Sonatype Nexus Repository 3.94.0 Release Notes

Sonatype Nexus Repository 3.94.0 Release Notes

The Sonatype Nexus Repository 3.94.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!

Released July 9, 2026

What’s New and Noteworthy in This Release?

Repository Firewall: Support for conda-forge Upstreams

Sonatype Repository Firewall now supports conda-forge as an upstream for conda proxy repositories. You can configure a conda proxy repository to use the conda-forge upstream and apply Repository Firewall policies to packages retrieved from that source, expanding protection to one of the most widely used community-managed conda repositories.

Support for Open Container Initiative (OCI) Repositories

Sonatype Nexus Repository now supports native Open Container Initiative (OCI) hosted, proxy, and group repositories, giving you a single solution for managing container images and other OCI artifacts throughout your software supply chain. You can proxy content from external OCI registries, publish and protect internally developed artifacts, and expose multiple repositories through a single endpoint to simplify client configuration and artifact management.

For full details, see the OCI Repositories help documentation.

Proxy Private Amazon Elastic Container Registry (ECR) Registries with Docker Repositories

Sonatype Nexus Repository now supports proxying private Amazon ECR registries through Docker proxy repositories. You can configure a Docker proxy repository by providing your AWS account's ECR registry URL along with AWS IAM credentials, allowing Nexus Repository to centrally cache and serve container images stored in private ECR registries.

For full details, see the Proxy Repository for Docker help documentation.

PyPI Simple API v1.1 Support for Faster Dependency Resolution

Sonatype Nexus Repository now supports Simple API v1.1 (PEP 700) for PyPI repositories, enabling modern Python clients such as pip and uv to access richer package metadata. With this additional metadata, clients can make more informed dependency resolution decisions, reducing the number of requests and improving overall performance when installing packages.

Java EE 10 Upgrade for Modernized Platform Infrastructure

Sonatype Nexus Repository now uses Java EE 10, modernizing the underlying servlet infrastructure and aligning core components with current standards. This update includes upgrades to key dependencies such as Jetty, RESTEasy, and OpenAPI 3, improving platform consistency, maintainability, and long-term compatibility with modern Java ecosystems.

Improved Docker Repository Management Experience

Sonatype Nexus Repository now streamlines Docker repository management with guided connector configuration and enhanced usability. The system suggests appropriate ports during setup, reducing configuration errors and helping you get repositories up and running more quickly.

Simplified URL Encoding Configuration for Proxy Repositories

Sonatype Nexus Repository now centralizes URL encoding behavior for proxy repositories through the Preserve Encoded Characters setting. This update removes ambiguity by making the repository-level configuration the single control point, allowing you to manage how encoded characters are handled without relying on additional global properties.

Updated Defaults for Conan Proxy Repositories

Sonatype Nexus Repository now defaults new Conan proxy repositories to Protocol Version V2, aligning with the latest Conan ecosystem standards.

Enhanced Compatibility for Terraform Proxy Repositories

Terraform proxy repositories now seamlessly proxy content from a wider range of compliant registries, including OpenTofu registries and registry.coder.com.

Immediate Session Invalidation on Password Change

Sonatype Nexus Repository now strengthens account security by immediately invalidating all active sessions when a user’s password is changed.

Stronger API Key Generation with UUID v4

Sonatype Nexus Repository now generates API keys for NuGet, npm, Docker, and Conan formats using UUID v4.

Repository Firewall: New Malware Threat Landscape Dashboard

Sonatype Repository Firewall now includes the Malware Threat Landscape dashboard in Enterprise Reporting, providing organizations with a broader view of malware activity across the open-source ecosystem.

Repository Firewall: Centralized Waiver Request and Management

Sonatype Repository Firewall now includes a complete in-product waiver management workflow that streamlines how policy exceptions are requested, reviewed, approved, and maintained.

Repository Firewall: Waiver Expiration Email Notifications

Sonatype Repository Firewall can now send configurable email notifications before component waivers expire.

Repository Firewall: Expanded Firewall Webhook Events

Sonatype Repository Firewall webhooks now support Violation Alert and Waiver Request events, enabling real-time notifications for repository proxy policies.

Repository Firewall: Repository-Scoped Access to the Firewall Dashboard

The Sonatype Repository Firewall dashboard now supports repository-scoped access, allowing users with read permission on individual proxy repositories to view dashboard data automatically limited to only the repositories they are authorized to access.

Repository Firewall: Improved Quarantine Timeline Visibility

Repository Results tables in Firewall now separate Evaluation Time and Quarantine Time into dedicated columns.

Bug Fixes

Issue ID Description
NEXUS-53700 Nexus Repository startup completes successfully with analytics disabled.
NEXUS-53682 Source RPMs in hosted Yum repositories now carry arch="src" in generated primary.xml metadata.
NEXUS-53492 PyPI group repositories now return the correct package and metadata hashes for locally hosted packages.
NEXUS-53454 Duplicate repository.search.update tasks are now prevented in High Availability deployments.
NEXUS-53449 PyPI group repositories now reflect updated package versions from proxy members automatically.
NEXUS-53396 Conda proxy repositories configured with channel-specific upstream URLs now send the correct package path to Sonatype IQ Server.
NEXUS-53395 Docker image layer extraction on Windows now handles paths containing illegal characters.
NEXUS-53310 Ansible Galaxy proxy repository metadata now rewrites download URLs dynamically.
NEXUS-53297 Package index updates in nested PyPI group repositories propagate automatically.
NEXUS-53266 Sensitive HTTP authentication headers are now automatically redacted from log files.
NEXUS-53242 Downloading models through a HuggingFace proxy repository now produces complete files.
NEXUS-53199 The UI is immediately interactive while permissions load asynchronously.
NEXUS-53184 NuGet V2 FindPackagesById() returns only exact package ID matches.
NEXUS-53173 PyPI proxy, hosted, and group repositories now return Simple API v1.1 responses.
NEXUS-53059 Frontend dependencies are updated to versions that resolve severity vulnerabilities.
NEXUS-53007 Rate-limit buckets for NuGet API key authentication are now isolated per token.
NEXUS-52998 Nexus Repository now starts cleanly when a Default Role capability references a nonexistent role.
NEXUS-52973 NuGet v2 proxy repositories now serve cached package results immediately.
NEXUS-52961 Support zip exports now include an oauth2UserExport.json file.
NEXUS-52912 Telemetry components load conditionally based on configuration.
NEXUS-52859 PyPI proxy, hosted, and group repositories now serve PEP 691/700-compliant JSON responses.
NEXUS-52856 Keyword-only searches now display the group repository name for users whose access is granted through a group.
NEXUS-52855 The Repair - Rebuild Maven repository metadata task skips certain repositories gracefully.
NEXUS-52846 Logging out of Nexus instances configured with Okta OIDC now completes successfully.
NEXUS-52831 Authentication rate limiting now blocks requests before credentials are evaluated.
NEXUS-52827 Clicking the Repository column header now sorts correctly across all repository formats.
NEXUS-52813 PyPI hosted repositories now correctly reflect newly uploaded packages in the per-package simple index.
NEXUS-52799 Downloading macOS universal (fat) binary artifacts succeeds with strict content type validation enabled.
NEXUS-52769 Raw proxy repositories now forward upstream redirect URLs byte-for-byte.
NEXUS-52759 Groovy scripts now execute under Groovy 5.0.6 with stricter sandbox security semantics.
NEXUS-52625 YUM/RPM repository components are now partially indexed.
NEXUS-52620 Blob store creation and modification through the UI complete successfully under HTTPS.
NEXUS-52580 Data Repair Plan recovery correctly preserves asset kind for Terraform versions.json files.
NEXUS-52571 Removing all nexus-managed roles from a user now saves cleanly.
NEXUS-52320 Terraform authentication through a context path now correctly extracts user tokens.
NEXUS-52117 Uploading components to hosted repositories completes successfully.
NEXUS-52107 Logging now includes repository name information for easier diagnosis.
NEXUS-52050 Clicking the Sonatype logo now navigates correctly to the landing page.
NEXUS-52006 The lastDownloaded timestamp update now uses a conditional database operation.
NEXUS-51920 Terraform hosted repositories now correctly upload and download modules with SemVer pre-release versions.
NEXUS-51877 Search index rebuild tasks skip empty component batches gracefully.
NEXUS-51835 Azure blob store initialization failures now log the root cause exception.
NEXUS-51662 Multi-term search queries now respect term order and position when enabled.
NEXUS-51660 Embedded wildcard patterns now return matching components.
NEXUS-51643 Helm hosted repositories now return a JSON 409 Conflict response when a chart push is rejected.
NEXUS-51593 Content selector privileges created via the REST API now display correct values in UI.
NEXUS-51522 Mixed-case Docker repository names are fully editable via the REST API.
NEXUS-51449 The Repository Health Check column is no longer displayed in the Browse view for Firewall customers.
NEXUS-50725 Startup log messages for the Job Key Unification task are now accurate.
NEXUS-50701 SSRF validation now defers to the configured global HTTP/HTTPS proxy.
NEXUS-41851 Logger override configurations are now exported to the support zip in High Availability deployments.
NEXUS-27554 The NuGet API Token section in user profiles is now hidden when the NuGet API-Key realm is disabled.

Coming Soon

Groovy Scripting Support Reaches End of Life in December 2026

Groovy scripting support in Sonatype Nexus Repository will reach end of life in December 2026.

Blob Store Names Cannot Contain HTML Special Characters

Beginning with self-hosted release 3.95.0 (expected August 2026), blob store names cannot contain HTML special characters.

Nexus One UI as Default

The Nexus One UI will soon become the default interface in Sonatype Nexus Repository.