Release Notes

AI Tools

MetaDefender Software Supply Chain v4.0.3

Release Date: August 20, 2026

This patch release sharpens package and SBOM reporting. Package counts now include transitive dependencies, new SBOM report exports the full component set, and dashboard figures stay current as files are re-analyzed and reports deleted. It also brings cross-domain report access to the high side, along with refinements to exports, pagination, and notifications.

Highlights

Complete Package Counts
Package totals now include transitive dependencies, so the number in a report reflects everything that was scanned. Ingestion retains packages whether or not a version or ecosystem is specified, and reports load full package inventories well beyond 100 entries.

Expanded SBOM Exports
SBOM PDF exports now include transitive dependencies, giving you the complete dependency tree in a single document. Cyclone DX exports carry end-of-life and criticality properties for each component along with the root dependency relationship.

Cross-Domain Scan Results Visibility
When you choose to run a scan on the high side, the report includes a direct redirect link, so you can move from a cross-domain transfer straight to the corresponding report.

Live Dashboard Totals
Re-analyzed files count once toward your totals, so repeat scans of the same content keep the dashboard accurate. Dashboard, package, and CVE aggregates refresh as soon as reports are deleted.

Notification and Interface Refinements
Notifications now deliver clearer, less intrusive updates during scans and exports, shaped by user feedback. Repository inventory includes a risk score column.

Offline Package Distribution
The release pipeline now publishes the MDSSC offline package to My OPSWAT, simplifying installation in air-gapped and restricted-network environments.

Bug fixes

  • SBOM exports in Cyclone DX and SPDX formats no longer drop packages whose version could not be resolved

  • PDF and CSV exports now report the correct package total for direct-file SBOM scans instead of double counting

  • The CVEs tab no longer presents pagination issues.

  • Opening a report or analysis detail view no longer raises a deceptive error notification

  • Creating a job with All References selected now sends the correct configuration