# Sonatype Nexus Repository 3.94.0 Release Notes

The Sonatype Nexus Repository 3.94.x release line includes exciting new features, enhancements, and bug fixes. Learn more in the sections below!

**Released July 9, 2026**

## What’s New and Noteworthy in This Release?

### Repository Firewall: Support for conda-forge Upstreams

Sonatype Repository Firewall now supports conda-forge as an upstream for conda proxy repositories. You can configure a conda proxy repository to use the conda-forge upstream and apply Repository Firewall policies to packages retrieved from that source, expanding protection to one of the most widely used community-managed conda repositories.

### Support for Open Container Initiative (OCI) Repositories

Sonatype Nexus Repository now supports native Open Container Initiative (OCI) hosted, proxy, and group repositories, giving you a single solution for managing container images and other OCI artifacts throughout your software supply chain. You can proxy content from external OCI registries, publish and protect internally developed artifacts, and expose multiple repositories through a single endpoint to simplify client configuration and artifact management.

For full details, see the [OCI Repositories help documentation](https://help.sonatype.com/en/oci-repositories.html "OCI Repositories").

### Proxy Private Amazon Elastic Container Registry (ECR) Registries with Docker Repositories

Sonatype Nexus Repository now supports proxying private Amazon ECR registries through Docker proxy repositories. You can configure a Docker proxy repository by providing your AWS account's ECR registry URL along with AWS IAM credentials, allowing Nexus Repository to centrally cache and serve container images stored in private ECR registries.

For full details, see the [Proxy Repository for Docker help documentation](https://help.sonatype.com/en/proxy-repository-for-docker.html "Proxy Repository for Docker").

### PyPI Simple API v1.1 Support for Faster Dependency Resolution

Sonatype Nexus Repository now supports Simple API v1.1 (PEP 700) for PyPI repositories, enabling modern Python clients such as `pip` and `uv` to access richer package metadata. With this additional metadata, clients can make more informed dependency resolution decisions, reducing the number of requests and improving overall performance when installing packages.

### Java EE 10 Upgrade for Modernized Platform Infrastructure

Sonatype Nexus Repository now uses Java EE 10, modernizing the underlying servlet infrastructure and aligning core components with current standards. This update includes upgrades to key dependencies such as Jetty, RESTEasy, and OpenAPI 3, improving platform consistency, maintainability, and long-term compatibility with modern Java ecosystems.

### Improved Docker Repository Management Experience

Sonatype Nexus Repository now streamlines Docker repository management with guided connector configuration and enhanced usability. The system suggests appropriate ports during setup, reducing configuration errors and helping you get repositories up and running more quickly.

### Simplified URL Encoding Configuration for Proxy Repositories

Sonatype Nexus Repository now centralizes URL encoding behavior for proxy repositories through the _Preserve Encoded Characters_ setting. This update removes ambiguity by making the repository-level configuration the single control point, allowing you to manage how encoded characters are handled without relying on additional global properties.

### Updated Defaults for Conan Proxy Repositories

Sonatype Nexus Repository now defaults new Conan proxy repositories to Protocol Version V2, aligning with the latest Conan ecosystem standards.

### Enhanced Compatibility for Terraform Proxy Repositories

Terraform proxy repositories now seamlessly proxy content from a wider range of compliant registries, including OpenTofu registries and `registry.coder.com`.

### Immediate Session Invalidation on Password Change

Sonatype Nexus Repository now strengthens account security by immediately invalidating all active sessions when a user’s password is changed.

### Stronger API Key Generation with UUID v4

Sonatype Nexus Repository now generates API keys for NuGet, npm, Docker, and Conan formats using UUID v4.

### Repository Firewall: New Malware Threat Landscape Dashboard

Sonatype Repository Firewall now includes the _Malware Threat Landscape_ dashboard in Enterprise Reporting, providing organizations with a broader view of malware activity across the open-source ecosystem.

|     |
| --- |
|  |

### Repository Firewall: Centralized Waiver Request and Management

Sonatype Repository Firewall now includes a complete in-product waiver management workflow that streamlines how policy exceptions are requested, reviewed, approved, and maintained.

### Repository Firewall: Waiver Expiration Email Notifications

Sonatype Repository Firewall can now send configurable email notifications before component waivers expire.

### Repository Firewall: Expanded Firewall Webhook Events

Sonatype Repository Firewall webhooks now support _Violation Alert_ and _Waiver Request_ events, enabling real-time notifications for repository proxy policies.

### Repository Firewall: Repository-Scoped Access to the Firewall Dashboard

The Sonatype Repository Firewall dashboard now supports repository-scoped access, allowing users with `read` permission on individual proxy repositories to view dashboard data automatically limited to only the repositories they are authorized to access.

### Repository Firewall: Improved Quarantine Timeline Visibility

_Repository Results_ tables in Firewall now separate _Evaluation Time_ and _Quarantine Time_ into dedicated columns.

## Bug Fixes

| Issue ID | Description |
| --- | --- |
| NEXUS-53700 | Nexus Repository startup completes successfully with analytics disabled. |
| NEXUS-53682 | Source RPMs in hosted Yum repositories now carry `arch="src"` in generated `primary.xml` metadata. |
| NEXUS-53492 | PyPI group repositories now return the correct package and metadata hashes for locally hosted packages. |
| NEXUS-53454 | Duplicate `repository.search.update` tasks are now prevented in High Availability deployments. |
| NEXUS-53449 | PyPI group repositories now reflect updated package versions from proxy members automatically. |
| NEXUS-53396 | Conda proxy repositories configured with channel-specific upstream URLs now send the correct package path to Sonatype IQ Server. |
| NEXUS-53395 | Docker image layer extraction on Windows now handles paths containing illegal characters. |
| NEXUS-53310 | Ansible Galaxy proxy repository metadata now rewrites download URLs dynamically. |
| NEXUS-53297 | Package index updates in nested PyPI group repositories propagate automatically. |
| NEXUS-53266 | Sensitive HTTP authentication headers are now automatically redacted from log files. |
| NEXUS-53242 | Downloading models through a HuggingFace proxy repository now produces complete files. |
| NEXUS-53199 | The UI is immediately interactive while permissions load asynchronously. |
| NEXUS-53184 | NuGet V2 `FindPackagesById()` returns only exact package ID matches. |
| NEXUS-53173 | PyPI proxy, hosted, and group repositories now return Simple API v1.1 responses. |
| NEXUS-53059 | Frontend dependencies are updated to versions that resolve severity vulnerabilities. |
| NEXUS-53007 | Rate-limit buckets for NuGet API key authentication are now isolated per token. |
| NEXUS-52998 | Nexus Repository now starts cleanly when a Default Role capability references a nonexistent role. |
| NEXUS-52973 | NuGet v2 proxy repositories now serve cached package results immediately. |
| NEXUS-52961 | Support zip exports now include an `oauth2UserExport.json` file.
| NEXUS-52912 | Telemetry components load conditionally based on configuration. |
| NEXUS-52859 | PyPI proxy, hosted, and group repositories now serve PEP 691/700-compliant JSON responses. |
| NEXUS-52856 | Keyword-only searches now display the group repository name for users whose access is granted through a group. |
| NEXUS-52855 | The Repair - Rebuild Maven repository metadata task skips certain repositories gracefully. |
| NEXUS-52846 | Logging out of Nexus instances configured with Okta OIDC now completes successfully. |
| NEXUS-52831 | Authentication rate limiting now blocks requests before credentials are evaluated. |
| NEXUS-52827 | Clicking the Repository column header now sorts correctly across all repository formats. |
| NEXUS-52813 | PyPI hosted repositories now correctly reflect newly uploaded packages in the per-package simple index. |
| NEXUS-52799 | Downloading macOS universal (fat) binary artifacts succeeds with strict content type validation enabled.
| NEXUS-52769 | Raw proxy repositories now forward upstream redirect URLs byte-for-byte.
| NEXUS-52759 | Groovy scripts now execute under Groovy 5.0.6 with stricter sandbox security semantics. |
| NEXUS-52625 | YUM/RPM repository components are now partially indexed. |
| NEXUS-52620 | Blob store creation and modification through the UI complete successfully under HTTPS. |
| NEXUS-52580 | Data Repair Plan recovery correctly preserves asset kind for Terraform `versions.json` files. |
| NEXUS-52571 | Removing all nexus-managed roles from a user now saves cleanly. |
| NEXUS-52320 | Terraform authentication through a context path now correctly extracts user tokens. |
| NEXUS-52117 | Uploading components to hosted repositories completes successfully. |
| NEXUS-52107 | Logging now includes repository name information for easier diagnosis. |
| NEXUS-52050 | Clicking the Sonatype logo now navigates correctly to the landing page. |
| NEXUS-52006 | The `lastDownloaded` timestamp update now uses a conditional database operation. |
| NEXUS-51920 | Terraform hosted repositories now correctly upload and download modules with SemVer pre-release versions.
| NEXUS-51877 | Search index rebuild tasks skip empty component batches gracefully.
| NEXUS-51835 | Azure blob store initialization failures now log the root cause exception.
| NEXUS-51662 | Multi-term search queries now respect term order and position when enabled.
| NEXUS-51660 | Embedded wildcard patterns now return matching components.
| NEXUS-51643 | Helm hosted repositories now return a JSON 409 Conflict response when a chart push is rejected.
| NEXUS-51593 | Content selector privileges created via the REST API now display correct values in UI. |
| NEXUS-51522 | Mixed-case Docker repository names are fully editable via the REST API. |
| NEXUS-51449 | The Repository Health Check column is no longer displayed in the Browse view for Firewall customers. |
| NEXUS-50725 | Startup log messages for the Job Key Unification task are now accurate.
| NEXUS-50701 | SSRF validation now defers to the configured global HTTP/HTTPS proxy.
| NEXUS-41851 | Logger override configurations are now exported to the support zip in High Availability deployments. |
| NEXUS-27554 | The NuGet API Token section in user profiles is now hidden when the NuGet API-Key realm is disabled. |

## Coming Soon

### Groovy Scripting Support Reaches End of Life in December 2026

Groovy scripting support in Sonatype Nexus Repository will reach end of life in **December 2026**.

### Blob Store Names Cannot Contain HTML Special Characters

Beginning with self-hosted release 3.95.0 (expected August 2026), blob store names cannot contain HTML special characters.

### Nexus One UI as Default

The Nexus One UI will soon become the default interface in Sonatype Nexus Repository.
