Combined Container Vulnerability Response release notes for upgrades from Xanadu to Yokohama
Summarize
Summary of Combined Container Vulnerability Response Release Notes for Upgrades from Xanadu to Yokohama
This consolidated release note guide helps ServiceNow customers prepare for upgrading Container Vulnerability Response from Xanadu to Yokohama versions. It combines all relevant updates, new features, changes, removals, and key upgrade considerations in one place to streamline the upgrade process and improve understanding of new capabilities.
Show less
Important Upgrade Information
- Review and complete pre- and post-upgrade tasks as specified before upgrading to Yokohama.
- No specific updates were noted for the Xanadu or Yokohama releases themselves, but features introduced between versions are detailed.
- Post-upgrade, run quick start tests to verify system functionality; customize tests if Container Vulnerability Response was customized.
- Install Container Vulnerability Response via the ServiceNow Store for Yokohama.
New Features
- Properties Module (v2.11.3): Added under Administration for easier, direct modification of system properties via the UI.
- Auto-Close Rules (v2.11.3): Define advanced filter criteria to automatically close older or stale container vulnerable items (CVITs).
- Age Parameter Customization (v2.11.3): Configure how “Age” and “Age Closed” durations are calculated based on Created, Opened, or First Found dates.
- Workspace Enhancements (v24.0.6 and v2.13):
- Open search results in Vulnerability Manager or IT Remediation Workspace instead of Classic UI, based on user roles.
- Role-based access for viewing and remediating container vulnerable items in respective workspaces.
- Navigate directly to list pages from the Container Vulnerability Response module with optional system property.
- Option to hide record counts on lists for cleaner views.
- Enable automatic refresh of Home page dashboard widgets.
- Bulk re-evaluation of remediation properties such as assignments, tasks, exceptions, and risk scores.
- Support for “Unassign” workflow in workspaces with optional approval requests to manage CVIT ownership.
- Manual creation of container remediation tasks in both Vulnerability Manager and IT Remediation Workspaces with appropriate roles.
- Granularity Configuration (v2.12.2): Configure CVIT granularity using Registry and data source to view image or Kubernetes details.
- Additional CVIT Metadata (v2.12.2): Display precise timestamps for discovery, status changes, and findings, supporting time zone clarity.
- Risk Score Work Notes (v2.12.2): Optional system property to log risk score changes in work notes, updating only on change.
- Performance Improvements: Enhanced scheduled job processing with multithreading for faster bulk data handling.
- Prisma Registry Integration: Ingest static image vulnerability findings from Prisma Cloud Compute scans into ServiceNow Container Vulnerability Response.
- Assignment Rules Enhancements: Use Prisma Cloud Compute data such as cloud account IDs, image namespaces, registry hosts, labels, and vendor status to create or update assignment rules.
Changes
- The admin role (snvul.vulnerabilityadmin) lost the privilege to delete container vulnerable items; this is now assigned to the granular role snvul.delete.
Removed Features
- The “Close” button was removed from remediation tasks in Classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.
Activation and Additional Notes
- Container Vulnerability Response must be installed via the ServiceNow Store for Yokohama.
- No new browser, localization, accessibility, or additional technical requirements were introduced between Xanadu and Yokohama.
Key Outcomes for ServiceNow Customers
- Upgrade preparation is streamlined with clear pre- and post-upgrade tasks and consolidated release notes.
- Improved management of container vulnerabilities via new UI modules and configurable auto-close rules reduces manual effort.
- Enhanced workspace functionality supports better role-based access, task management, and workflow control including unassign and reassignment capabilities.
- Integration with Prisma Cloud Compute enriches vulnerability data ingestion for container environments.
- Performance improvements and bulk remediation re-evaluation improve operational efficiency and vulnerability response speed.
- Customers can expect a more user-friendly and efficient Container Vulnerability Response experience aligned with modern workspace navigation and automation capabilities.
Consolidated page of all release notes for Container Vulnerability Response from Xanadu to Yokohama.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Container Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Yokohama.
Important information for upgrading Container Vulnerability Response to Yokohama
Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
New features
Between your current release family and Yokohama, new features were introduced for Container Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Changes
Between your current release family and Yokohama, some changes were made to existing Container Vulnerability Response features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
No updates for this release. |
Removed
Between your current release family and Yokohama, some Container Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
The Close button has been removed for a remediation task in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace. |
Yokohama |
No updates for this release. |
Deprecations
Between your current release family and Yokohama, some Container Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Activation information
Review information on how to activate Container Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
Install Container Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Accessibility information
Review details on accessibility information for Container Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Localization information
If there are specific localization considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Container Vulnerability Response for more information. |
Yokohama |
See Container Vulnerability Response for more information. |