Combined Application Vulnerability Response release notes for upgrades from Xanadu to Yokohama
Summarize
Summary of Combined Application Vulnerability Response Release Notes for Upgrades from Xanadu to Yokohama
This consolidated release note guide assists ServiceNow customers in preparing for upgrading Application Vulnerability Response (AVR) from the Xanadu release family to Yokohama. It summarizes new features, changes, removals, and activation details across these versions to ensure smooth transition and effective use of the application.
Show less
Key Features
- Customizable Age Calculations: Configure Age and Age Closed parameters for application vulnerable items based on Created, Opened, or First Found dates to better track vulnerability lifecycles.
- Workspace Enhancements: Search results open automatically in Vulnerability Manager or IT Remediation Workspaces rather than Classic UI, with role-based access to view and remediate application vulnerable items.
- System Properties Management: A new Properties module enables direct editing of system properties for easier configuration and management.
- Software Bill of Materials (SBOM) Management:
- License administration module allows classification and assignment of software licenses from SBOM uploads to manage license compliance and risk.
- Closed application vulnerable items reopen automatically upon vulnerability detection, controlled by a default-activated system property.
- Support for CycloneDX SBOM files with enhanced parsing for versions 1.4 to 1.6 and import of additional metadata and license information.
- Integration with Policy as Code Engine (PaCE) to identify stale or abandoned components marked as Non-compliant.
- SBOM uploads can be automated via GitHub Actions, improving continuous integration workflows.
- Vulnerability and Remediation Enhancements:
- Conditional re-evaluation of remediation properties for application vulnerable items directly from the Vulnerability Manager Workspace.
- Improved performance for scheduled jobs using multithreading to speed up vulnerability data processing.
- Manual creation of application remediation tasks in Vulnerability Manager and IT Remediation Workspaces, enabling better control over grouping and assignments.
- Manual ingestion of vulnerability data from external sources simplifies consolidation of penetration test findings.
- Penetration Testing Workspace: New workspace to monitor penetration test requests, findings, and progress with enhanced dashboards and assessment types including Emergency Release and Bug Bounty Program.
- Change Request Integration: Users with appropriate roles can create change requests from remediation tasks to expedite investigations for vulnerabilities associated with configuration items.
- GitHub Secrets Scanning: Ingest code secrets detected by GitHub to aid developers in mitigating security risks.
- Risk Score Tracking: Optionally log changes to risk scores of application vulnerable items in work notes for audit and review purposes.
Key Outcomes
- Improved visibility and management of application vulnerabilities and remediation tasks through enhanced workspaces and role-based access.
- Greater automation and integration capabilities with SBOM uploads, GitHub Actions, and third-party scanner data ingestion.
- Streamlined penetration testing workflows with new workspace and expanded assessment request types to better align with security standards.
- Efficient remediation tracking and change management through manual task creation and change request integration.
- Increased system performance for processing vulnerability data through multithreaded job execution.
- Enhanced license compliance management by classifying and assigning licenses from SBOM components.
Upgrade Considerations and Activation
Before upgrading to Yokohama, customers should review pre- and post-upgrade tasks to ensure system readiness. Application Vulnerability Response is installed via the ServiceNow Store and included as part of the Vulnerability Response application. Note that Software Bill of Materials applications require separate subscriptions.
System properties introduced or enhanced in these releases allow customization of key behaviors such as automatic reopening of closed vulnerabilities, workspace navigation, and risk score tracking.
Removals and Deprecations
The Close button for remediation tasks was removed from the classic UI and workspaces starting in Xanadu, with no additional removals or deprecations in Yokohama.
Additional Information
No changes were noted regarding browser requirements, accessibility, localization, or additional prerequisites between Xanadu and Yokohama.
For customers customizing Application Vulnerability Response, it is recommended to copy and adapt quick start tests post-upgrade to validate functionality.
Consolidated page of all release notes for Application Vulnerability Response from Xanadu to Yokohama.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Application Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Yokohama.
Important information for upgrading Application Vulnerability Response to Yokohama
Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
New features
Between your current release family and Yokohama, new features were introduced for Application Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Changes
Between your current release family and Yokohama, some changes were made to existing Application Vulnerability Response features.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Removed
Between your current release family and Yokohama, some Application Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
The Close button has been removed for a remediation task in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace. |
Yokohama |
No updates for this release. |
Deprecations
Between your current release family and Yokohama, some Application Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Activation information
Review information on how to activate Application Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
Install Application Vulnerability Response by requesting it from the ServiceNow Store. Application Vulnerability Response is included as a part of the Vulnerability Response application. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Yokohama |
Install Application Vulnerability Response by requesting it from the ServiceNow Store. Application Vulnerability Response is included as a part of the Vulnerability Response application. The Software Bill of Materials applications require a separate subscription. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Application Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Application Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Accessibility information
Review details on accessibility information for Application Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Localization information
If there are specific localization considerations for Application Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Application Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Application Vulnerability Response for more information. |
Yokohama |
See Application Vulnerability Response for more information. |