Release Notes
MetaDefender Software Supply Chain v4.1.0 Release Date: September 30, 2026 |
|---|
This release adds role-based access control and single sign-on, contains a broad set of security hardening changes and expands JFrog container and cross-domain support. It also includes many reliability and usability fixes. HighlightsRole-Based Access ControlAccess to MDSSC is now governed by roles. Administrators have full control, and Read-Only Administrators can view all data but cannot make changes. Permissions are enforced on every API endpoint, not only in the interface. The UI adapts to what the signed-in user is allowed to do, and when an action is blocked by a permission, the message says so rather than reporting it as a license limitation. Single Sign-On (SSO)Users can now sign in through your organization's identity provider. Groups in the identity provider can be mapped to the MetaDefender Administrator and Read-Only Administrator roles, so access follows your existing directory membership. Security HardeningThis release strengthens security across the platform. We added protections against brute-force attacks, API requests are rate-limited, and passwords are no longer submitted as a cleartext field in secure browsers. Sessions are better protected, with hardened session cookies, no session tokens in URLs, and Origin checks on real-time connections. The password policy is stronger and now requires at least 15 characters. The password reset flow no longer reveals whether an account exists and can no longer be used to send spam email. Input validation is tighter across connections, user roles and outgoing email content. HTTP security headers and TLS settings have been updated to current best practice. Finally, new safeguards protect the platform against oversized or maliciously compressed repository archives, and cross-domain transfers now enforce stricter authorization. User Session ManagementAdministrators can now see and end active user sessions. Ending a session signs that user out right away, which helps when a device is lost, someone leaves the organization, or an account may be compromised. Improvements
Bug fixes
|