now applies additional validation when updating proxy repository connection settings. As part of this update, administrators may be prompted to provide authentication credentials when modifying proxy repository connection details. This change strengthens protection for upstream credentials and supports more secure management of authenticated proxy repositories.
Refreshed Artifact Upload User Interface
Sonatype Nexus Repository includes an updated artifact upload UI with improved visual consistency and usability. The refreshed experience introduces a more cohesive layout, addresses several visual presentation issues, and aligns the upload workflow with the design patterns used throughout the application.
Expanded Enterprise Deployment Options for Kubernetes
Sonatype Nexus Repository now supports the enterprise Kubernetes deployment capabilities introduced in Helm chart 93.0.0 and later. These enhancements add support for ephemeral storage for transient log and support files, Horizontal Pod Autoscaler (HPA) for clustered high-availability deployments, and Azure Workload Identity with External Secrets Operator for Azure Key Vault integration.
These capabilities give DevOps and platform teams greater flexibility when deploying Nexus Repository in Kubernetes. They can reduce persistent storage requirements for temporary data, automatically scale clustered deployments based on workload demand, and simplify secure secret management using Azure-native identity services. Ephemeral storage is intended for environments that forward logs externally because transient data is not retained when pods restart or are rescheduled.
Authentication Attempt Rate Limits For Added Protection
Sonatype Nexus Repository now includes authentication rate limiting to help protect against brute force login attempts. After three consecutive failed authentication attempts, login requests to both the user interface and API authentication endpoints are temporarily rate limited, reducing the risk of automated credential-guessing attacks.
Administrators can configure this behavior using the nexus.auth.ratelimit.* properties to align authentication controls with their organization's security requirements.
Bug Fixes
3.93.2 Bug Fixes
| Issue ID | Description |
|---|---|
| NEXUS-53512 | Users with multi-action application privileges can now access authorized resources correctly, preventing incorrect 403 responses during permission checks. |
3.93.1 Bug Fixes
| Issue ID | Description |
|---|---|
| NEXUS-53214 | Ansible Galaxy hosted repositories configured with Disable RIQ Redeploy now allow publishing new collection versions while continuing to block redeployment of existing versions. |
| NEXUS-53183 | Collection installations from Ansible Galaxy hosted repositories now correctly resolve dependencies and complete successfully. |
| NEXUS-53062 | Chained PyPI proxy repositories now successfully retrieve packages from upstream Nexus Repository instances that redirect artifact requests to S3 presigned URLs by removing the Authorization header before following cross-host redirects. |
| NEXUS-52551 | Chained PyPI proxy repositories now generate correct outbound package download URLs for .whl files without duplicating repository path segments. |
| NEXUS-53281 | Firewall quarantine requests now omit unsupported fields when communicating with IQ Server versions earlier than 204, maintaining compatibility with older releases. |
| NEXUS-53184 | NuGet V2 FindPackagesById() now returns only exact package ID matches, preventing partial-name matches from appearing in search results. |
3.93.0 Bug Fixes
| Issue ID | Description |
|---|---|
| NEXUS-52536 | Docker GC tasks now evaluate all unreferenced blob assets across every page, ensuring unused layers beyond the first 100 are correctly identified and reclaimed during cleanup runs. |
| NEXUS-52906 | PyPI proxy and group repositories now return correctly resolved package download URLs when clients access the PEP 691 JSON Simple API without a trailing slash. |
| NEXUS-52921 | Swift proxy repositories now strip leading "v" and "V" prefixes from Git tags when building the registry version list, so SwiftPM resolves dependencies like 5.3.0 correctly instead of encountering a mismatch with v5.3.0. |
| NEXUS-52812 | Outbound TLS connections in FIPS mode now succeed on Java 21, with the SSL layer explicitly enforcing TLSv1.2 and JKS keystore type to ensure compatibility with the BouncyCastle FIPS provider. |
| NEXUS-52690 | The Google Cloud Storage blobstore now bundles io.opentelemetry:opentelemetry-api version 1.61.0, resolving CVE-2026-45292 (CWE-770, resource allocation without limits). |
| NEXUS-52659 | Anonymous Docker pulls through a group repository now succeed when member repositories have "Allow Anonymous Docker Pulls" disabled, with the group-level anonymous access setting governing requests routed through the group. |
| NEXUS-52631 | UI Branding headers and footers now correctly preserve <style> block rules when the provided HTML uses a full document structure, restoring layout behavior such as flexbox-based horizontal arrangements to match pre-3.92.1 behavior. |
| NEXUS-52584 | npm group repositories now reflect newly published versions in the latest tag immediately, without waiting for the 24-hour metadata cache to expire. |
| NEXUS-52583 | UI login permission checks for users with large role sets now complete in a fraction of the previous time, eliminating the extended "Loading Permissions" screen that blocked access for up to 20 seconds. |
| NEXUS-52567 | Nexus Repository Server startup completes successfully when the malware risk feature flag (nexus.malware.risk.enabled=false) is disabled, with malware components now correctly gated behind the feature flag. |
| NEXUS-52475 | Pre-signed URL generation for S3 blobstores with explicitly configured access key credentials now uses those credentials correctly, rather than falling back to environment-level credentials. |
| NEXUS-52414 | Wildcard name searches containing path separators (such as /EUCLID/*Euclid_Develop*26_99_0*) now return matching components correctly in PostgreSQL-backed deployments. |
| NEXUS-52412 | Swift proxy repositories now successfully fetch package releases through authenticated corporate HTTP proxies, with JGit's lsRemote replaced by a direct Git Smart HTTP implementation that routes through Nexus's existing HTTP client infrastructure. |
| NEXUS-52384 | Swift proxy repositories now fetch the correct version-specific manifest file (Package@swift-X.Y.swift) when a swift-version query parameter is provided, and return an HTTP 303 redirect to the base Package.swift when no version-specific manifest exists upstream. |
| NEXUS-52382 | Azure Blob Store downloads now stream data with bounded backpressure, preventing heap memory exhaustion when clients consume blobs slower than Azure delivers them. |
| NEXUS-52362 | Maven group repositories now respect the minimum metadataMaxAge of their proxy members, ensuring cached merged maven-metadata.xml is revalidated against upstream sources instead of being served indefinitely. |
| NEXUS-52353 | CocoaPods proxy repositories now perform a full recursive git clone for pods declaring "submodules": true, delivering complete archives with all submodule content instead of the incomplete tarballs previously returned by the GitHub archive API. |
| NEXUS-52333 | When a Helm proxy repository's index.yaml cannot be parsed, the error log now includes the full exception stack trace and filename, making the root cause immediately visible without requiring DEBUG-level logging. |
| NEXUS-52266 | The Compact blob store task now honors the rebuildDeletedBlobIndex flag for S3 blob stores, rebuilding the deleted blob index and removing the flag from metadata.properties upon completion. |
| NEXUS-52224 | Nexus Repository startup logs no longer include the full nexus.properties map, preventing database credentials and other sensitive configuration values from appearing in plaintext during bootstrap. |
| NEXUS-52199 | Yum hosted repository metadata rebuild tasks now use a direct indexed key lookup to check RPM registration status, replacing a repeated full-category scan that could cause rebuild operations to run for days on large repositories. |
| NEXUS-52197 | Verbose PE binary parsing diagnostics from the PortEx library are now suppressed during Firewall scanning of Docker proxy repositories, keeping nexus.log free of excessive PELoader INFO entries when pulling Windows-based images. |
| NEXUS-51975 | Cleanup policy asset name regex patterns containing the + quantifier are now preserved correctly during preview and policy creation, returning accurate results without requiring workarounds like [0-9][0-9]*. |
| NEXUS-51890 | H2-to-PostgreSQL database migration now handles Docker foreign layer data correctly, generating new UUIDs during migration to bridge the INTEGER-to-UUID type difference between the two database schemas. |
| NEXUS-51884 | NPM proxy repository ETags now update correctly when quarantined components are released via a Firewall policy waiver, ensuring downstream clients and chained proxy instances receive refreshed metadata rather than stale cached responses. |
| NEXUS-51880 | The "Repair - Recalculate Blob Store Storage" task is no longer visible in Sonatype Repository Firewall SaaS instances, where blob storage is managed automatically by Sonatype. |
| NEXUS-51700 | NuGet v2 Search() requests against group repositories now execute filtering, sorting, and pagination at the database level, eliminating the full asset table scans that caused response times of several minutes under concurrent load. |
| NEXUS-51672 | Heap memory warnings are now triggered only after sustained high usage across multiple consecutive samples, preventing false alarms during normal GC sawtooth activity on busy instances. |
| NEXUS-51521 | Docker push operations to S3-backed hosted repositories complete successfully, with AWS SDK v2 checksum settings now configured programmatically to prevent stream closure errors during multipart uploads. |
| NEXUS-51514 | The S3 compact blob store task now logs a warning and continues processing remaining blobs when an individual blob deletion fails, rather than halting the entire compaction run. |
| NEXUS-50997 | Routing rule updates and deletions made on one High Availability node are now propagated to all other nodes in the cluster immediately, keeping routing behavior consistent across the deployment. |
| NEXUS-50972 | PyPI simple index pages are updated correctly when packages are removed through cleanup policies, preventing stale entries from appearing with broken links. |
| NEXUS-50965 | Proxy repository HTTP connection pools are pre-warmed at startup, so Maven, npm, NuGet, PyPI, Swift, and Terraform asset requests succeed on the first attempt without requiring client-side retries. |
| NEXUS-50780 | PyPI proxy and hosted repository package links resolve correctly whether the simple index URL is requested with or without a trailing slash. |
| NEXUS-50778 | APT snapshots now include i18n/Translation-* metadata files, allowing Debian and Ubuntu clients to run apt update against snapshot repositories without encountering 404 errors. |
| NEXUS-50731 | OAuth2/OIDC configuration is now accessible through a public REST API, allowing developers to retrieve, update, and delete OAuth2 settings programmatically via GET, PUT, and DELETE requests to /service/rest/v1/security/oauth2. |
| NEXUS-50643 | Authentication attempts across all Nexus endpoints are now subject to exponential backoff rate limiting, returning HTTP 429 with a Retry-After header after three consecutive failures, with API and token-based authentication always enforced and UI login rate limiting applied only when SSO is not configured. |
| NEXUS-48928 | PyPI hosted and proxy repositories now serve package metadata inline (PEP 658) and respond to JSON Simple API requests (PEP 691), enabling faster dependency resolution with pip, Poetry, and uv while remaining backward compatible with HTML-based clients. |
| NEXUS-47909 | Maven group repositories now serve archetype-catalog.xml hash files (.sha1, .md5, .sha256, .sha512) successfully instead of returning a 500 error. |
| NEXUS-39223 | RubyGems group repositories now merge duplicate gem entries from hosted and proxy members into a single /versions row with a unified version list and correctly recomputed checksum, allowing Bundler to resolve all available versions without errors. |
| NEXUS-22160 | YUM hosted repositories now support modules.yaml, enabling offline mirroring of RHEL 8+ and CentOS 8+ modular package repositories. |
Known Issues & Upgrade Guidance
This section captures known issues in the 3.93.x line as well as upgrade guidance.
Resolved Known Issues
| Impacted Version(s) | Version in which Issue is Resolved | Description |
|---|---|---|
| 3.93.0 - 3.93.2 | 3.94.0 | Sonatype is aware of an issue impacting users of PyPI group repositories in Sonatype Nexus Repository 3.93.x who override packages from PyPI by uploading a patched package with the same version to a hosted repository. When a PyPI group repository merges metadata from hosted and proxy repositories, the package hash advertised in the metadata can reference the upstream package instead of the hosted package. pip 26 validates the metadata hash and reports a checksum mismatch, preventing installation of the patched package even though the hosted artifact is served correctly. This issue is resolved in 3.94.0. However, if you are unable to upgrade to 3.94.0, a partial workaround is to publish the patched package using a new version instead of replacing an existing upstream version. |
| 3.93.0 – 3.93.1 | 3.93.2 | When a role includes an application privilege that grants multiple actions (for example, Create + Read or Update + Read), Nexus Repository may incorrectly deny access to operations that require one of the granted actions. This issue affects built-in and custom application privileges that combine multiple actions in a single permission and may result in unexpected HTTP 403 responses, even when the user has been assigned the required privilege. The issue is most likely to affect users assigned roles containing multi-action application privileges, such as User Token settings, security administration, blob store creation, user management, or custom privileges configured with more than one action. |
| 3.93.0 | 3.93.1 | When a NuGet V2 client calls FindPackagesById() with a package ID, Nexus Repository may return packages whose IDs partially match the requested value, even when the request does not include a wildcard. For example, a request for Project may also return packages such as Project-main. This issue is most likely to affect repositories where multiple NuGet packages have IDs that share a common prefix or tokenized package ID. |
| 3.91.x – 3.93.0 | 3.93.1 | When a PyPI proxy repository points to a remote repository that returns relative links for Python wheel files, Nexus Repository may incorrectly resolve those links when constructing the upstream download request. This can result in invalid upstream URLs and HTTP 404 responses returned to Python clients. This issue is known to affect chained PyPI proxy configurations where one Nexus Repository instance proxies another Nexus Repository instance. PyPI proxy repositories configured to proxy PyPI.org directly are not known to be affected. |
| 3.93.0 and IQ 203.x | IQ 204 | When Sonatype Nexus Repository 3.93.0 is used with IQ Server 203.x or earlier, Nexus Firewall functionality may not operate correctly. This may result in failed client requests to Firewall-enabled repositories and potential service disruption. To avoid this issue, upgrade IQ Server to version 204 or later before upgrading to Sonatype Nexus Repository 3.93.0. |