Sonatype IQ Server Cloud Bug Fixes
This page contains a list of bug fixes included in our 2026 Sonatype IQ Server Cloud releases.
New features and enhancements are covered in the 2026 Sonatype IQ Server Cloud Release Notes.
September 9, 2026
FIRE-812 – Container image evaluation reports now support configurable data retention policies, with older reports removed according to the configured retention period after you enable a policy.
FIRE-724 – Component change detection requests can now exclude component evaluation data to reduce response payload size, and unsupported values for this option return an
HTTP 400response.CLM-50081 – SP-initiated SAML login now completes successfully by reducing the amount of authentication request data stored during the login process.
CLM-43911 – Go module paths with mixed-case characters now retain their original casing during SBOM evaluation, ensuring accurate component matching and vulnerability reporting.
CLM-40847 – Role permission cache reads now include only fully committed database changes, preventing stale cache entries from causing 403 permission errors for users with valid role assignments.
CLM-40826 – License override API requests now serialize component identifiers correctly when generated through the API Reference.
CLM-40070 – CycloneDX SBOM exports now identify Sonatype as the vulnerability rating source when Sonatype's CVSS assessment differs from the original CVE record.
CLM-39841 – Application reports now update the package URL with the claimed Maven coordinates after you claim a proprietary component, keeping it consistent with the displayed component identifier.
CLM-39539 – Advanced Search now returns associated Sonatype vulnerabilities when you search by a linked CVE identifier.
CLM-37390 – Dashboard violations CSV exports now include the complete organization hierarchy for each violation.
CLM-37199 – The Component Search API contract now defines component identifiers correctly so generated clients can serialize them as a single JSON-encoded value.
CLM-37133 – Notification overrides configured at a parent organization now appear in the policy editor when you view the policy from a child application.
CLM-37101 – Waiver Request webhook payloads now preserve the requested expiration date so the Add Waiver form prefills the correct expiration instead of defaulting to Never.
CLM-36306 – Server logs now provide additional context when corrupted report data causes a parsing failure, helping administrators identify the affected report.
CLM-32103 – When SCM onboarding repository URL validation fails, server logs now include the affected repository and organization while protecting sensitive URL information.
CLM-32012 – PDF reports now reduce the title font size for applications with long names so the complete application name remains visible.
CLM-30586 – PDF report generation now substitutes characters that embedded fonts cannot render when they occur in component filenames instead of returning an error.
CLM-30488 – Components with unknown dependency data now match applicable negative dependency type policy conditions, ensuring security violations are evaluated correctly.
CLM-29783 – Poetry scans now exclude lock file dependencies when the project defines no production dependencies, preventing development-only dependencies from appearing as violations.
CLM-21579 – Role membership requests can now validate that a specified user or group exists in a configured security realm, preventing invalid role memberships from being persisted.
CLM-21225 – The Vulnerability Details tab now remains available when Sonatype security data changes after a scan and displays a warning prompting users to run a new evaluation for current vulnerability information.
September 2, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-46061 – Policy evaluation now completes successfully for applications containing components with incomplete Maven coordinates, and affected reports remain accessible in the UI.
CLM-45805 – Sonatype SBOM Manager list rows now remain fully visible and clickable across supported browser window sizes and screen resolutions.
CLM-43913 – The applications API documentation now identifies the correct application identifier query parameter, reducing confusion with internal application IDs used by other endpoints.
CLM-42907 – Application startup now stops when it detects an incompatible database schema version, preventing the application from running against an unsupported schema.
CLM-42239 – Policy evaluation now completes successfully when concurrent scans run against the same application using file-backed report storage.
CLM-42088 – OIDC single sign-on reauthentication now succeeds after a session timeout when users are on nested application pages.
CLM-42014 – Application name validation now rejects forward slashes before form submission and displays the validation message immediately.
CLM-41113 – Reachability Analysis results are now preserved when scans are promoted between lifecycle stages.
CLM-40952 – Developer Priorities CSV exports now quote fields correctly for reliable use with Excel and standards-compliant CSV readers.
CLM-39952 – Policy condition selections now display the saved license or other selected value immediately after a constraint is updated.
CLM-39541 – Policy violations now display as open in component details after their associated waiver is removed.
CLM-39468 – GitLab commit-status processing no longer suspends repository URLs when a referenced commit cannot be found, allowing subsequent SCM activity to continue normally.
CLM-38965 – Organizations containing large numbers of applications can now be deleted reliably, including when the server restarts during deletion.
CLM-38931 – Developer Dashboard links for CI/CD, SCM, and IDE integrations now open the correct Sonatype documentation pages.
CLM-38693 – Version Explorer now displays consistent vulnerability information across scan reports, version comparisons, and version graphs.
CLM-38445 – Policy re-evaluation now completes successfully on NFS-backed deployments when filesystem state changes between requests.
CLM-38357 – Advanced Legal Pack license obligations now display the correct text for applicable licenses in disjunctive license groups and provide an explanation when obligation text is unavailable.
CLM-38349 – Advanced Legal Pack license details now provide explanatory guidance when Sonatype cannot fully identify a license.
CLM-38159 – Policy evaluations using security vulnerability group constraints now complete more efficiently for components with large numbers of versions.
CLM-36831 – SPDX imports with percent-encoded Package URLs now preserve special characters correctly in Sonatype SBOM Manager.
CLM-36766 – Pull request policy evaluations now recover from transient SCM connectivity errors so commit status checks can complete successfully.
CLM-35754 – License data refreshes now complete successfully across nodes in high-availability and multi-instance deployments when synchronization occurs concurrently.
CLM-35150 – Support ZIP database exports now include vulnerability group data so policies that depend on vulnerability groups load correctly during troubleshooting.
CLM-34757 – The OpenAPI specification for CycloneDX SBOM export endpoints now accurately describes the response and download metadata returned by the endpoints.
CLM-34302 – Proprietary regex matchers containing
@now correctly identify scoped npm packages when their coordinates match the configured pattern.CLM-34160 – Scan tickets now warn users when archived SBOM files cannot be read, making incomplete scan results easier to identify and investigate.
CLM-33893 – The global error banner now displays a meaningful message when the server cannot be reached.
CLM-32605 – The Access tile on organization pages now displays an error message and retry option when role membership data cannot be loaded.
CLM-32341 – License checks for unavailable features no longer generate unnecessary error-level log entries when users navigate organization pages.
CLM-32078 – The proxy configuration page is now accessible when a product license is not installed.
CLM-28854 – Version Explorer and Risk Remediation data now load correctly for applications with non-ASCII characters in their public IDs.
CLM-25452 – View the latest report on an InnerSource component details page now opens the producer application's most recent scan report regardless of lifecycle stage.
CLM-25209 – LDAP read operations now complete successfully when short connection timeout values are configured.
CLM-22062 – Advanced Search now supports larger queries by default, reducing failures for searches containing many clauses.
CLM-18813 – Proxy authentication now succeeds with supported NTLMv2-only proxy configurations, allowing outbound service connections to complete normally.
August 26, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
FIRE-517 – Policy Compliant Component Selection for PyPI proxy repositories now more consistently applies applicable Firewall policies when determining which package versions are available to clients.
CLM-45874 – The
realmquery parameter for the user token REST API now correctly resolves LDAP realm identifiers and returns a400 Bad Requestresponse for unrecognized realm values instead of falling back to the Internal realm.CLM-44461 – Reviewer comments added while approving or rejecting a waiver request are now preserved in the waiver record and displayed in the approved waiver details.
CLM-44448 – The Legal tab Application backlog now displays a loading indicator while retrieving data and shows No applications found only when the request completes with no results.
CLM-44361 – Legal tab Application backlog pages now load faster in large deployments by limiting query processing to the current page size instead of the total application count.
CLM-44352 – The Legal Application backlog now loads faster in large deployments by batching tag and component data queries instead of retrieving them individually for each application.
CLM-42782 – Reachability Analysis status now displays as Unknown when a CVE has no callable method signatures instead of incorrectly displaying Not Reachable.
CLM-41535 – Reviewers can now reject pending waiver requests when the associated policy violation no longer exists, allowing orphaned requests to be cleared through the standard review workflow.
CLM-39367 – Version Explorer now loads component and version details when Source Control contains an invalid access token, while pull request and remediation features are marked unavailable.
CLM-39208 – Role Memberships REST API endpoints now accept user and group names containing
/, supporting IdP group names such as/securityandengineering/design.CLM-38965 – Large organization deletions now commit each application independently, preserving completed deletions after a server restart and allowing the operation to resume.
CLM-38947 – Reachability markers and associated auto-waivers are now preserved in application reports after Continuous Monitoring re-evaluates a previously scanned application.
CLM-38597 – The helSecurity/IQ Policy Evaluation status check on Azure DevOps pull requests now completes after pipeline-triggered policy evaluations without requiring Pull Request Commenting.
CLM-38445 – Policy re-evaluation now completes reliably on NFS-mounted storage without intermittent 500 errors during report directory renaming.
CLM-38428 – Automated remediation pull requests now support configurable commit message templates with ${component} and ${version} placeholders.
CLM-35315 – Reachability Analysis data now appears correctly when the same application is scanned across multiple lifecycle stages, including promoted scans.
CLM-34161 – CycloneDX SBOM ingestion now correctly processes UTF-16 BOM-encoded files and reports their components and policy violations.
CLM-31661 – The Security/IQ Policy Evaluation status check on Azure DevOps pull requests now completes correctly for feature-branch commits targeting the default branch.
CLM-30716 – The report history API now returns scan results across all pipeline stages when no stage filter is specified, preventing high-volume stages from crowding out results from less-active stages.
CLM-29888 – Report retrieval now handles large and concurrent report entries without triggering out-of-memory errors that can cause server outages.
CLM-29728 – Vulnerability custom-data API requests now return a validation error when component coordinates contain fields that are invalid for the specified format, preventing malformed records from causing report failures.
August 18, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
FIRE-792 – Quarantined PyPI components evaluated through the Firewall Evaluation API now retain separate entries for each package version, preventing versions of the same package from overwriting one another.
CLM-43732 – Container scans of Docker images now report vulnerabilities only for the installed platform-specific Python wheel, preventing duplicate findings for other platform variants.
CLM-33982 – CycloneDX SBOM scans now log a warning when an invalid or unparseable package URL causes a component to be omitted from the scan.
CLM-33964 – Advanced Search permission filtering no longer counts toward the query clause limit, preventing searches from exceeding
maxAdvancedSearchClauseCountbecause of permission-filter clauses.
August 13, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-43920 – GitHub pull request comments that exceed the character limit now truncate lower-priority content and link to the full Sonatype Lifecycle report instead of failing to post.
CLM-40845 – Audit log responses no longer include NUL byte sequences caused by corruption in the underlying log files.
CLM-38213 – Container scans now report accurate policy violations for all Sonatype Lifecycle product licenses without requiring a Sonatype Repository Firewall license.
CLM-37981 – Advanced Search CSV exports now complete successfully when requests pass through HTTP/1.0 reverse proxies.
CLM-37109 – Bitbucket pull request comments that exceed the character limit now display the first 10 components and link to the full Sonatype Lifecycle report instead of failing to post.
CLM-36307 – Processing SBOM files with
externalRefsthat use non-registered reference types under theOTHERcategory no longer generates spurious WARN log entries from the SPDX parsing library.CLM-34834 – Source control evaluations now complete successfully after enabling and disabling SSH for applications originally imported with SSH disabled.
CLM-33964 – Advanced Search now supports users with access to large numbers of organizations or applications without producing a 'too many clauses' error.
CLM-25312 – Violation details in older evaluation reports now display an error message when they cannot load instead of remaining indefinitely in a Loading... state.
August 5, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-40143 - User token authentication now uses SHA-256 hashing, reducing authentication latency and memory usage while automatically migrating existing stored token hashes during successful authentication.
CLM-34561 - Third-party scans now continue processing valid SBOM items when individual archive entries cannot be parsed, while repeated processing errors no longer generate excessive clm-server.log output.
July 30, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
FIRE-513 – Firewall metrics consolidation jobs now correctly aggregate per-date counts on PostgreSQL deployments, keeping historical charts in the Firewall dashboard complete and up to date.
CLM-42178 – npm package aliases in
package-lock.jsonare now resolved using the entry'snamefield, ensuring aliased dependencies are identified by their actual package name during analysis.CLM-41689 – Authenticated usernames are now consistently recorded in
request.logacross bothclassicandlogback-accessrequest log configurations.CLM-37908 – The younger than N days age policy constraint now treats the boundary value as strictly exclusive, so components cataloged exactly N days ago no longer trigger a policy violation.
July 22, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-42440 – Database connections used by jOOQ streaming queries are now returned to the connection pool when streaming operations fail, preventing pool exhaustion and subsequent IQ Server outages.
CLM-42247 – IQ Server now starts successfully with multiple
applicationConnectorsandadminConnectorsconfigured, binding all configured HTTP and HTTPS ports as expected.
July 15, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-40930 – Deleting an SBOM version through the API now also removes associated policy evaluation report files and scan artifacts from storage, preventing orphaned files from accumulating
July 8, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38159 - Policy evaluation now preloads security vulnerability group data during repository component metadata evaluation, eliminating unnecessary database queries and improving evaluation performance.
July 1, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-52537 - View Repository Results now routes Docker proxy repositories to the correct container results page, matching the behavior of selecting the repository name directly.
INT-9591 - Container scans now complete successfully when CVE reference URLs are malformed or missing, returning full report links instead of a server error.
CLM-38947 - Reachability markers from manual scans are now preserved during Continuous Monitoring re-evaluation, keeping reachability-scoped auto-waivers intact across monitoring cycles.
June 24, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
INT-10303 – Large policy reports can now be retrieved in smaller chunks, improving compatibility with ServiceNow size limitations.
CLM-40944 – GitHub App registration for SCM authentication now completes successfully without configuration errors.
CLM-39938 – Developer prioritization now loads only the data required for analysis, preventing memory exhaustion on large scans.
CLM-38777 – Vulnerability customizations for NeuVector-sourced OS-level findings now load correctly when weakness or severity values are null.
CLM-32426 – Source Control settings at the sub-organization and application levels now correctly display Inherit (Not Configured) when no explicit value has been set.
June 17, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-52941 – The Malware Defense evaluate API now returns malware assessment results when components are identified by hash only, without requiring a
packageUrl.CLM-39800 – Components with names similar to internal project modules are no longer incorrectly classified as InnerSource components, and previously affected records are automatically corrected during subsequent scans.
CLM-37563 – View Dependency Tree now remains available and fully populated after Re-Evaluate Report and Quick Re-Evaluate operations on SBOM-uploaded scans.
CLM-35969 – SBOM components with empty license values are now treated as Not Provided and Not Declared, allowing License-None policies to evaluate correctly.
June 10, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-52196 – The format filter selection on the Repository Managers page persists correctly when navigating into a repository detail view and returning to the list.
NEXUS-52143 – The Firewall container quarantine view now displays only Docker images from repositories where quarantine is actively enabled, excluding audit-only repositories whose images were never blocked.
NEXUS-49583 – The Quarantine Time column in container-specific repository results views is now labeled Evaluation Time, accurately reflecting that the timestamp represents when the container image was scanned, not when it was quarantined.
CLM-40144 – Telemetry processing now limits queue growth and per-scan data collection to prevent excessive memory consumption when HDS is unavailable or responding slowly.
CLM-40054 – Go module scanning now ignores
go.sumfiles in auxiliary directories to prevent incorrect component matches from bundled tooling, examples, and test assets.CLM-39840 – When an Auto or Golden PR fails because a detected component is not declared as a direct dependency in the manifest file, the Retry button is now disabled with an actionable tooltip explaining that the component must first be added as a direct dependency before a pull request can succeed.
CLM-39830 – The policy violations API endpoint now retrieves application component data in a single batch query rather than one database call per violation, eliminating timeouts for policies with millions of violations.
CLM-39739 – Component age policies now skip age evaluation for components that are not present in the HDS catalog.
CLM-38844 – Audit log entries for license identification and component status changes scoped to non-root organizations are now captured and visible in the application audit log view, including any comments entered at the time of the change.
CLM-38729 – SBOM scans now complete successfully when license URLs exceed 200 characters.
CLM-38128 – The OIDC option in Firewall product preferences now navigates correctly to the OIDC configuration page.
CLM-37954 – Nexus IQ Server now automatically restores missing reference policies at the root organization during upgrades to ensure accurate Firewall malware-risk export results.
May 20, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-52635 – Concurrent npm and PyPI proxy requests under PCCS now coalesce across cluster nodes, preventing uncoordinated bursts of evaluate/componentMetadata calls from exhausting IQ Server heap memory. (This fix requires IQ Server 204+ and Nexus Repository 3.92.3+.)
NEXUS-52385 – (Included in Self-Hosted 203.2) The IQ Server HDS connection pool size is now configurable to support concurrent npm metadata requests in HA deployments and reduce fallback to stale cache when the default connection limit is reached.
CLM-38656 – The Priorities report now displays a Create PR button instead of a stale link when a previously merged pull request's changes are reverted and a new scan detects the reintroduced violation.
CLM-35417 – Source control configuration validation now provides specific error messages for invalid repository URLs, authentication failures, and insufficient token permissions to help users quickly identify and correct configuration issues.
May 13, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-52434 – PCCS evaluation results for PyPI and npm proxy repositories are now cached and reused within the configured metadata maximum age window, so a single request to IQ Server serves all subsequent lookups until the cache expires. (Fixed in Nexus Repository 3.92.3)
NEXUS-52218 – The Malware Components CSV now removes components whose malicious classifications were retracted or corrected during Automatic Malware Management reconciliation, ensuring unresolved findings reflect current Sonatype threat intelligence.
NEXUS-51730 – Repository Manager-scoped Firewall integration users can now retrieve custom quarantine messages without 403 errors or repeated WARN log entries in Nexus Repository.
May 6, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-51450 – The Automatic Malware Management task log now reports accurate quarantine states for malicious components detected in Firewall-enabled proxy repositories.
CLM-39406 – Saving custom filters in Success Metrics and Enterprise Reporting now succeeds for LDAP users with distinguished names longer than 50 characters.
CLM-38233 – Policy name validation during support zip imports now performs a single bulk database query per policy instead of recursive traversal, reducing import times for large organization hierarchies from more than 15 minutes to seconds.
CLM-31884 – Session cookies now use
SameSite=Laxby default, while SAML authentication paths retainSameSite=Nonefor IdP callback compatibility. Identity provider configuration review may be required before upgrading.CLM-30626 – Application create and update operations now validate application IDs against existing internal UUIDs to prevent collisions that could cause the application management UI to crash.
April 29, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38299 – License Threat Group updates now complete successfully without UI hangs by optimizing name validation queries to eliminate excessive database calls in large organizational hierarchies.
April 22, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-51881 - Component re-evaluation through Firewall completes successfully when using an H2 database, allowing quarantined components to be released without lock timeout errors.
NEXUS-51535 - Bulk waiver functionality in the Firewall dashboard container view now works correctly, with the waive button fully operational, the date picker displaying without overlapping text, and the back button returning users directly to the Firewall dashboard.
NEXUS-51509 - Concurrent Policy Compliant Component Selection requests for the same PyPI or npm package are now deduplicated, ensuring only one evaluation request reaches Firewall.
NEXUS-51485 - Docker proxy repositories now return Docker Registry API V2-compliant error responses containing the quarantine reason and Firewall report URL directly in the JSON body, making blocked image pulls immediately actionable in standard Docker and Podman clients without requiring additional client-side configuration.
CLM-39913 - Policy evaluations no longer deadlock when database connection pools are exhausted, improving reliability under high-load conditions with concurrent
ClusterLockand transaction operations.CLM-39405 - User and role detail pages open correctly for Repository Firewall-only licensed instances, without redirecting to the Firewall dashboard.
CLM-36995 - The Dependency Tree REST API, CycloneDX exports, and SPDX exports include all components shown in the UI dependency tree, including those with unknown match states.
CLM-36831 - SPDX files containing percent-encoded Package URLs, including special characters, are imported into SBOM Manager without double-encoding or UI display issues. The
packageurl-javalibrary upgrade introduces updated PURL normalization behavior that may affect existing integrations.CLM-38424 - OIDC token exchange requests route through the HTTP proxy configured via the IQ Server REST API (
/api/v2/config/httpProxyServer), removing the need for JVM system property-based proxy configuration.CLM-37414 - Migration from H2 to PostgreSQL requires granting
SET ON PARAMETER"session_replication_role"to the importing user prior to running the import, including in managed PostgreSQL environments.
April 15, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38934 – Vulnerability Lookup displays KEV and EPSS data correctly regardless of whether CVE identifiers are entered in uppercase, lowercase, or mixed case.
CLM-38699 – Policy conditions combining
DependencyTypewith other criteria now correctly evaluate Python packages, which may result in new violations appearing for components that were previously skipped.CLM-38674 – Raw reports now include AI Content policy violation details for troubleshooting and analysis.
April 13, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38690 – Re-evaluating a CycloneDX SBOM report now preserves SBOM-supplied license data for exactly matched components, so License Detections no longer change to Not Provided when no better curated license data exists.
April 3, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38633 – Support ZIP files now include OAuth2, OIDC, Crowd, and tenant metadata configuration details, enabling more efficient troubleshooting of authentication and tenant-related issues while ensuring sensitive data remains obfuscated.
April 2, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-39124 - Bitbucket Cloud integrations automatically discover repositories across all accessible workspaces following Bitbucket's API migration from deprecated cross-workspace endpoints to workspace-scoped APIs.
CLM-38555 - CycloneDX SBOM evaluations now accept components containing newer SPDX license identifiers such as SMAIL-GPL and WXwindows without validation errors.
CLM-37113 - Application deletion completes successfully even when approved policy waivers are associated with the application, and historical reports remain accessible throughout the deletion process.
March 25, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38750 - Reduced excessive INFO and DEBUG logging in
SbomPersistenceServiceProviderduring Applicable Waivers REST API calls, preventing rapid log growth and excessive disk consumption.CLM-38370 - HDS requests that require a license are no longer sent when the license header is missing or null, eliminating intermittent 402 Invalid License responses for valid tenants.
March 11, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-50206 – Quarantine counts for Docker repositories are now displayed only when quarantine is enabled, preventing misleading vulnerability status information in the Firewall UI.
CLM-38747 – Automated remediation pull requests for Go projects now successfully update direct dependencies in go.mod files, including support for Go 1.21+ projects using toolchain directives.
CLM-38213 – Container image scans performed with the CLI now correctly evaluate policy violations across all Lifecycle product licenses, including SBOM Manager and Teams Edition.
February 25, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-50689 – Updated the
verifyoperation to validate the correct license feature, ensuring connection verification succeeds for Sonatype Repository Firewall licenses and only fails when a legitimate license restriction exists.NEXUS-49616 – The Firewall dashboard container waivers view honors organization-specific View IQ Elements permissions as documented.
NEXUS-49569 – Firewall scan reports now accurately display policy violations even when Legacy Violations are enabled at the root organization level, providing clear visibility into why components are quarantined.
NEXUS-48549 – Enhanced container image error messages to display the specific image identifier (namespace, name, and version) when processing failures occur, making troubleshooting more straightforward.
CLM-38607 – Email server configuration is now automatically managed in SaaS environments, ensuring consistent and reliable email delivery across all tenants.
February 18, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-43058 – Quarantined components now display only safer alternative versions that meet policy requirements, excluding pre-cached versions with security violations from the allowed versions list.
CLM-38434 – Policy violation First Reported dates now remain stable when reordering or modifying policy conditions, ensuring consistent tracking for compliance reporting and SLA management.
February 5, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
CLM-38370 – IQ SaaS customers should no longer see intermittent 402 invalid license responses.
NEXUS-48816 – The Review Obligations button now works as expected for customer with an Advanced Legal Pack license.
February 4, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-47170 – NuGet registry index JSON assets are now excluded from Firewall analysis by expanding the ignore pattern to filter all NuGet feed JSON metadata, ensuring repository reports focus only on actual package artifacts such as .nupkg files.
NEXUS-44853 – Improved synchronization handling between Sonatype Repository Firewall and JFrog Artifactory so that out-of-sync states are automatically detected and corrected, ensuring users receive clear and accurate quarantine status messages when downloading components.
January 29, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-41977 – The Repository Managers navigation item now expands when selected, and its counter accurately displays the number of repository managers instead of the total number of repositories.
NEXUS-49174 – The Firewall Evaluate API no longer requires a SHA1 hash for formats like Conan that use coordinate-based matching, allowing requests to omit the hash field without impacting evaluation.
NEXUS-37403 – Components with a null
pathnamein audit batch requests no longer prevent processing of the entire batch, allowing Repository Audit to complete successfully even when encountering malformed assets.CLM-38540 – Deleting applications with more than 1,000 associated reports now uses batched delete requests to avoid exceeding S3 request limits and prevent errors during deletion. (SaaS only)
CLM-38452 – Vulnerability lookup results and the vulnerability API now return EPSS scores consistently with application reports, even when a
componentIdentifieris not provided.CLM-35001 – The
/api/v2/config/sourceControlendpoint now enforces a non-zero minimum forpullRequestMonitoringIntervalSeconds, preventing invalid values from being saved and avoiding startup failures caused by a zero scheduling interval.
January 21, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-49650 – Clicking a row in the Auto Release from Quarantine view now opens the Component Information panel as expected.
NEXUS-47131 – Long repository names in the Repository Firewall left-hand navigation now display correctly, and the back button from component details reliably returns users to the appropriate prior context in Repository Firewall.
CLM-38159 – Reduced query volume and improved component metadata evaluation performance for large component sets when performing policy evaluations for PCCS. (This fix will be made available to self-hosted deployments in release 200.)
January 14, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-47170 – NuGet registry index JSON assets beyond index.json are now excluded from analysis to prevent unnecessary Component-Unknown entries in repository reports.
NEXUS-44585 – Users with repository-level access now see only authorized information without encountering 403 errors on the Firewall landing page or Repository Manager screen.
CLM-34494 – IQ Server now provides a clearer error message when database connection fails due to incorrect PostgreSQL credentials.
January 7, 2026
This Sonatype IQ Server Cloud release includes the following bug fixes:
NEXUS-49569 – Docker policy violations marked as legacy no longer bypass quarantine enforcement when Allow violations of this policy to be granted legacy status is enabled at the root organization level.
NEXUS-47285 – The malware remediation task now skips components with empty or null hashes in NuGet proxy repositories, allowing the evaluation batch to continue running without interruption. (Will require Nexus Repository 3.88.0+ to be fully resolved.)