# Exclude SNAPSHOTS from latest version for internal components

**URL:** <https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808>\
**Category:** Sonatype Nexus Repository\
**Created:** [June 9, 2022, 1:26pm UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808 "2022-06-09T13:26:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [June 9, 2022, 1:26pm UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808/1 "2022-06-09T13:26:48Z")

</div>

I maintain system that contains a complete inventory of every dependency in every one of my projects. Latest version information is derived via connection to maven central, jboss-releases, etc (just using maven as an example).

I want to connect to my NXRM so that latest version info is reported for all internal components. Well… it works great (including the authentication) but I cannot figure out how to configure things so that SNAPSHOT versions are excluded.

When I point at the “standard” Maven URL (the proxy that has a score of more members, including our releases and snapshots repos) then I get SNAPSHOT version information on everything internal. ie, both releases and for SNAPSHOT components themselves. So, I guess that this would be 100% expected.

When I update the URL to use our hosted “maven-releases” repo directly then I only get latest version info for releases… but it still tells me that every single component is out of date because it is still telling me that the latest version is a SNAPSHOT version.

So, any thoughts on how I might go about solving this?

---

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [June 20, 2022, 10:54am UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808/2 "2022-06-20T10:54:49Z")

</div>

Has anyone got any tips/pointers that might help? It really is quite important for me to get this addressed.

---

<div class="post-metadata">

**Author:** ![mpiggott](https://avatars.discourse-cdn.com/v4/letter/m/f0a364/32.png) [@mpiggott](https://community.sonatype.com/u/mpiggott)\
**Post date:** [June 21, 2022, 2:41pm UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808/3 "2022-06-21T14:41:42Z")

</div>

This doesn’t really sound like a question about Nexus to me. It sounds more like the Maven CLI tool is telling you something? If so you may want to access your question on the maven users list.

---

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [June 22, 2022, 2:16pm UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808/4 "2022-06-22T14:16:28Z")

</div>

I am not using the Maven CLI tool. I am using [Dependency-Track](https://dependencytrack.org/), which should be familiar to Sonatype!

Dependency-Track comes “out of the box” with multiple repositories defined for different ecosystems (ranging from cargo to python). For maven, there are several repos defined. eg, for maven-central, the URL used is:

[https://repo1.maven.org/maven2/](https://repo1.maven.org/maven2/)

With that, Dependency-Track succesfully reports the latest versions of all Java components that we are using that come from maven-central. Now that the latest development snapshots of Dependency-Track support authentication for repos, I have the chance to connect to our NXRM repo for the first time and report latest version information for _internal_ components.

But, as explained above, things are not working as desired. SNAPSHOT versions are always reported as being the latest version, which (whilst technically true) is NOT what is desired. So what URL in NXRM should be used? Do I maybe need to configure NXRM to (say) add a new proxy and use that URL?

---

<div class="post-metadata">

**Author:** ![msymons](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@msymons](https://community.sonatype.com/u/msymons)\
**Post date:** [November 7, 2022, 11:38am UTC](https://community.sonatype.com/t/exclude-snapshots-from-latest-version-for-internal-components/8808/5 "2022-11-07T11:38:15Z")

</div>

The above problem is now addressed and will be implemented in Dependency-Track v4.7.0 (which should be released before the end of November 2022).

In the end the solution was very simple… DT is currently retrieving versions using the` latest` tag. v4.7.0 will use `release` tag and if that is not present use `latest`.
