Release Notes

AI Tools

MetaDefender Software Supply Chain v4.0.0

Release Date: July 20, 2026

This major release introduces a redesigned user experience, a new Jobs-based workflow model, repository risk scoring, and expanded scanning, export, and integration capabilities.

Highlights

New User Interface

The web interface has been rebuilt from the ground up for a faster, clearer, and more consistent experience. Navigation, dashboards, and result views have been reorganized to surface the information that matters most and to make large repositories easier to explore.

Jobs Replacing Scans

The "Scan" concept has been replaced by Jobs, a more flexible unit of work that groups the processing of a repository or source into a single, trackable activity. Jobs provide clearer status, history, and results, and lay the foundation for the platform's expanded workflows.

Risk Score for Repositories

Repositories now display an aggregated risk score, giving teams an at-a-glance measure of overall security posture. The score consolidates findings across a repository so you can prioritize the sources that need attention first.

Security Suggestions

The platform now provides Security Suggestions - actionable recommendations that help you remediate detected issues. Suggestions turn raw findings into clear next steps, reducing the time from detection to resolution.

New SBOM PDF Export with More Fields

SBOM PDF export has been expanded to include additional fields, producing a richer, more complete software bill of materials. The enhanced report makes it easier to share comprehensive component and dependency information with stakeholders and auditors.

CSV Exports for Packages

Package inventories can now be exported to CSV, making it simple to analyze, filter, and share package data outside the platform or feed it into other tools and reporting pipelines.

Container Layer Scanning and Skip by Hash

Container images are now scanned layer by layer, with previously scanned layers skipped by hash. This improves the granularity of container findings while avoiding redundant work, delivering faster scans across images that share common layers.

JFrog Container Webhooks (Event-Based)

The JFrog container integration now supports event-based scanning via webhooks. New or updated container artifacts trigger scanning automatically, enabling continuous monitoring.

Telemetry

Optional product telemetry has been added, allowing the platform to report operational and usage data to a configured collector. Telemetry helps OPSWAT improve the product and gives administrators better visibility into deployment health.