Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Server-Side JavaScript Sandbox Replacement: Large Numbers of Findings but Mostly OOTB Platform Calls

Jeff Boltz1
Mega Guru

Hello Community,

 

We are currently reviewing findings associated with the Server-Side JavaScript Sandbox Replacement initiative and were surprised by what we are seeing.

 

At first glance, the report appeared to indicate a significant number of potential issues. However, after analysis, most occurrences seem to collapse into a small number of recurring patterns rather than a large number of unique remediation items.

 

In our environment, the majority of findings appear to be associated with out-of-box platform functionality, including:

 

  • Platform Analytics / Dashboard-related calls
  • VisualizationFiltersParser methods
  • Flow Designer functionality
  • A small number of HR Workspace / GraphQL-related calls

So far, we have not identified many clear customer customizations requiring remediation. Instead, much of the activity appears to be generated by platform features themselves.

 

I'm curious what other customers are experiencing:

  • Are you seeing similar results?
  • Do your findings primarily consist of OOTB platform functionality or custom code?
  • Have you been advised by ServiceNow that certain findings are expected and can be ignored?
  • Have you implemented exemptions, and if so, for which use cases?
  • Did the volume of findings increase following Zurich?
  • Have you identified any actual end-user or business impact related to these findings?

At the moment, our largest challenge is determining which findings represent actionable customer remediation versus expected platform behavior.

 

Any experiences, lessons learned, or guidance would be greatly appreciated.

 

Thank you.

1 REPLY 1

Jeff Boltz1
Mega Guru

Additional Question for Customers Reviewing Their Findings

 

Based on the product documentation, the expected remediation workflow is to identify the underlying script, determine whether it should be rewritten or exempted, and then implement the appropriate remediation.

 

However, many of the findings we are reviewing appear to reference platform components, analytics functionality, Flow Designer functionality, or application-provided functionality rather than clearly identifiable customer-developed scripts.

 

For organizations that have already completed this review:

 

  • How are you distinguishing customer-owned findings from platform-owned findings?
  • Have you received guidance from ServiceNow regarding which findings require customer remediation versus monitoring?
  • Were any findings ultimately addressed through Store application upgrades, product fixes, PRBs, or KB articles?
  • Are you tracking all findings as remediation candidates, or only those where a customer-owned script has been identified?
  • Have you identified any findings that resulted in actual business impact or user-facing issues?

One observation from our review is that occurrence count alone may not be the best indicator of remediation priority, as a significant percentage of activity appears to be concentrated within a very small number of recurring patterns.