Release Notes

AI Tools

MetaDefender Software Supply Chain v4.0.4

Release Date: August 28, 2026

This patch release hardens package and SBOM reporting with complete transitive dependency inclusion, cross-domain report access on the high side, and several stability and usability fixes.

Highlights

Nexus Container Support Nexus Container repositories are now available as a scan source alongside existing container registries. Connect to Nexus Container registries using the new integration, triggering scans directly against your Nexus container storage.

Nexus Container Cross-Domain Transfers Transfer containers to and from Nexus Container repositories in cross-domain scenarios, completing the Nexus integration story alongside existing binary and raw-format support.

ECR ↔ Harbor Cross-Domain Transfers Cross-domain transfers now work between Amazon ECR and Harbor registries, enabling secure container movement between cloud environments. Combine this with existing GitLab and Nexus binary/container transfer capabilities to build flexible supply chain workflows across your registry infrastructure.

Complete Package Counts with Transitive Dependencies
Package totals now include transitive dependencies, so the number in a report reflects everything that was scanned. Ingestion retains packages whether or not a version or ecosystem is specified, and reports load full package inventories well beyond 100 entries.

Expanded SBOM Exports
SBOM PDF exports now include transitive dependencies, giving you the complete dependency tree in a single document. CycloneDX exports carry end-of-life and criticality properties for each component along with the root dependency relationship.

Cross-Domain Scan Results Visibility
High-side analyze logs now include direct redirect links to their corresponding reports, so you can move from a cross-domain transfer straight to the report without manual navigation.

Notification and Interface Refinements
Improved error handling for unconfigured cross-domain settings, better SBOM completion on TLS setups, and cleaner onboarding flows.

Bug Fixes

  • SBOM exports in CycloneDX and SPDX formats no longer drop packages whose version could not be resolved

  • PDF and CSV exports now report the correct package total for direct-file SBOM scans instead of double counting

  • CVE search now matches the "Repositories With Issues" column

  • TLS certificate validation for SBOM completion now works correctly when MD_CORE_CERTIFICATE_VALIDATION=IgnoreAllErrors is set

  • Global cross-domain config endpoints now return clean 200 responses on unconfigured installs instead of 404s

  • Archive content views on direct SBOM scans now display properly



On This Page
Release Notes