Release Notes

AI Tools

MetaDefender Software Supply Chain v4.1.0

Release Date: September 30, 2026

This release adds role-based access control and single sign-on, contains a broad set of security hardening changes and expands JFrog container and cross-domain support. It also includes many reliability and usability fixes.

Highlights

Role-Based Access Control

Access to MDSSC is now governed by roles. Administrators have full control, and Read-Only Administrators can view all data but cannot make changes. Permissions are enforced on every API endpoint, not only in the interface. The UI adapts to what the signed-in user is allowed to do, and when an action is blocked by a permission, the message says so rather than reporting it as a license limitation.

Single Sign-On (SSO)

Users can now sign in through your organization's identity provider. Groups in the identity provider can be mapped to the MetaDefender Administrator and Read-Only Administrator roles, so access follows your existing directory membership.

Security Hardening

This release strengthens security across the platform. We added protections against brute-force attacks, API requests are rate-limited, and passwords are no longer submitted as a cleartext field in secure browsers. Sessions are better protected, with hardened session cookies, no session tokens in URLs, and Origin checks on real-time connections.

The password policy is stronger and now requires at least 15 characters. The password reset flow no longer reveals whether an account exists and can no longer be used to send spam email. Input validation is tighter across connections, user roles and outgoing email content. HTTP security headers and TLS settings have been updated to current best practice. Finally, new safeguards protect the platform against oversized or maliciously compressed repository archives, and cross-domain transfers now enforce stricter authorization.

User Session Management

Administrators can now see and end active user sessions. Ending a session signs that user out right away, which helps when a device is lost, someone leaves the organization, or an account may be compromised.

Improvements

  • JFrog Container Improvements: JFrog container discovery now supports OCI package-type repositories. Images cached in JFrog remote repositories can be listed and scanned by digest.

  • Cross-Domain Support for Binaries: Cross-domain transfer is now available for binary registry integrations as well as source code.

  • Smoother, More Reliable Processing: Scan, SBOM and package processing now run in a dedicated processing service instead of being spread across several services. SBOM preparation, calculation and storage all happen in one place, so results are produced the same way whatever the source.

Bug fixes

  • The Add User form now checks the full name as you type, and its error messages match the rule

  • On the high side of a cross-domain setup, container images are now unpacked when re-scanned before import, so the secrets policy blocks images that contain secrets

  • The package list now keeps the severity filter applied when changing pages

  • Jira and Microsoft Teams notifications now require a Base URL, the same as SMTP

  • Onboarding now shows an error you can act on if the final step fails, instead of waiting indefinitely