Combined Container Vulnerability Response release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Container Vulnerability Response release notes for upgrades from Yokohama to Zurich
This document consolidates release notes for the Container Vulnerability Response application covering upgrades from the Yokohama release family to Zurich. It provides ServiceNow customers with essential upgrade preparation tasks, new features, changes, and deprecations relevant to Container Vulnerability Response. The notes also address integration updates with third-party scanners like Wiz and clarify activation and compatibility requirements for the Zurich release.
Show less
Important Upgrade Information
- If not upgrading to Unified Security Exposure Management (USEM), customers should install Container Vulnerability Response versions below v30.x and compatible third-party integrations.
- The Missing Assets [snvulwizmissingasset] table used in backfill integrations with Wiz is deprecated. After upgrading to version 1.1 of the Wiz integration, existing primary integrations must be backdated by three days and rerun to ensure data consistency.
- For detailed compatibility and schema changes, customers should consult the Vulnerability Response Compatibility Matrix and related knowledge base articles.
Key Features Introduced Between Yokohama and Zurich
- Unassign Workflow Support: From Yokohama onwards, the ability to unassign container vulnerable items (CVITs) and remediation tasks (CVULs) is supported in Vulnerability Manager and IT Remediation workspaces, with options for approval workflows.
- Manual Creation of Container Remediation Tasks: Users with appropriate roles can manually create container remediation tasks by selecting CVITs in both Vulnerability Manager and IT Remediation workspaces. Grouping criteria can be applied during task creation.
- Enhanced CVIT Granularity and Data: Starting in v2.12.2, customers can configure CVIT granularity using Registry and data source information, view detailed timestamps for CVIT lifecycle events, and optionally track risk score changes in work notes.
- Vulnerability Response Integration with Wiz Enhancements (Zurich):
- Updated image repository name format to registry/repository for container images.
- Additional fields added such as sourceid in findings for better mapping.
- Backfill integrations now activated by default and some older backfill integrations are no longer required.
- Improved mapping of fix information, vendor severity, and cluster/namespace evaluation across entity types.
- Import of cloud configuration test results to support compliance enforcement in Configuration Compliance application.
- Imported Scanner Results Enhancements: Improved support for scanner data imports including namespaces and cluster hierarchies.
Changes
- System property
snvulcmn.relatedlist.setmaxrowintroduced to limit maximum rows in related lists on forms, improving UI readability and performance.
Removals and Deprecations
- No removals or additional deprecations beyond the noted deprecation of the Missing Assets table for Wiz integration.
Activation and Installation
- Container Vulnerability Response and related third-party integrations are installed by requesting them from the ServiceNow Store.
- Customers should review cumulative release notes and version history available in the ServiceNow Store for full context.
Additional Information
- Accessibility: The Zurich release introduces the Coral theme with a dark mode option designed to improve readability and reduce eye strain across web and mobile interfaces.
- Browser and Localization: No updates or new requirements were introduced in these areas.
- Highlight Notes: Manual creation of remediation tasks remains a core feature, and customers interested in migrating to USEM should refer to the Unified Security Exposure Management release notes.
Practical Benefits for ServiceNow Customers
- Enhanced vulnerability management workflows with unassign and manual remediation task capabilities improve operational control and accuracy.
- Improved integration with Wiz scanner data enhances vulnerability insights, compliance tracking, and remediation accuracy.
- Configuration options for CVIT granularity and detailed timestamps aid in precise vulnerability tracking and reporting.
- Performance improvements and UI enhancements provide a better user experience in managing container vulnerabilities.
- Clear upgrade guidance and compatibility information support smooth transitions to Zurich with minimal disruption.
Consolidated page of all release notes for Container Vulnerability Response from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Container Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Container Vulnerability Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
If you are currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications. The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community. For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base. |
New features
Between your current release family and Zurich, new features were introduced for Container Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Container Vulnerability Response features.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Removed
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Container Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
Install Container Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Container Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Container Vulnerability Response for more information. |
Zurich |
See Container Vulnerability Response for more information. |