Hi all,
Latest version of Sonatype IQ Server version 169 has been released and is freely available for download for all existing users.
Release 169 Contains a Critical Fix
We are releasing IQ Server version 169 ahead of schedule (regular releases are scheduled for the first week of the month.)
This release fixes a critical issue that affected the command line scanning of SBOMs and containers on installations of release 168 running on the embedded H2 database. Earlier versions (prior to 168) or those running on PostgreSQL (external database) are not affected.
Users facing issues with release 168 installations running on H2 database should upgrade immediately.
Other Improvements in this Release
Onboard Unlimited Applications in Sonatype Lifecycle
We have removed the previous limit of 5000 applications. Users can now onboard unlimited applications to Sonatype Lifecycle to maximize the benefits and improve the security profile of expanding software supply chains.
RPM Data Cleanup
It has come to our attention that some customers were experiencing unusual results with our RPM data. Upon investigation we discovered that we had accidentally released some RPM data before it was ready for general availability. We have since removed this RPM data from our catalog to restore quality. Policy results may change as a result of this retraction. We apologize for the inconvenience.
New Method Added to Firewall REST API
Using the new POST method, users can now add a new repository manager using the Firewall REST API.
Replacing Deprecated REST API
The Manifest Evaluation REST API-v2 (deprecation announced in release 126) has reached the end of the sunsetting window and can no longer be used. We recommend using the successor API, Source Control Evaluation REST API to perform application policy evaluations in a source control branch.
For more detailed information on release 169 and tracking resolved issues, please refer to the release notes.
Thank you,
Dariush Griffin
Sonatype Lifecycle - Product Manager