Reviewing the Components module in the Software Bill of Materials Workspace
Summarize
Summary of Reviewing the Components module in the Software Bill of Materials Workspace
The Components module within the Software Bill of Materials (SBOM) Workspace provides ServiceNow customers with detailed insights into the status of software components they import. It highlights vulnerable, stale, abandoned, and high-risk components, enabling effective risk management and compliance oversight. This module supports roles with thesnsbomresp.sbomanalystpermission and is accessed viaWorkspaces > SBOM Workspace > Components.
Show less
Data shown is imported rather than live-calculated, with scores refreshed daily to optimize performance and improve load times without impacting data storage.
Key Features
- SBOM Core Application: Provides an inventory of all imported components detailing their name, description, version, and associated BOM entity counts.
- SBOM Response Application: Enables interactive visualizations such as graphs showing stale, abandoned, and vulnerable components. Selecting graph elements reveals associated records for deeper analysis.
- Component Classifications:
- Stale components: Versions more than two major versions and two years behind the latest.
- Abandoned components: Not updated for over two years.
- Vulnerable components: Components with vulnerabilities rated High or above.
- High-risk combinations: Components that are stale or abandoned and have at least one Critical or High severity vulnerability as identified through Deps.dev integration.
- Fixability Status: Indicates whether vulnerabilities in components are completely fixable, partially fixable, or not fixable, helping prioritize remediation efforts.
- License Classification: Displays totals and breakdowns of components based on license types, supporting compliance management.
- Component Details: Includes version history, highlighting the current version, along with Common Vulnerabilities and Exposures (CVE) and fixability information.
Practical Benefits for ServiceNow Customers
- Quick identification of components requiring immediate attention due to vulnerabilities or outdated status.
- Enhanced reporting performance with daily score updates and faster load times for dashboards.
- Support for prioritizing remediation efforts with fixability insights, ensuring efficient vulnerability management.
- License classification enables thorough license compliance reviews within the SBOM Workspace.
Additional Guidance
For detailed vulnerability assessment, customers can refer to guidance on checking SBOM entities for vulnerabilities within the workspace. For managing license compliance, resources explain classifying and resolving component licenses to maintain overall compliance.
The Components module in the Software Bill of Materials (SBOM) Workspace displays current information about vulnerable, stale, abandoned, and high-risk combinations for the components you import.
Viewing the Components module
Role required: sn_sbom_resp.sbom_analyst
Navigate to .
What you can see in the module depends on the applications you have installed.
Imported data is not calculated and populated by live queries. Scores on the Home and Components pages are updated once daily with performance enhancements for reporting. This enhancement might provide you with faster load times for the scorecards on the Home and Components modules in the SBOM Workspace.
These enhancements have no impact on how or where data is stored.
| Installed application | Description |
|---|---|
| If you have installed SBOM Core | An inventory of all uploaded components that includes the following information:
|
| If you have installed SBOM Response | Select a graph or a number on the graph to view a list of associated records.
The Component List under the visualizations enables you to see the name, description, version, and entity counts. In the right panel, you can view a version history. The current version is highlighted in the version history. The Common Vulnerabilities and Exposure (CVE) and Fixability columns are also displayed. |
Assessing your risk with vulnerability intelligence
See Checking a Software Bill of Materials entity for vulnerabilities for more information about how to review vulnerability intelligence data in the workspace.
Assessing your risk with license compliance
See Classifying licenses and resolving component licenses in the Software Bill of Materials workspace for more information about how to license data your import with your components and viewing your over-all license compliance in the workspace.