Sonatype Nexus Repository 3.94.0 Release Notes
Sonatype Nexus Repository 3.94.0 Release Notes
The Sonatype Nexus Repository 3.94.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!
Released July 9, 2026
What’s New and Noteworthy in This Release?
Repository Firewall: Support for conda-forge Upstreams
Sonatype Repository Firewall now supports conda-forge as an upstream for conda proxy repositories. You can configure a conda proxy repository to use the conda-forge upstream and apply Repository Firewall policies to packages retrieved from that source, expanding protection to one of the most widely used community-managed conda repositories.
Support for Open Container Initiative (OCI) Repositories
Sonatype Nexus Repository now supports native Open Container Initiative (OCI) hosted, proxy, and group repositories, giving you a single solution for managing container images and other OCI artifacts throughout your software supply chain. You can proxy content from external OCI registries, publish and protect internally developed artifacts, and expose multiple repositories through a single endpoint to simplify client configuration and artifact management.
For full details, see the OCI Repositories help documentation.
Proxy Private Amazon Elastic Container Registry (ECR) Registries with Docker Repositories
Sonatype Nexus Repository now supports proxying private Amazon ECR registries through Docker proxy repositories. You can configure a Docker proxy repository by providing your AWS account's ECR registry URL along with AWS IAM credentials, allowing Nexus Repository to centrally cache and serve container images stored in private ECR registries.
For full details, see the Proxy Repository for Docker help documentation.
PyPI Simple API v1.1 Support for Faster Dependency Resolution
Sonatype Nexus Repository now supports Simple API v1.1 (PEP 700) for PyPI repositories, enabling modern Python clients such as pip and uv to access richer package metadata. With this additional metadata, clients can make more informed dependency resolution decisions, reducing the number of requests and improving overall performance when installing packages.
Java EE 10 Upgrade for Modernized Platform Infrastructure
Sonatype Nexus Repository now uses Java EE 10, modernizing the underlying servlet infrastructure and aligning core components with current standards. This update includes upgrades to key dependencies such as Jetty, RESTEasy, and OpenAPI 3, improving platform consistency, maintainability, and long-term compatibility with modern Java ecosystems.
Improved Docker Repository Management Experience
Sonatype Nexus Repository now streamlines Docker repository management with guided connector configuration and enhanced usability. The system suggests appropriate ports during setup, reducing configuration errors and helping you get repositories up and running more quickly.
Simplified URL Encoding Configuration for Proxy Repositories
Sonatype Nexus Repository now centralizes URL encoding behavior for proxy repositories through the Preserve Encoded Characters setting. This update removes ambiguity by making the repository-level configuration the single control point, allowing you to manage how encoded characters are handled without relying on additional global properties.
Updated Defaults for Conan Proxy Repositories
Sonatype Nexus Repository now defaults new Conan proxy repositories to Protocol Version V2, aligning with the latest Conan ecosystem standards.
Enhanced Compatibility for Terraform Proxy Repositories
Terraform proxy repositories now seamlessly proxy content from a wider range of compliant registries, including OpenTofu registries and registry.coder.com.
Immediate Session Invalidation on Password Change
Sonatype Nexus Repository now strengthens account security by immediately invalidating all active sessions when a user’s password is changed.
Stronger API Key Generation with UUID v4
Sonatype Nexus Repository now generates API keys for NuGet, npm, Docker, and Conan formats using UUID v4.
Repository Firewall: New Malware Threat Landscape Dashboard
Sonatype Repository Firewall now includes the Malware Threat Landscape dashboard in Enterprise Reporting, providing organizations with a broader view of malware activity across the open-source ecosystem.
Repository Firewall: Centralized Waiver Request and Management
Sonatype Repository Firewall now includes a complete in-product waiver management workflow that streamlines how policy exceptions are requested, reviewed, approved, and maintained.
Repository Firewall: Waiver Expiration Email Notifications
Sonatype Repository Firewall can now send configurable email notifications before component waivers expire.
Repository Firewall: Expanded Firewall Webhook Events
Sonatype Repository Firewall webhooks now support Violation Alert and Waiver Request events, enabling real-time notifications for repository proxy policies.
Repository Firewall: Repository-Scoped Access to the Firewall Dashboard
The Sonatype Repository Firewall dashboard now supports repository-scoped access, allowing users with read permission on individual proxy repositories to view dashboard data automatically limited to only the repositories they are authorized to access.
Repository Firewall: Improved Quarantine Timeline Visibility
Repository Results tables in Firewall now separate Evaluation Time and Quarantine Time into dedicated columns.
Bug Fixes
| Issue ID | Description |
|---|---|
| NEXUS-53700 | Nexus Repository startup completes successfully with analytics disabled. |
| NEXUS-53682 | Source RPMs in hosted Yum repositories now carry arch="src" in generated primary.xml metadata. |
| NEXUS-53492 | PyPI group repositories now return the correct package and metadata hashes for locally hosted packages. |
| NEXUS-53454 | Duplicate repository.search.update tasks are now prevented in High Availability deployments. |
| NEXUS-53449 | PyPI group repositories now reflect updated package versions from proxy members automatically. |
| NEXUS-53396 | Conda proxy repositories configured with channel-specific upstream URLs now send the correct package path to Sonatype IQ Server. |
| NEXUS-53395 | Docker image layer extraction on Windows now handles paths containing illegal characters. |
| NEXUS-53310 | Ansible Galaxy proxy repository metadata now rewrites download URLs dynamically. |
| NEXUS-53297 | Package index updates in nested PyPI group repositories propagate automatically. |
| NEXUS-53266 | Sensitive HTTP authentication headers are now automatically redacted from log files. |
| NEXUS-53242 | Downloading models through a HuggingFace proxy repository now produces complete files. |
| NEXUS-53199 | The UI is immediately interactive while permissions load asynchronously. |
| NEXUS-53184 | NuGet V2 FindPackagesById() returns only exact package ID matches. |
| NEXUS-53173 | PyPI proxy, hosted, and group repositories now return Simple API v1.1 responses. |
| NEXUS-53059 | Frontend dependencies are updated to versions that resolve severity vulnerabilities. |
| NEXUS-53007 | Rate-limit buckets for NuGet API key authentication are now isolated per token. |
| NEXUS-52998 | Nexus Repository now starts cleanly when a Default Role capability references a nonexistent role. |
| NEXUS-52973 | NuGet v2 proxy repositories now serve cached package results immediately. |
| NEXUS-52961 | Support zip exports now include an oauth2UserExport.json file. |
| NEXUS-52912 | Telemetry components load conditionally based on configuration. |
| NEXUS-52859 | PyPI proxy, hosted, and group repositories now serve PEP 691/700-compliant JSON responses. |
| NEXUS-52856 | Keyword-only searches now display the group repository name for users whose access is granted through a group. |
| NEXUS-52855 | The Repair - Rebuild Maven repository metadata task skips certain repositories gracefully. |
| NEXUS-52846 | Logging out of Nexus instances configured with Okta OIDC now completes successfully. |
| NEXUS-52831 | Authentication rate limiting now blocks requests before credentials are evaluated. |
| NEXUS-52827 | Clicking the Repository column header now sorts correctly across all repository formats. |
| NEXUS-52813 | PyPI hosted repositories now correctly reflect newly uploaded packages in the per-package simple index. |
| NEXUS-52799 | Downloading macOS universal (fat) binary artifacts succeeds with strict content type validation enabled. |
| NEXUS-52769 | Raw proxy repositories now forward upstream redirect URLs byte-for-byte. |
| NEXUS-52759 | Groovy scripts now execute under Groovy 5.0.6 with stricter sandbox security semantics. |
| NEXUS-52625 | YUM/RPM repository components are now partially indexed. |
| NEXUS-52620 | Blob store creation and modification through the UI complete successfully under HTTPS. |
| NEXUS-52580 | Data Repair Plan recovery correctly preserves asset kind for Terraform versions.json files. |
| NEXUS-52571 | Removing all nexus-managed roles from a user now saves cleanly. |
| NEXUS-52320 | Terraform authentication through a context path now correctly extracts user tokens. |
| NEXUS-52117 | Uploading components to hosted repositories completes successfully. |
| NEXUS-52107 | Logging now includes repository name information for easier diagnosis. |
| NEXUS-52050 | Clicking the Sonatype logo now navigates correctly to the landing page. |
| NEXUS-52006 | The lastDownloaded timestamp update now uses a conditional database operation. |
| NEXUS-51920 | Terraform hosted repositories now correctly upload and download modules with SemVer pre-release versions. |
| NEXUS-51877 | Search index rebuild tasks skip empty component batches gracefully. |
| NEXUS-51835 | Azure blob store initialization failures now log the root cause exception. |
| NEXUS-51662 | Multi-term search queries now respect term order and position when enabled. |
| NEXUS-51660 | Embedded wildcard patterns now return matching components. |
| NEXUS-51643 | Helm hosted repositories now return a JSON 409 Conflict response when a chart push is rejected. |
| NEXUS-51593 | Content selector privileges created via the REST API now display correct values in UI. |
| NEXUS-51522 | Mixed-case Docker repository names are fully editable via the REST API. |
| NEXUS-51449 | The Repository Health Check column is no longer displayed in the Browse view for Firewall customers. |
| NEXUS-50725 | Startup log messages for the Job Key Unification task are now accurate. |
| NEXUS-50701 | SSRF validation now defers to the configured global HTTP/HTTPS proxy. |
| NEXUS-41851 | Logger override configurations are now exported to the support zip in High Availability deployments. |
| NEXUS-27554 | The NuGet API Token section in user profiles is now hidden when the NuGet API-Key realm is disabled. |
Coming Soon
Groovy Scripting Support Reaches End of Life in December 2026
Groovy scripting support in Sonatype Nexus Repository will reach end of life in December 2026.
Blob Store Names Cannot Contain HTML Special Characters
Beginning with self-hosted release 3.95.0 (expected August 2026), blob store names cannot contain HTML special characters.
Nexus One UI as Default
The Nexus One UI will soon become the default interface in Sonatype Nexus Repository.