The latest release of MetaDefender Software Supply Chain focuses on two things at once: making the product easier to run in an enterprise environment, and tightening how it protects the repositories it connects to. This update adds single sign-on, a read-only user role, and expanded JFrog container coverage. Alongside those, it signs Cross Domain Transfers with a pairing secret, strengthens the password policy, and reduces the detail exposed in error messages. Here's what changed and why it matters.
For more on securing artifact movement between environments, see MetaDefender Software Supply Chain v3.3.0: Cross Domain Transfer.
Cross Domain Transfer Now Signs Every Transfer
Moving code between isolated environments is one of the most sensitive things MetaDefender Software Supply Chain does, so v4.1.0 adds another layer of protection to it. On top of the authentication token Cross Domain Transfer already uses, every transfer is now signed with a pairing secret as well — two secrets instead of one.
The point is defense in depth: a token can be compromised on its own, but a stolen token alone can no longer write into a connected repository. It also has to prove it holds the pairing secret for that specific setup. Configuration takes two secret fields, one for each side.
If you run cross-domain workflows, review your pairing configuration as part of the upgrade.

Enterprise-Ready Access: SSO and a Read-Only Role
Two changes make MetaDefender Software Supply Chain easier to operate inside a larger organization.
- SSO (single sign-on) — Users can now sign in through your existing identity provider, so access follows the same authentication and offboarding process as the rest of your stack.
- Read-only user role — A new role grants visibility into scans and results without configuration rights, so auditors, analysts, and stakeholders can see what they need without the ability to change settings.
Together they give administrators finer control over who gets in and what they can do once inside.

Broader Container Coverage: JFrog OCI Repositories
JFrog container support now extends to OCI (Open Container Initiative) package-type repositories. That includes remote images that are cached only by digest, with no tag — a common blind spot, since untagged, digest-only images are easy to miss in an inventory but still run in production. You can now list and scan them alongside the rest of your registry.
Security Hardening Across the Board
Beyond the headline features, this release resolves a set of security findings and tightens the product's overall posture:
- Stronger password policy — Weak passwords are no longer accepted.
- Rate-limited password reset — The password reset endpoint can no longer be used to send unlimited email.
- Open redirect closed — Exported PDFs and emails no longer trust an attacker-controlled base URL; the product address is now a network setting.
- Stricter role validation — User roles can no longer be set to values the interface does not offer.
- Stricter input validation and quieter errors — Error messages now reveal less detail, giving less away to anyone probing the system, and archive unpack limits cap oversized or malformed archives.
None of these are features you'll see in the interface, but each addresses a way the product could have been misused.
Quality-of-Life Improvements
Two smaller additions round out the release:
- Settings now generates and saves an API key automatically, so you don't have to create one by hand.
- A new public GET /api/version endpoint returns the running version for health checks and monitoring.
Upgrade Today
This release is designed to make MetaDefender Software Supply Chain safer to connect and easier to govern — signed transfers, identity-provider sign-in, a read-only role, and broader container coverage, on top of a round of security hardening. Review your Cross Domain Transfer pairing configuration as part of the upgrade, then take advantage of SSO and the new role to bring access in line with the rest of your environment.
Available from My OPSWAT™ Portal.
