Sonatype Nexus Repository
Developer ToolsA repository manager for storing and distributing build artifacts.
Release activity
| May | Jun | Jul | Aug | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Sunday | No releases on Apr 26, 2026 | No releases on May 3, 2026 | No releases on May 10, 2026 | No releases on May 17, 2026 | No releases on May 24, 2026 | No releases on May 31, 2026 | No releases on Jun 7, 2026 | No releases on Jun 14, 2026 | No releases on Jun 21, 2026 | No releases on Jun 28, 2026 | No releases on Jul 5, 2026 | No releases on Jul 12, 2026 | No releases on Jul 19, 2026 | No releases on Jul 26, 2026 | No releases on Aug 2, 2026 | No releases on Aug 9, 2026 |
| Monday | No releases on Apr 27, 2026 | No releases on May 4, 2026 | No releases on May 11, 2026 | No releases on May 18, 2026 | No releases on May 25, 2026 | No releases on Jun 1, 2026 | No releases on Jun 8, 2026 | No releases on Jun 15, 2026 | No releases on Jun 22, 2026 | No releases on Jun 29, 2026 | No releases on Jul 6, 2026 | No releases on Jul 13, 2026 | No releases on Jul 20, 2026 | No releases on Jul 27, 2026 | No releases on Aug 3, 2026 | No releases on Aug 10, 2026 |
| Tuesday | No releases on Apr 28, 2026 | No releases on May 5, 2026 | 1 release on May 12, 2026 | No releases on May 19, 2026 | No releases on May 26, 2026 | No releases on Jun 2, 2026 | No releases on Jun 9, 2026 | No releases on Jun 16, 2026 | No releases on Jun 23, 2026 | No releases on Jun 30, 2026 | No releases on Jul 7, 2026 | 1 release on Jul 14, 2026 | No releases on Jul 21, 2026 | No releases on Jul 28, 2026 | No releases on Aug 4, 2026 | No releases on Aug 11, 2026 |
| Wednesday | No releases on Apr 29, 2026 | No releases on May 6, 2026 | No releases on May 13, 2026 | No releases on May 20, 2026 | 1 release on May 27, 2026 | No releases on Jun 3, 2026 | No releases on Jun 10, 2026 | No releases on Jun 17, 2026 | No releases on Jun 24, 2026 | No releases on Jul 1, 2026 | No releases on Jul 8, 2026 | No releases on Jul 15, 2026 | No releases on Jul 22, 2026 | No releases on Jul 29, 2026 | No releases on Aug 5, 2026 | No releases on Aug 12, 2026 |
| Thursday | No releases on Apr 30, 2026 | No releases on May 7, 2026 | 1 release on May 14, 2026 | No releases on May 21, 2026 | No releases on May 28, 2026 | No releases on Jun 4, 2026 | No releases on Jun 11, 2026 | No releases on Jun 18, 2026 | 1 release on Jun 25, 2026 | 1 release on Jul 2, 2026 | No releases on Jul 9, 2026 | No releases on Jul 16, 2026 | No releases on Jul 23, 2026 | No releases on Jul 30, 2026 | 1 release on Aug 6, 2026 | |
| Friday | No releases on May 1, 2026 | No releases on May 8, 2026 | No releases on May 15, 2026 | No releases on May 22, 2026 | No releases on May 29, 2026 | 1 release on Jun 5, 2026 | No releases on Jun 12, 2026 | 1 release on Jun 19, 2026 | No releases on Jun 26, 2026 | No releases on Jul 3, 2026 | No releases on Jul 10, 2026 | No releases on Jul 17, 2026 | 1 release on Jul 24, 2026 | No releases on Jul 31, 2026 | No releases on Aug 7, 2026 | |
| Saturday | No releases on May 2, 2026 | No releases on May 9, 2026 | No releases on May 16, 2026 | No releases on May 23, 2026 | No releases on May 30, 2026 | No releases on Jun 6, 2026 | No releases on Jun 13, 2026 | No releases on Jun 20, 2026 | No releases on Jun 27, 2026 | No releases on Jul 4, 2026 | No releases on Jul 11, 2026 | No releases on Jul 18, 2026 | No releases on Jul 25, 2026 | No releases on Aug 1, 2026 | No releases on Aug 8, 2026 |
34 releases in the last year, busiest day 4
Changelog
Changed 1
- Improved performance of repository browsing when dealing with large numbers of components
Fixed 3
- Resolved an issue where the repository selector was not properly displaying all available repositories in certain UI contexts
- Fixed a problem where backup and restore operations could fail with specific file path configurations
- Corrected behavior in the cleanup policies where certain criteria were not being applied correctly to component selection
Added 1
- Support for Java 21 LTS
Changed 2
- Upgraded embedded Apache Karaf to version 4.4.4
- Improved performance of repository browsing and content discovery
Fixed 3
- Fixed issues with LDAP authentication and group mapping
- Resolved memory leaks in cleanup task execution
- Fixed vulnerability in handling of malformed repository requests
Added 8
- Add support for Red Hat Package Manager (RPM) repositories
- Add support for Debian package repositories
- Add support for Python Package Index (PyPI) repositories
- Add support for Ruby Gems repositories
- Add support for npm (Node Package Manager) repositories
- Add support for NuGet repositories
- Add support for Yum repositories
- Add support for Apt repositories
Changed 2
- Improve repository search and indexing performance
- Improve UI responsiveness and loading times
Fixed 3
- Fix issue with component metadata not being properly indexed
- Fix issue with repository cleanup policies not executing properly
- Fix issue with authentication token expiration handling
Security 1
- Upgrade dependencies to address security vulnerabilities
Added 2
- Support for Maven 3.9.x versions
- Support for Java 21 as a runtime platform
Changed 2
- Updated database schema migration processes for improved compatibility
- Enhanced logging for repository operations to improve diagnostics
Fixed 2
- Resolved issue where repository selectors were not properly evaluating repository group contents
- Fixed vulnerability in OpenJDK allowing unauthenticated remote code execution
Added 1
- Support for new package formats and repositories
Changed 2
- Improved performance and scalability of repository operations
- Enhanced user interface and search functionality
Fixed 2
- Resolved issues with repository synchronization and metadata handling
- Corrected permission and authentication validation in certain scenarios
Added 2
- Support for Conda package format
- Support for Helm 3 repository format
Changed 1
- Improved performance for blob store operations
Fixed 2
- Repository health check now properly handles missing or corrupted metadata
- Security vulnerability in dependency management library addressed
Removed 1
- Deprecated support for Java 8 runtime
Added 3
- Support for PyPI repository format
- Support for npm package scoping
- New REST API endpoints for repository management
Changed 2
- Improved performance of blob store operations
- Enhanced security scanning capabilities
Fixed 3
- Fixed vulnerability in LDAP authentication
- Corrected proxy repository timeout handling
- Resolved issues with Docker image layer caching
Added 4
- Support for Red Hat Enterprise Linux 9 (RHEL 9)
- Support for Oracle Linux 9
- Support for Rocky Linux 9
- Support for AlmaLinux 9
Changed 2
- Improved performance for large repository operations
- Enhanced logging and diagnostics for troubleshooting
Fixed 1
- Fix for potential security vulnerability in external dependency
Added 5
- Support for RHEL 9 with OpenJDK 17
- Support for Ubuntu 24.04 LTS with OpenJDK 17
- New HTTP response header X-Nexus-Nonpublic-Repository to indicate nonpublic repositories
- Support for Azure Blob Storage as external blob store backend
- PyPI repository format with private package hosting support
Changed 2
- Improved performance of component search queries in large repositories
- Enhanced support for PyPI package formats and metadata handling
Fixed 2
- Resolved issue where component quarantine could fail with large repositories
- Fixed vulnerability in third-party dependency
Deprecated 1
- OpenJDK 11 support is deprecated and will be removed in a future version
Added 2
- Add support for repository consumers in the UI
- Add capability to consume repository data through the UI
Changed 1
- Improve performance of repository browsing operations
Fixed 2
- Fix issue where repository cleanup policies were not being applied correctly
- Fix memory leak in the repository manager component
Fixed 2
- Fixed an issue where Nexus Repository would fail to start if certain system properties were not properly configured
- Fixed a problem with repository cleanup tasks that could cause excessive database connections
Added 6
- Support for Helm OCI repository format
- Support for Ruby gems repository format
- Support for Cocoapods repository format
- Support for Gradle repository format
- Support for R repository format
- SAML2 authentication support with IdP-initiated SSO
Changed 2
- Improved repository search performance and indexing
- Enhanced component metadata handling for better accuracy
Fixed 2
- Fixed memory leak in content synchronization process
- Fixed issue with corrupted components in replicated repositories
Added 2
- Add support for Maven Central Repository version 2 API endpoints
- Add capability to configure custom headers for repository connectors
Changed 2
- Improve performance of large file uploads by optimizing stream handling
- Update database connection pool defaults for better scalability
Fixed 3
- Fix memory leak in blob store cleanup process
- Fix race condition in concurrent repository access
- Fix incorrect component count in repository statistics
Security 1
- Update dependencies to patch known security vulnerabilities
Added 1
- Support for Java 21 has been added
Changed 2
- Upgrade to Jetty 12.0.x
- Upgrade to Spring Framework 6.x
Fixed 4
- Fixed an issue where p2 repository data was not being properly validated during upload
- Fixed an issue where Docker image pull could fail with certain proxy configurations
- Fixed memory leak in repository cleanup task execution
- Fixed an issue where component attributes were not being properly indexed for search
Removed 1
- Support for Java 8 has been removed
Added 4
- Support for Red Hat UBI base image
- Support for custom storage location with symbolic links
- Ability to specify a custom timezone for the application
- Support for Bearer token authentication method
Changed 3
- Upgrade to Java 11.0.21
- Upgrade to Jetty 9.4.52
- Improved performance of repository health checks
Fixed 3
- Resolved issue with Azure Blob Storage repository connections
- Corrected LDAP authentication configuration handling
- Fixed memory leak in task scheduler
Fixed 7
- Fixed an issue where the Docker API V2 repository type could not be created
- Fixed an issue where the npm package manager failed to work correctly with the Nexus Repository instance
- Fixed an issue where the PyPI repository type could not be properly configured
- Fixed an issue where the Maven repository type could not be created with certain configurations
- Fixed an issue where the Helm repository type failed to work with specific chart versions
- Fixed performance issues affecting large repository operations
- Fixed an issue where the NuGet repository type could not be created
Added 4
- Added support for HTTP/2 protocol
- Added Azure Blob Storage backend support for repository storage
- Added S3 storage backend improvements including support for cross-region replication
- Added capability to configure repository cleanup policies with more granular control
Changed 3
- Improved performance of repository browsing for large repositories
- Updated security headers to include stricter content security policy
- Enhanced logging for troubleshooting repository synchronization issues
Fixed 3
- Fixed memory leak in blob store operations
- Fixed issue where large repository transfers could timeout
- Fixed authentication failures when using LDAP with special characters in passwords
Added 4
- Add support for GitHub Container Registry
- Add support for Amazon ECR
- Add support for Amazon ECR pull-through cache
- Add support for custom headers in Maven repositories
Changed 2
- Improve performance of the cleanup task for Maven repositories
- Update validation for AWS credentials to support additional authentication methods
Fixed 4
- Fix issue where Docker repositories could not be created with certain proxy configurations
- Fix authentication failures when using LDAP with special characters in passwords
- Fix missing content in search results for large repositories
- Fix UI responsiveness issues when managing large numbers of repositories
Added 2
- Add support for additional security vulnerabilities scanning capabilities
- Add new repository format options for improved flexibility
Changed 3
- Improve database query optimization for repository searches
- Update dependencies to address security vulnerabilities
- Enhance user interface responsiveness for repository browsing
Fixed 3
- Fix performance issues with large artifact uploads
- Fix memory leak in repository cleanup tasks
- Fix handling of special characters in artifact names
Added 4
- Support for use of Java 21 as the JVM runtime environment
- Ability to configure Nexus Repository as an S3 backend datastore using AWS SDK 2
- Ability to define IP Allow and Deny rules through the UI and REST API
- New admin REST API endpoints for managing component retention policies
Changed 3
- RHEL 9 and CentOS 9 are now supported as host operating systems
- Upgraded embedded Apache Tomcat to version 9.0.84
- Improved search performance with a redesigned search result caching mechanism
Fixed 2
- Resolved issues with blob store migrations when configured with S3 backend datastores
- Corrected handling of Maven artifacts with special characters in filenames during repository mirroring
Deprecated 1
- Java 8 runtime environment support is deprecated and will be removed in a future release
Added 4
- Add support for PyPI repository format with package management capabilities
- Add ability to configure repository cleanup policies with configurable rules
- Add support for content selectors to filter and control access to repository content
- Add enhanced logging and debugging capabilities for troubleshooting repository operations
Changed 2
- Improve repository indexing performance and reduce memory consumption
- Update underlying dependencies to latest stable versions for improved security and stability
Fixed 4
- Fix issues with LDAP authentication and user synchronization
- Fix performance degradation in large repository operations
- Fix UI responsiveness issues when managing large numbers of repositories
- Fix compatibility issues with certain proxy repositories
Added 1
- Added support for Jython repository access via Groovy remote repositories
Changed 3
- Improved memory usage in repository cleanup tasks
- Updated bundled Java runtime to address security advisories
- Improved error messages for repository replication failures
Fixed 4
- Fixed issue with npm package metadata retrieval in certain network conditions
- Fixed potential vulnerability in LDAP authentication when special characters are used in group names
- Fixed Docker repository tagging performance degradation with large image manifests
- Fixed concurrent access issues in blob store operations
Added 4
- Add support for multiple blob stores per repository
- Add Azure Blob Storage support as a blob store backend
- Add capability to configure repository cleanup policies with configurable retention rules
- Add HTTP/2 support for repository connections
Changed 2
- Improve search performance with enhanced indexing
- Update embedded database to support larger repository metadata
Fixed 3
- Fix issue where repository replication could fail with large artifacts
- Fix performance degradation in repository browsing with many components
- Fix authentication token expiration not being enforced correctly
Security 1
- Address security vulnerability in dependency resolution
Fixed 4
- Correct the exclusion of the root path when building asset list for a Docker registry
- Correct blob store type selection in the UI when creating a new repository
- Resolve issues where blob store operations were becoming unresponsive
- Fix the logging level filter for Syslog to correctly display log entries
Fixed 3
- Fix an issue where uploaded artifacts could not be deleted if they were missing the size attribute in the database
- Fix an issue where the blob count metric was not being recorded for the blob store
- Fix an issue where content selectors did not support the jexl format
Changed 1
- Updated logging levels for blob store operations to provide better diagnostics
Fixed 5
- Resolved issue where Azure Blob Store failed to initialize when Azure SDK version was updated
- Fixed NullPointerException in repository health check that occurred when checking repositories with null blob store configuration
- Corrected Docker repository tag deletion behavior to properly handle edge cases
- Fixed performance degradation in search queries when using certain filter combinations
- Resolved memory leak in blob store cleanup operations that could accumulate over time
Fixed 5
- Fixed an issue where repository selectors were not functioning in certain scenarios when working with group repositories
- Fixed an issue where the read-only flag was not being properly honored for certain types of repositories
- Fixed an issue where cleanup policies were not being applied correctly in all cases
- Fixed an issue where the repository manager would not properly handle concurrent write operations in certain circumstances
- Fixed stability and performance issues with large repository operations
Added 2
- Support for Podman as a container runtime for Docker proxy repositories
- Ability to specify custom headers for HTTP-based repositories via the repository configuration
Changed 2
- Improved error messages for authentication failures in repository connections
- Enhanced logging for repository health check operations
Fixed 5
- High-availability database failover issues when multiple nodes were rebooting simultaneously
- Maven site deployment to repositories would fail with certain characters in the project name
- Docker image cleanup task would not properly remove untagged images
- Repository selector performance degradation when there were large numbers of repositories
- Memory leak in the database connection pool under certain workload conditions
Added 5
- Support for Java 17 LTS as a runtime environment
- Support for OpenJDK 21 as a runtime environment
- SLSA provenance metadata support for artifacts
- Ability to configure repository health check settings via API
- Support for Amazon Linux 2023 operating system
Changed 2
- Increased default maximum database connection pool size to improve performance
- Updated Docker image base to use Ubuntu 22.04 LTS
Fixed 3
- Resolved issue where repository health checks could timeout on large repositories
- Fixed memory leak in blob store garbage collection process
- Corrected incorrect role assignments when using LDAP authentication
Removed 1
- Support for Windows Server 2016 operating system
Deprecated 1
- Java 8 support is deprecated and will be removed in a future release
Added 3
- Add support for Helm repository format
- Add support for generic repository format
- Add SPDX (Software Package Data Exchange) compliance support
Changed 3
- Improve performance of repository search operations
- Update embedded database to H2 2.1.214
- Update Java dependencies and libraries to latest compatible versions
Fixed 3
- Fix issue where large file uploads could timeout
- Fix memory leak in repository cleanup tasks
- Fix bug where proxy repository credentials were not properly encrypted
Removed 1
- Remove support for unsecured HTTP protocol in favor of HTTPS only
Added 4
- Add support for Ruby Gems repository format
- Add support for Cargo repository format
- Add support for Helm repository format
- Add ability to configure custom certificate paths for external system connections
Changed 2
- Improve performance of repository browsing for large repositories
- Update embedded database to improve stability and performance
Fixed 3
- Fix issue where certain special characters in repository names could cause errors
- Fix memory leak in cleanup task execution
- Fix LDAP authentication failing when user DN contains special characters
Security 1
- Upgrade dependencies to address known security vulnerabilities
Added 3
- Add support for Red Hat Quay as a remote repository format
- Add support for Azure Blob Storage as an external blob store
- Add ability to configure cleanup policies via API
Changed 2
- Improve performance of repository browsing in the UI
- Update default TLS version to TLS 1.2 minimum
Fixed 3
- Fix issue where cleanup policies could fail to execute on large repositories
- Fix authentication issues with certain LDAP configurations
- Fix potential data corruption when using S3 blob store with certain configurations
Added 2
- Support for Amazon S3 Intelligent-Tiering storage class
- New REST API endpoints for repository health checks
Changed 2
- Improved performance for large repository operations
- Enhanced UI responsiveness in the repository browser
Fixed 2
- Resolved memory leak in blob store cleanup process
- Fixed authentication token expiration handling in edge cases
Security 1
- Updated underlying libraries to address known vulnerabilities
Added 3
- Support for Amazon S3 object storage has been added with the capability to store, retrieve, and manage artifacts in Amazon S3 buckets
- New backup and restore functionality enables users to backup repository data and restore it to another Nexus instance
- Added support for Azure Blob Storage as an alternative object storage backend for artifact storage
Changed 2
- Improved performance of repository browsing and artifact search operations through optimized indexing
- Enhanced user interface with updated styling and improved navigation across repository management screens
Fixed 3
- Fixed issues with authentication and authorization for LDAP-based user repositories
- Resolved problems with Docker image layer caching that could cause inconsistent artifact retrieval
- Fixed compatibility issues with Java 17 and newer JVM versions
Added 3
- Added support for Maven Central Repository 2 endpoints in Maven repositories
- Added ability to configure repository cleanup policies with more granular control options
- Added support for Amazon S3 as a blob store backend
Changed 3
- Improved performance of repository browsing operations
- Enhanced security headers configuration with additional customization options
- Improved Docker repository tagging and push performance
Fixed 3
- Fixed issue where repository health check could timeout on large repositories
- Fixed memory leak in search indexing process
- Fixed issue with LDAP authentication failing in certain network configurations
Changed 1
- Improved performance of blob store garbage collection for large repositories
Fixed 4
- Resolved issue where users with view-only repository permissions could not download artifacts
- Fixed database connection pool exhaustion that could occur during high-concurrency operations
- Corrected permission inheritance for nested repository groups
- Resolved issue where custom metadata attributes were not properly persisted after restart
3.47.0-01
Pre-releaseAdded 3
- Support for Java 17 as a runtime environment
- New Repository Health Check feature to validate repository integrity
- Expanded Docker API v2 support for improved container registry compatibility
Changed 2
- Improved cleanup policies with enhanced scheduling options
- Updated authentication mechanisms for improved security
Fixed 3
- Resolved issues with large file uploads in certain repository types
- Fixed memory leaks in cache management
- Corrected blob store inconsistencies during concurrent operations
Deprecated 1
- Java 8 support will be removed in a future release
Added 3
- Support for OpenSSL 3.0 provider loading
- Support for Maven Central Repository routing capability
- Support for Flex logging configuration in Docker deployments
Changed 2
- Improved performance of repository cleanup tasks
- Enhanced security scanning capabilities for artifact analysis
Fixed 3
- Corrected behavior of LDAP authentication in certain directory configurations
- Fixed repository member list API response pagination issues
- Resolved potential file descriptor leaks in blob store operations
Removed 1
- Removed support for Java 8 runtime environment
3.45.1-01
Changed 1
- Enhance logging for better troubleshooting and diagnostics
Fixed 4
- Improve error handling and reporting in blob store operations
- Resolve issues with repository selector functionality
- Fix potential null pointer exceptions in component metadata processing
- Address performance degradation in search operations
Added 3
- Add support for npm package provenance
- Add SIEM event logging support
- Add support for custom certificate authorities in system settings
Changed 2
- Improve performance of the repository browse UI
- Update npm audit API endpoint handling
Fixed 3
- Fix authentication issues with Azure Blob Storage
- Fix potential data loss when deleting blob stores
- Fix permission validation for anonymous access to repositories
Security 1
- Address vulnerability in XML parsing to prevent XXE attacks
Added 4
- Support for Helm repository format
- Support for Cargo repository format
- Support for Cocoapods repository format
- Health Check API endpoint for repository health status
Changed 2
- Improved performance of blob store operations
- Updated database schema for better scalability
Fixed 3
- Fixed issue with LDAP authentication in certain configurations
- Fixed memory leak in repository cleanup tasks
- Fixed UI rendering issues with large numbers of repositories
Security 1
- Updated dependencies to address known security vulnerabilities
Fixed 2
- Restore support for S3 direct download URLs when using path-style buckets with virtual hosted-style bucket URIs
- Correct S3 access logging configuration which was failing when using path-style buckets
Added 2
- Add support for CVSS v3.1 vulnerability scoring
- Add capability to configure repository cleanup policies with more granular control
Changed 2
- Improve performance of repository browsing and search operations
- Update embedded dependencies to latest patch versions for security and stability
Fixed 3
- Fix issue where large artifacts could fail to upload in certain network conditions
- Fix memory leak in the blob store garbage collection process
- Fix incorrect permission checks when accessing repository content through the REST API
Security 1
- Update log4j dependency to address known security vulnerabilities
Changed 1
- Improve performance of repository operations
Fixed 6
- Provide support for Java 17 in the Docker image
- Fix missing authentication header when proxying requests through HTTPS proxy servers
- Fix cleanup task incorrectly deleting components when using composite repositories
- Fix Docker API v2 manifest compatibility issues
- Fix repository selection logic for Docker repositories
- Fix excessive memory usage in some scenarios
Added 3
- Added support for Maven Central Repository signing requirements including support for GPG signing during publishing
- Added ability to view blob store usage statistics and disk space information from the UI
- Added FIPS 140-2 mode support for enhanced security compliance
Changed 1
- Updated default security headers to include additional content security policy directives
Fixed 3
- Fixed issue where HTTP connections could be established with untrusted SSL certificates
- Fixed race condition in cleanup policy execution that could cause data loss
- Fixed incorrect calculation of repository size statistics
Added 5
- Add support for Amazon S3 as a blob store backend
- Add Docker API v2 manifest configuration support
- Add support for PyPI normalized package names
- Add Helm chart repository signing capability
- Add support for Conan 2.0 package format
Changed 2
- Improve performance of repository metadata operations
- Upgrade to Log4j 2.17.1 for security improvements
Fixed 4
- Fix issue with Docker manifest digest calculation
- Fix performance degradation in large repository searches
- Fix cleanup policy execution for hosted repositories
- Fix npm package vulnerability scanning integration
Deprecated 1
- Deprecate support for Java 8 runtime
More in Developer Tools
View allyt-dlp
A feature-rich command-line audio/video downloader
yt-dlp
Microsoft-Activation-Scripts
Open-source Windows and Office activator featuring HWID, Ohook, TSforge, and Online KMS activation methods, along with advanced troubleshooting.
massgravel
Claude Code
Anthropic's agentic coding tool for the terminal, IDE and web.
Anthropic
tmux
tmux release notes.
tmux
Shadowrocket
Rule based proxy utility client for iPhone/iPad.
Shadow Launch Technology Limited
GitHub CLI
GitHub command-line tool
GitHub