---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://www.servicenow.com/docs/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# SBOM Core Response release notes

# SBOM Core Response release notes {#ariaid-title1}

Release version: Store  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of SBOM Core Response release notes

SBOM Core Response is a ServiceNow application designed to help organizations maintain a detailed, searchable inventory of open-source components in their environment through Software Bill of Materials (SBOM) management.
It supports ingesting SBOM files in CycloneDX and SPDX formats, enhancing visibility into component relationships, vulnerabilities, and licensing information.
Continuous improvements focus on performance, usability, data management, and integration with ServiceNow's Vulnerability Response capabilities.
Show full answer Show less  

## Key Features

* **SBOM Ingestion and Parsing:** Supports CycloneDX (XML/JSON) and SPDX (JSON) SBOM formats, with enhanced parsers for versions up to CycloneDX 1.6 and SPDX 2.3. Improved handling of component relationships, dependencies, and license data ensures comprehensive data capture.
* **Data Management and Cleanup:** Automated cleanup rules enable removal of older SBOM documents and metadata to reduce data volume, improving query and ingestion performance. Archival capabilities unlink and deactivate components from previous versions when newer SBOMs are ingested.
* **Performance Enhancements:** Parallel processing of SBOM files significantly reduces ingestion time for high-volume environments. Caching and optimized upsert operations improve throughput for frequently accessed data and BOM processing jobs.
* **SBOM Workspace Enhancements:** Bulk deletion of BOM entity records with automatic closure of associated Application Vulnerable Items (AVITs). UI improvements for accessibility, localization, and consistent visual design across platform languages.
* **Error Handling and Visibility:** Automatic timeout detection for stuck BOM processing with detailed metrics on processing duration. Enhanced error reporting captures specific failure reasons directly on BOM queue records for immediate troubleshooting.
* **Security and Access Controls:** Enforcement of proper access checks on internal SBOM Workspace data components ensures secure data handling without requiring customer intervention.
* **Integration and Automation:** Support for GitHub Actions integration to verify SBOM file queuing within ServiceNow AI Platform, aiding continuous integration and deployment workflows.

## Key Outcomes

* Improved efficiency and scalability in managing large volumes of SBOM data, enabling organizations to maintain up-to-date, actionable component inventories.
* Enhanced data quality and integrity through robust parsing, validation, and cleanup processes, reducing errors and empty component records.
* Greater operational visibility into SBOM processing status and failures, facilitating proactive management and faster resolution.
* Streamlined user experience with UI improvements, localization support, and bulk management capabilities, tailored for global and diverse user bases.
* Secure handling of SBOM data with enforced access controls, minimizing risk while supporting collaborative workflows.
* Seamless integration with vulnerability response processes by linking SBOM components to Application Vulnerable Items, enabling effective risk mitigation.  
Version history for the Vulnerability Response SBOM Core application on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## Version history

Version 6.5.1 - September 2026
:
    * New:
      * You can configure an automated cleanup of older SBOM documents and metadata from a dedicated configuration page where you create and manage your own cleanup rules. This cleanup helps you reduce your data volume in the SBOM data tables and might help you improve query and ingestion performance.
      * An archival capability that automatically unlinks and deactivates components from a prior SBOM version once a newer SBOM is ingested for the same application. Archiving helps you maintain the SBOM workspace so that you can focus on current, actionable data.
      {#store-secops-rn-vr-sbom-core__ul_sj3_n4p_lkc}
    * Changed: SBOM ingestion performance enhancements through parallel processing of uploaded SBOM files that significantly reduces processing time for customers with high-volume SBOM ingestion of hundreds of thousands of files per week.
    * Fixed:
      * An issue where CycloneDX SBOM ingestion failed when a file's vulnerability rating data was split across multiple partial rating objects instead of one complete object. Fixed by adding null-safe checks so ingestion now processes the available rating data instead of failing the whole file.
      * In some cases, SBOM ingestion could generate large numbers of blank, empty component records if a component relationship pointed at a missing or deleted reference. Each blank record then triggered another recount, compounding the problem. Fixed by validating references before use and preventing empty relationships from being created in the first place.
      * An issue where SBOM uploads could get stuck indefinitely in a "Processing" state due to a coding error in the routine that reconciles external references and hashes during ingestion. Fixed by correcting the reference so ingestion completes and queued uploads process normally.
      * An access-related security issue in an internal SBOM Workspace data component. Fixed by enforcing proper access checks throughout. No customer action is required.
      * An issue where SBOM Workspace UI action buttons did not appear for platform languages other than English. Fixed by correcting the identifier format so action buttons render correctly regardless of language setting.
      {#store-secops-rn-vr-sbom-core__ul_q1y_n4p_lkc}

Version 6.3.8 - August 2026
:
    * Fixed:
      * An UI issue on the SBOM Queue page where content cards had inconsistent padding and overly heavy shadows. Cards now render with improved spacing and a more consistent visual appearance.
      * An issue where the BOM Queue, SBOM Record pages, and BOM Document list incorrectly displayed, "No data available" for existing records due to an invalid default filter.
      {#store-secops-rn-vr-sbom-core__ul_wrp_lmw_bkc}

Version 6.3.2 - June 2026
:
    * Fixed:
      * SPDX entity-to-component relationships restored --- An issue where the SPDX parser previously created relationships only from the explicit relationships block, so SPDX BOMs that rely on the package list to imply dependencies showed almost no "Depends on" data on the BOM entity record, for example, \~171 dependencies instead of the expected \~2500. The parser now performs an additional pass that creates an entity-to-component relationship for every non-root package, matching the existing CycloneDX behavior.
      * Vendor SBOM upload errors --- Resolved errors raised during vendor SBOM uploads so SBOMs supplied by third parties can be ingested without manual intervention.
      * VR BOM Entries deletion restored --- The background-job configuration that drives VR BOM Entries deletion was packaged under a folder name that no longer matched the SBOM Sec Common plugin. The folder has been renamed so the background job is recognized again and BOM-entry deletion runs as expected.
      * Localized failure messages --- The CycloneDX parser's "failed components" message is now produced as complete translatable sentences with numbered parameters, so the message is fully translatable.
      {#store-secops-rn-vr-sbom-core__ul_y1d_wvf_kjc}

Version 6.3.1 - April 2026
:
    * New:
      * Automatic timeout handling for BOM records
        * Implemented automatic timeout handling for BOM records that remain stuck in the processing state for more than an hour. The system now tracks processing metrics by populating processing_startedtimestamp when BOM processing begins and calculating processing_durationwhen processing completes, times out, encounters errors, or is skipped, providing better visibility into BOM processing performance and reliability.
        {#store-secops-rn-vr-sbom-core__ul_zdj_hq4_53c}
      {#store-secops-rn-vr-sbom-core__ul_egf_hq4_53c}
    * Fixed: An issue where BOM processing failures updated the queue record status but left the error message field empty or generic. Error reasons are now properly captured on BOM queue records, providing you with immediate visibility into failure causes without requiring you to analyze error logs.
    {#store-secops-rn-vr-sbom-core__ul_rd1_hq4_53c}

Version 6.2.2 - December 2025
:
    * Changed: Improved UI accessibility by rectifying heading hierarchy, updating the labels, and aligning components with the latest platform standards.
    * Fixed
      * Fixed CycloneDX v1.6 author parsing logic to ensure stable and compliant SBOM processing.
      * Fixed SBOM import failures by rectifying the license-handling logic during SBOM processing.
      {#store-secops-rn-vr-sbom-core__ul_sjr_q5l_mhc}

Version 6.1.1 - August 2025
:
    * New:
      * Implemented caching improvements for frequently accessed data with optimized upsert operations for contacts, component relationships, BOM-component mappings, and license information.
      * Added two new scheduled jobs: an hourly job to process components with non-empty unprocessed_sbom_data, parsing and storing the information in appropriate tables before clearing the field
      * Enhanced BOM processing job that now handles all queued BOMs in a single execution instead of one at a time, significantly improving system throughput.
      {#store-secops-rn-vr-sbom-core__ul_m5b_nxn_bgc}

Version 6.0.6 - May 2025
:
    * Fixed:
      * Fixed issue with SBOM API upload throwing "Unsupported BOM format" error; SBOM files now upload successfully without content type issues.
      * The CycloneDX parser is refactored to improve SBOM ingestion performance by reducing database transactions, implementing an LRU cache, and improving extensibility through modular parsing functions for different CycloneDX model properties.
      {#store-secops-rn-vr-sbom-core__ul_bhz_2dc_cfc}

    {#store-secops-rn-vr-sbom-core__latest-store-secops-rn-vr-sbom-core}
{#store-secops-rn-vr-sbom-core__latest-store-secops-rn-vr-sbom-core}

Version 6.0.3 - February 2025
:
    * New:
      * Improvements to the Software Bill of Materials Workspace permit you to delete multiple BOM entity records and their related components from the Home (landing) page with bulk edit.
      * Any Application Vulnerable Items (AVIT)s that are associated with the BOM entities you delete automatically transition to 'Closed'.
      {#store-secops-rn-vr-sbom-core__ul_rwp_wz2_d2c}

Version 5.0.5 - December 2024
:   Minor fixes for this release.

Version 5.0.4 - November 2024
:
    * New: SBOM parser and validation improvements for the SBOM file upload.
    * Changed: Updates to the SBOM upload modal to include the "Business application" and "Product model" attributes.

Version 4.0.4 - August 2024
:
    * New:
      * Improvements to support SBOM files in CycloneDX format:
        * Activate the (sn_sbom_core.collect_properties) property to import information that is generally not supported.
        * View imported component data for declared and concluded licenses for SBOM files in versions 1.4 and later of CycloneDX.
        * SBOM parsing support is improved for the following CycloneDX versions and component types: Version 1.5 - Platform, Data, Device driver, Machine Learning model. Version 1.6 - Cryptographic.
        * Use GitHub Actions in your GitHub environment to determine if SBOM files generated in your CI/CD (continuous integration and continuous delivery/deployment) pipelines have been successfully queued in your ServiceNow AI Platform instance.
        {#store-secops-rn-vr-sbom-core__ul_xqp_jwp_ccc}
      {#store-secops-rn-vr-sbom-core__ul_mdg_jwp_ccc}
    {#store-secops-rn-vr-sbom-core__ul_fzd_hwp_ccc}

Version 3.0.3 - May 2024
:
    * New:
      * Upload SBOM files for the CycloneDX and SPDX standards.
      * XML and JSON formats are supported for CycloneDX for versions up to and including v1.4.
      * JSON format is supported for SPDX for versions up to and including v2.3.
      {#store-secops-rn-vr-sbom-core__ul_r3q_hm1_hbc}

Version 2.1.1 - February 2024
:
    * New:
      * View the SBOM inventory in the SBOM Workspace.
      * Component information displayed on the application vulnerable item (AVIT) record.
      * PURL validation support.
      {#store-secops-rn-vr-sbom-core__ul_owk_2xv_21c}

Version 2.0.2 - November 2023
:
    * New:
      * Created the \[sn_sbom_pkg_grp\] table for the Data Model.
        * Package manager and name is the unique key for this table.
        * Added ACLs on the table for the sn_sbom_dm.app_read role.
        * Records are created and updated by scripts, but you cannot create, write, or delete the data.
        {#store-secops-rn-vr-sbom-core__ul_kg1_wqj_fzb}
      * Added a report view ACL with the sn_sbom_dm.app_read role.
      * Added a reference to the package group table on the BOM Component table.
      * Updated the CycloneDX parser so it identifies the package group and populates its information into the \[sn_sbom_pkg_grp\] table. For each component of the type, 'library' the parser:
        * Determines and populates the package manager, name, and base PURL in the package group table.
        * Updates the Package group reference on that component's record.
        {#store-secops-rn-vr-sbom-core__ul_lg1_wqj_fzb}
      {#store-secops-rn-vr-sbom-core__ul_m21_wqj_fzb}

Version 1.0.8 - September 2023
:
    * New: Added the BOM Entities related list on the component form. You can see all the BOM entities that the component is used in on this related list.
    * Fixed: You can manually upload BOM documents as expected.
    {#store-secops-rn-vr-sbom-core__ul_t21_2gb_qyb}

Version 1.0.5 - August 2023
:   Initial release: SBOM Core helps organizations maintain the searchable inventory of all the open-source components used in their environment.

