DevOps Vulnerability Integrations release notes

  • Release version: Store
  • Updated June 11, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of DevOps Vulnerability Integrations release notes

    DevOps Vulnerability Integrations is an add-on application for ITSM Pro customers that extends the capabilities of DevOps Change Velocity in ServiceNow. It enables you to connect various security tools and vulnerability scanners to your DevOps pipelines, retrieve vulnerability data, and incorporate this information into your change management process for improved security visibility and automation.

    Show full answer Show less

    Key Features

    • Integration with Security Tools: Supports popular security scanners such as Checkmarx (One and SAST), Veracode, and others for Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), and Software Composition Analysis (SCA).
    • Pipeline Integration: Connects with CI/CD pipelines including GitHub Actions, Jenkins, Azure DevOps, GitLab, and Harness to import security scan results directly into ServiceNow.
    • Evidence Collection Enhancements: Import-based evidence collection for GitLab and Jenkins improves instance efficiency by skipping step-level pipeline processing, accelerating change management and vulnerability data retrieval.
    • Localization: Improvements to localization frameworks enhance usability across different languages and regions.
    • Change Management Automation: Security scan results can be integrated into change policies and conditions to support automated change approvals and risk assessments.
    • Bug Fixes and UI Improvements: Resolved issues with tool grouping in the Tools module and other maintenance updates ensure a smoother user experience.

    Version Consistency

    Several releases primarily updated version numbers without code changes to maintain alignment with related DevOps applications, ensuring compatibility and consistent version tracking.

    What You Can Expect

    • Enhanced visibility of application vulnerabilities within your DevOps and change management workflows.
    • The ability to connect a wide range of security scanning tools and orchestration platforms to streamline vulnerability tracking.
    • Improved performance and efficiency in evidence collection from pipelines.
    • Better support for global teams through localization improvements.
    • Integration of security insights into change policies enabling more informed and automated change approval processes.

    Version history for the DevOps Vulnerability Integrations on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.

    Version history

    Version 7.0.0 - June 2026
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in related DevOps applications.
    Version 6.3.0 - March 2026
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in related DevOps applications.
    Version 6.2.0 - December 2025
    • New:
      • Import-based evidence collection for GitLab and Jenkins
      • Improve instance efficiency by skipping step-level pipeline processing for accelerated change management and evidence collection for GitLab and Jenkins orchestration tools.
    Version 6.1.0 - August 2025
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in related DevOps applications.
    Version 6.0.0 - May 2025
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in related DevOps applications.
    Version 5.1.0 - February 2025
    • New:
      • Harness tool integration with ServiceNow
        • Integrate the Harness orchestration tool with DevOps Change Velocity. This integration enables ServiceNow to connect, discover, import, process real-time events, and integrate CI/CD with change in ServiceNow for Harness pipelines
    • Fixed: Bug fixes
    Version 5.0.0 - November 2024
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in related DevOps applications.
    Version 4.1.0 - August 2024
    Changed: No code updates were made in this release. The release number has been updated to maintain consistency with changes in the related DevOps applications.
    Version 4.0.0 - May 2024
    Fixed: Issues related to security tool not being grouped correctly in the Tools module has been resolved.
    Version 3.1.0 - February 2024
    New: Localization framework improvements.
    Version 3.0.0 - November 2023
    • New:
      • Checkmarx support
        • Connect Checkmarx that is integrated with your CI/CD pipelines to DevOps Change Velocity to retrieve security scan results. This helps you determine how vulnerable your code is. Checkmarx scans that are configured on GitHub Actions, Jenkins, and Azure DevOps pipelines are supported in the base system. You can view the security scan results either in the related list of a Change Request or in the Pipeline UI in your ServiceNow Instance. You can use security results in defining change policies and conditions for change automation. Both Checkmarx One and Checkmarx SAST are supported.
    Version 2.0.0 - August 2023
    DevOps Vulnerability Integrations is an additional feature set that is available for ITSM Pro customers. You need to install this application separately besides installing DevOps Change Velocity. It helps you to connect your security tools to DevOps Change Velocity. It enables you to retrieve application vulnerabilities found during Dynamic Application Security Testing (DAST) or Static Application Security Testing (SAST) or Software Composition Analysis (SCA) scanning. These vulnerabilities are generally identified by third-party systems such as Veracode or other application vulnerability scanners that are available as out-of-the-box integrations for you to use.