# BUG: Nexus 3.93.1 and PEP 691 JSON

**URL:** <https://community.sonatype.com/t/bug-nexus-3-93-1-and-pep-691-json/16432>\
**Category:** Sonatype Nexus Repository\
**Created:** [June 25, 2026, 8:10am UTC](https://community.sonatype.com/t/bug-nexus-3-93-1-and-pep-691-json/16432 "2026-06-25T08:10:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![itperfecto](https://avatars.discourse-cdn.com/v4/letter/i/ed8c4c/32.png) [@itperfecto](https://community.sonatype.com/u/itperfecto)\
**Post date:** [June 25, 2026, 8:10am UTC](https://community.sonatype.com/t/bug-nexus-3-93-1-and-pep-691-json/16432/1 "2026-06-25T08:10:31Z")

</div>

This morning we ran into the following issue:

1. If I use pip version 22, then when querying Nexus the latest version of the `click` package is 8.4.1:

```auto
pip3 --version
pip 22.0.2 from /usr/lib/python3/dist-packages/pip (python 3.10)

pip index versions click
WARNING: pip index is currently an experimental command. It may be removed/changed **`in`** ` a future release without prior warning.
click 8.4.1
Available versions: 8.4.1, 8.4.0, 8.3.3, 8.3.2, 8.3.1, 8.3.0, 8.2.1, 8.2.0, 8.1.8, 8.1.7, 8.1.6, 8.1.5, 8.1.4, 8.1.3, 8.1.2, 8.1.1, 8.1.0, 8.0.4, 8.0.3, 8.0.2, 8.0.1, 8.0.0, 7.1.2, 7.1.1, 7.1, 7.0, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 6.0, 5.1, 5.0, 4.1, 4.0, 3.3, 3.2, 3.1, 3.0, 2.6, 2.5, 2.4, 2.3, 2.2, 2.1, 2.0, 1.1, 1.0, 0.7, 0.6, 0.5.1, 0.5, 0.4, 0.3, 0.2, 0.1

```

On the proxy repository I have `metadata_max_age = 1440`.

1. If I upgrade pip to the latest version, the index already shows the new 8.4.2 release:

```auto
pip3 install --upgrade pip
Successfully installed pip-26.1.2

pip index versions click
click (8.4.2)
Available versions: 8.4.2, 8.4.1, 8.4.0, 8.3.3, 8.3.2, 8.3.1, 8.3.0, 8.2.1, 8.2.0, 8.1.8, 8.1.7, 8.1.6, 8.1.5, 8.1.4, 8.1.3, 8.1.2, 8.1.1, 8.1.0, 8.0.4, 8.0.3, 8.0.2, 8.0.1, 8.0.0, 7.1.2, 7.1.1, 7.1, 7.0, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 6.0, 5.1, 5.0, 4.1, 4.0, 3.3, 3.2, 3.1, 3.0, 2.6, 2.5, 2.4, 2.3, 2.2, 2.1, 2.0, 1.1, 1.0, 0.7, 0.6, 0.5.1, 0.5, 0.4, 0.3, 0.2, 0.1

```

As a result, our pipelines break, because the new version is already visible in the index, but the package with this new version has not yet been downloaded/cached on Nexus itself.

My question is: how does the JSON index already know about the new metadata? Does `metadata_max_age = 1440` not apply to it?

---

<div class="post-metadata">

**Author:** ![mpiggott](https://avatars.discourse-cdn.com/v4/letter/m/f0a364/32.png) [@mpiggott](https://community.sonatype.com/u/mpiggott)\
**Post date:** [July 9, 2026, 3:23pm UTC](https://community.sonatype.com/t/bug-nexus-3-93-1-and-pep-691-json/16432/2 "2026-07-09T15:23:46Z")

</div>

Hi,

I passed this along at the time but I guess I didn’t reply.

I haven’t looked at the changes that were made to support the JSON metadata but I suspect what has happened is that the types of metadata were cached independently with different expiration times and the gap happened to align with a version being released.

You could temporarily reduce the metadata timeout from 1-day (1440), if you do that I’d suggest reverting it later to reduce the load on the pypi infrastructure.
