MetaDefender Software Supply Chain reaches a major milestone with version 4.0.0, introducing a fully rebuilt interface, a new job-based workflow, repository-level risk scoring, a richer SBOM PDF export, along with new telemetry, event-based JFrog webhooks, and many more giving security teams faster visibility, smarter remediation guidance, and stronger compliance reporting across the software supply chain.
This release is designed to reduce friction for security and development teams managing complex pipelines, while strengthening alignment with regulatory frameworks including US Executive Order 14028 and the EU Cyber Resilience Act.
New in this Release
- New User Interface
- Jobs replacing Scans
- Risk Score for Repositories
- Security Suggestions
- New SBOM PDF Export with More Fields
- Telemetry
- CSV Exports for Packages
- Container Layer Scanning and Skip by Hash
- Binary Package Skip by Hash
- JFrog Container Webhooks (Event-Based)
A Modern Interface Built for Security Teams
As software supply chain threats continue to grow in scale and sophistication, security teams need tools that keep up, not just in capability, but in usability.
Version 4.0.0 introduces a fully rebuilt user interface aligned with the broader OPSWAT product suite. Every page and workflow has been redesigned to reduce navigation friction, surface relevant information faster, and deliver a more consistent experience across the platform.
This update reflects a broader commitment to making security tooling accessible to the teams who rely on it every day, whether they are managing a handful of repositories or overseeing a complex, multi-team pipeline.

From Scans to Jobs: Better Visibility into Pipeline Activity
The shift from a scan-based to a job-based model is one of the most significant workflow changes in this release.
Where scans were point-in-time operations, jobs provide a more structured and trackable unit of work, giving teams a clearer picture of what has been analyzed, when, and with what result. This change improves auditability, makes it easier to identify gaps in coverage, and gives security and development teams a shared language for tracking pipeline activity.

Repository Risk Scoring: Prioritize What Matters Most
Not all repositories carry the same risk. Version 4.0.0 introduces repository-level risk scores that aggregate vulnerability, malware, and policy data into a single, actionable signal.
Security teams can now quickly identify which repositories represent the greatest exposure without having to dig through individual scan results, and prioritize remediation efforts accordingly. This is particularly valuable for organizations managing large numbers of repositories across distributed development environments.
Security Suggestions: From Detection to Remediation
Detecting a vulnerability is only the first step. Acting on it quickly is what reduces risk.
Security suggestions surface actionable guidance directly in the product at the point of detection. Rather than leaving teams to research fixes independently, the platform now provides specific remediation recommendations, helping organizations move faster from identification to resolution.
Enhanced SBOM Export: Compliance-Ready Reporting
Regulatory pressure around software transparency continues to intensify. US Executive Order 14028 and the EU Cyber Resilience Act have made SBOM generation a compliance requirement for many sectors, and the bar for what a compliant SBOM must contain continues to rise.
The new SBOM PDF export adds fields for richer component-level detail and improves alignment with current and emerging compliance frameworks. Organizations can generate audit-ready reports directly from the platform, reducing the manual effort required to meet regulatory obligations.

Usage Reporting
Aggregated usage data and job activity help us support you faster, build the features you actually need, and fix the issues affecting you most.
CSV Exports for Packages
Package-level data can now be exported directly to CSV, making it easier for teams to analyze findings offline, feed results into other reporting tools, or share package-level detail with stakeholders outside the platform.
Container Layer Scanning and Binary Package Skip by Hash
Smarter scanning logic now identifies previously analyzed container layers and binary packages by hash and skips them on subsequent jobs, reducing redundant analysis and speeding up scan times across large, frequently rebuilt images.
JFrog Container Webhooks (Event-Based)
Event-based webhooks for JFrog container repositories trigger analysis automatically as new images are pushed, keeping scan results current without requiring manual or scheduled jobs.

A Stronger Platform for the Evolving Threat Landscape
MetaDefender Software Supply Chain 4.0.0 is a comprehensive platform for securing every stage of the software lifecycle. The combination of a rebuilt interface, smarter risk analysis, expanded automation, and stronger compliance reporting reflects the growing complexity of the threat landscape, and the increasing expectations placed on security teams to address it.
Explore the full documentation to discover more about how these updates can support your workflows.
To learn more:
Release Details:
- Product: MetaDefender Software Supply Chain
- Version: 4.0.0
- Release Date: 20 July 2026
- Release Notes: v4.0.0
- Download: Available from the OPSWAT Portal
