Combined Container Vulnerability Response release notes for upgrades from Xanadu to Zurich

  • Release version: Zurich
  • Updated July 20, 2026
  • 12 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Container Vulnerability Response Release Notes for Upgrades from Xanadu to Zurich

    This consolidated release notes document provides ServiceNow customers with a comprehensive view of new features, changes, and important upgrade information for Container Vulnerability Response (CVR) from the Xanadu through Zurich releases. It is designed to assist in preparing for upgrades, understanding enhancements, and ensuring smooth transitions between versions.

    Show full answer Show less

    Key upgrade guidance includes reviewing pre- and post-upgrade tasks and noting deprecated components, such as the Missing Assets table for the Vulnerability Response Integration with Wiz.

    New Features

    • Properties Module (Xanadu v2.11.3): Added under Administration for easy modification of system properties directly within the interface.
    • Auto-Close Rules: Define advanced conditions to automatically close stale Container Vulnerable Items (CVITs).
    • Customizable Age Calculations: Configure how Age and Age Closed durations are calculated using Created, Opened, or First Found dates.
    • Workspace Enhancements (Yokohama and Zurich):
      • Open search results automatically in Vulnerability Manager or IT Remediation Workspaces instead of Classic UI.
      • Role-based access to container vulnerable items and remediation tasks within these workspaces.
      • UI improvements such as hiding record counts, auto-refreshing dashboards, and streamlined navigation.
      • Support for unassigning and reassigning CVITs to improve assignment accuracy.
      • Manual creation of container remediation tasks in both Vulnerability Manager and IT Remediation Workspaces.
    • Granularity Configuration: Set CVIT granularity using Registry and data source information to better reflect image or Kubernetes data.
    • Risk Score Tracking: Optionally log changes to container vulnerable item risk scores in Work Notes.
    • Performance Improvements: Enhanced multithreaded processing of scheduled jobs for faster rollup of CVIT data.
    • Prisma Registry Integration: Import static image findings from Prisma registry scans into CVR.
    • Vulnerability Response Integration with Wiz (Zurich):
      • Updated image repository naming conventions for consistency.
      • Backfill integrations now default active; existing integrations require backdating and rerunning post-upgrade.
      • Improved mapping of fix status, vendor severity, and cluster/namespace data to strengthen vulnerability insights.
      • Import of cloud configuration test results from Wiz to enforce security policies through Configuration Compliance application.
    • Dark Theme Support: Introduction of a dark theme option to improve readability and reduce eye strain in web and mobile experiences (Zurich).

    Changes

    • Privilege Updates: Admin role no longer has deletion rights for CVITs; this is now managed via a dedicated granular role.
    • Related Lists Configuration: Ability to limit maximum rows shown on related lists for improved UI performance and readability.

    Removed Features

    • The Close button for remediation tasks has been removed from Classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.

    Upgrade Considerations

    • Review deprecated components—specifically the Missing Assets table for Wiz integration—and perform necessary backdating and reruns as detailed.
    • For customers not upgrading to Unified Security Exposure Management (USEM), ensure installation of Container Vulnerability Response versions below v30.x and compatible third-party integrations.
    • Post-upgrade, run quick start tests to verify expected functionality; customize tests if CVR has been tailored.

    Activation and Installation

    Container Vulnerability Response and related third-party integrations can be requested and installed via the ServiceNow Store. Customers should refer to the Store for app availability and submission guidelines.

    Practical Benefits for ServiceNow Customers

    • Enhanced automation and workflow efficiency through auto-close rules, improved assignment management, and workspace usability enhancements.
    • Greater flexibility in configuring vulnerability item attributes and risk scoring for tailored vulnerability management.
    • Improved integration and data fidelity with external scanners and cloud security tools such as Wiz and Prisma Registry.
    • Performance optimizations that reduce processing time for vulnerability data aggregation.
    • Modernized UI experience with workspace enhancements and optional dark theme for user comfort.

    These improvements empower security and operations teams to better identify, triage, and remediate container vulnerabilities within the ServiceNow platform, contributing to a stronger security posture and more efficient vulnerability response workflows.

    Consolidated page of all release notes for Container Vulnerability Response from Xanadu to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Container Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Container Vulnerability Response to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    If you are currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications.

    The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community.

    For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.

    New features

    Between your current release family and Zurich, new features were introduced for Container Vulnerability Response.

    Release Release notes

    Xanadu

    New Properties module
    Starting with v2.11.3 of Container Vulnerability Response, a new Properties module has been added to the navigation menu under the Administration section. This module enables direct modification of the values, offering a user-friendly method to manage and update system properties directly from the interface.
    Create auto-close rules for Container Vulnerability Response
    Starting with v2.11.3 of Container Vulnerability Response, define auto-close rules with advanced conditions to automatically close older or stale CVITs based on defined filter criteria on container vulnerabilities.
    Customize the calculation of Age and Age closed parameters of a container vulnerable item
    Starting with v2.11.3 of Container Vulnerability Response, the Age and Age Closed durations of a Container Vulnerable Item can be configured to be calculated from the date in the Created, Opened, or First Found fields.
    Open the search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI
    Starting with v24.0.6 of Vulnerability Response, automatically open your search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI, by adjusting the application scope in the unified navigation bar to Vulnerability Manager Workspace or IT Remediation Workspace respectively. These application scopes are available to you based on your assigned role.
    Vulnerability Manager Workspace access to the sn_vul_container.read_all role
    Starting with v24.0.6 of Vulnerability Response, as a user with the sn_vul_container.read_all role, you can view the container vulnerable items in the Vulnerability Manager Workspace.
    IT Remediation Workspace access to the sn_vul_container.read_assigned role
    Starting with v24.0.6 of Vulnerability Response, as a user with the sn_vul_container.read_assigned role, you can view the container vulnerable items assigned to you and your assignment groups in the IT Remediation Workspace and remediate them.
    Navigate to the List page in the Vulnerability Manager Workspace or IT Remediation Workspace by selecting the links from the All menu
    Starting with v24.0.6 of Vulnerability Response, when you enable the 'sn_vul_cmn_ws.navigate_to_workspace' system property, selecting predefined filter links in the Container Vulnerability Response module from the 'All' menu will automatically open these links in the List page in the Vulnerability Manager Workspace or IT Remediation Workspace based on your role.
    Hide the record count on the lists in the Vulnerability Manager Workspace and IT Remediation Workspace
    Starting with v24.0.6 of Vulnerability Response, you can hide the record count on the lists in the List page of the Vulnerability Manager Workspace and IT Remediation Workspace, by adding the table names to the glide.ui.list.seismic.omit.count system property.
    Enable automatic refresh for the Home page dashboard in the Vulnerability Manager Workspace
    Starting with v24.0.6 of Vulnerability Response, when creating and editing filters on the Container Vulnerabilities tab on the Home page of the Vulnerability Manager Workspace, you can configure the widgets to automatically refresh. Otherwise, you can manually refresh the widgets by selecting the Refresh button on the Container Vulnerabilities tab.
    Re-evaluating remediation properties for all records in the Vulnerability Manager Workspace
    Starting with v24.0.6 of Vulnerability Response, you can evaluate the remediation properties for all the Container Vulnerable Items from the Container Vulnerable Items list by selecting the All items in the Record selection field of the Re-evaluate remediation properties modal in the Vulnerability Manager Workspace.
    Re-evaluate the remediation properties for container vulnerable items in the Vulnerability Manager Workspace
    Select the container vulnerable items conditionally for reevaluating the following remediation properties in Vulnerability Manager Workspace:
    • Assignments
    • Remediation tasks
    • Remediation target date
    • Exceptions (Vulnerability Response v24.0.6)
    • Risk score
    Enhanced processing performance of scheduled job
    The Rollup container vulnerable item values to vulnerability and group scheduled job is enhanced to create background jobs with multithreading capabilities. This upgrade involves segmenting the job into several smaller child jobs, which are executed either in parallel or concurrently. This modification enables processing of multiple records simultaneously, thus significantly speeding up the overall task.
    for Container Vulnerability Response

    After upgrades and deployments of new applications or integrations, run quick start tests to verify that Container Vulnerability Response works as expected. If you customized Container Vulnerability Response, copy the quick start tests and configure them for your customizations.

    Vulnerability Response Prisma Registry Integration
    Now you can ingest the static image findings obtained from the Prisma registry scan into the ServiceNow Container Vulnerability Response.

    Yokohama

    Enhancements to the Vulnerability Manager and IT Remediation workspaces starting with version 2.13
    The Unassign workflow is supported for container vulnerable items (CVITs) and remediation tasks (CVULs).
    • Streamline vulnerability assignments in the workspaces with the Unassign UI action from the more actions menu on a CVIT.
    • Reassign incorrectly assigned CVITs, clarify ownership for reassessment, and maintain accurate triage records in workspace views.
    • You have the option to send unassign requests for approval prior to clearing the Assigned to and Assignment group fields on records.

    [Placeholder link text to key cvr-assignment-rules]. You can use the following values imported from the Prisma Cloud Compute integration as conditions when you create or update your assignment rules to help you track ownership across your container environments.

    • Cloud account IDs
    • Image namespaces
    • Registry
    • Hosts
    • Labels
    • Status - Vendor status for a resolved (Fixed) vulnerability
    Create container remediation tasks manually in the Vulnerability Manager Workspace
    With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, you can create container remediation tasks manually by selecting some or all the records in the Container vulnerable items lists in the Vulnerability Manager Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating container remediation tasks.
    Create container remediation tasks manually in the IT Remediation Workspace
    With the role sn_vul_container.remediation_owner, you can create container remediation tasks manually by selecting some or all the records in the Container vulnerable items’ lists in the IT Remediation Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating container remediation tasks.
    Configure container vulnerable items (CVITs) granularity using Registry and data source
    Starting with v2.12.2 of Container Vulnerability Response, you can configure the granularity of container vulnerable items (CVITs) using Registry information and data sources. Depending on the chosen data source, you can view either image or kubernetes information related to a CVIT record.
    Additional columns in the container vulnerable items (CVITs) table
    Starting with v2.12.2 of Container Vulnerability Response, you can see the precise date and time when a CVIT was first discovered, last opened, resolved, and last found, ensuring clarity and accounting for different time zones.
    View risk score details of a container vulnerable item in the Work Notes section
    Starting with v2.12.2 of Container Vulnerability Response, the system property sn_sec_cmn.risk_score_changes_add_worknotes is inactive by default. If you enable it, only then you can see all the changes related to the risk score of a container vulnerable item in the Work notes section. Additionally, the work notes are updated only if there’s a change in the risk score.

    Zurich

    Enhancements to the Vulnerability Response Integration with Wiz
    • The image repository name format for new and existing discovered container images has been updated to align with the discovery format. The supported format is registry/repository. A separate finding is created for a repository present in each registry.
    • Appended all repositories that are associated with an image to the Repository field on the discovered container image records.
    • Added the source_id column to the Container Image Finding table (sn_vul_container_image_findings) and mapped the id attribute from the Wiz import to this field on findings records.
    • The default integration instance parameter for configuring finding keys for the Container Vulnerability Integration includes src_ci, vulnerability, package, image_layer, and image_repository.
    Enhancements to the Vulnerability Response Integration with Wiz

    The Missing Assets [sn_vul_wiz_missing_asset] is deprecated. After updating to version 1.1, you must backdate your existing primary Wiz integrations by three days and run them.

    The backfill integrations are activated by default.

    After you run them after updating to v1.1, the following backfill integrations are no longer required:
    • Host Vulnerability Backfill Integration
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    Data for resources that have the validated_at_runtime flag set to 'yes' is imported and populated on detections.

    The CMDB internet-facing field on the discovered item is mapped to Limited Internet Exposure on findings.

    Fix information that includes 'Fix available', 'Partial fix available', 'No fix available', and 'Fix version' from the [fix_available] and [fix_version] columns is rolled up to CVITs from findings. Note: If there are two or more findings on a CVIT, the fixed version might only apply to one. In that case, 'Partial fix available' is rolled up to the CVIT.

    The Wiz vendor severity attribute is mapped to the 'Source severity' column on findings records in the Container Image Findings [sn_vul_container_image_findings] table.

    The cluster and namespace is evaluated for all the following entity Types: DEPLOYMENT, DAEMON_SET, STATEFUL_SET, POD.

    Import container vulnerability data with the Vulnerability Response Integration with Wiz
    Import configuration test results from Wiz to detect non-compliant cloud configurations. Findings are mapped to cloud test results (CTRs) in the Configuration Compliance application to help you enforce security policies and standards across your cloud environment.
    Enhancements to imported scanner results
    Enhancements support more scanner data on imports. Namespaces and hierarchy cluster are considered and populated in the discovered container image [sn_vul_container_image] table if this data is imported.

    Changes

    Between your current release family and Zurich, some changes were made to existing Container Vulnerability Response features.

    Release Release notes

    Xanadu

    Deprecated the privilege to delete a container vulnerable item for the Admin role
    As an admin with the sn_vul.vulnerability_admin role, you can't delete a container vulnerable item. This privilege is now given to the sn_vul.delete granular role.

    Yokohama

    No updates for this release.

    Zurich

    Configure maximum rows in related lists
    To improve readability and performance, you can now limit the number of rows shown in related lists on forms by setting the system property sn_vul_cmn.related_list.set_max_row.

    Removed

    Between your current release family and Zurich, some Container Vulnerability Response features or functionality were removed.

    Release Release notes

    Xanadu

    The Close button has been removed for a remediation task in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Container Vulnerability Response features or functionality were deprecated.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Container Vulnerability Response.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Install Container Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Additional requirements

    If any additional requirements were introduced or changed for Container Vulnerability Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Container Vulnerability Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Container Vulnerability Response, such as specific requirements or compliance levels.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    Dark theme
    The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.

    Localization information

    If there are specific localization considerations for Container Vulnerability Response we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Container Vulnerability Response we have noted them here.

    Release Release notes

    Xanadu

    • Reevaluate the risk score, assignments, remediation target date, exceptions, and remediation task for a specific set of container vulnerable items in Vulnerability Manager Workspace.

    See Container Vulnerability Response for more information.

    Yokohama

    • With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, create container remediation tasks manually in the Vulnerability Manager Workspace.
    • With the role sn_vul_container.remediation_owner, create container remediation tasks manually in the IT Remediation Workspace.

    See Container Vulnerability Response for more information.

    Zurich

    • If you are currently using Container Vulnerability Response and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management release notes for more information about USEM and the Unified Security Exposure Management migration.
    • Import container image vulnerability data from the Wiz scanners into container vulnerable items (CVITs) with the Vulnerability Response Integration with Wiz.
    • With the sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin role, create container remediation tasks manually in the Vulnerability Manager Workspace.
    • With the role sn_vul_container.remediation_owner, create container remediation tasks manually in the IT Remediation Workspace.

    See Container Vulnerability Response for more information.