Combined Container Vulnerability Response release notes for upgrades from Xanadu to Zurich
Summarize
Summary of Combined Container Vulnerability Response Release Notes for Upgrades from Xanadu to Zurich
This consolidated release notes document provides ServiceNow customers with a comprehensive view of new features, changes, and important upgrade information for Container Vulnerability Response (CVR) from the Xanadu through Zurich releases. It is designed to assist in preparing for upgrades, understanding enhancements, and ensuring smooth transitions between versions.
Show less
Key upgrade guidance includes reviewing pre- and post-upgrade tasks and noting deprecated components, such as the Missing Assets table for the Vulnerability Response Integration with Wiz.
New Features
- Properties Module (Xanadu v2.11.3): Added under Administration for easy modification of system properties directly within the interface.
- Auto-Close Rules: Define advanced conditions to automatically close stale Container Vulnerable Items (CVITs).
- Customizable Age Calculations: Configure how Age and Age Closed durations are calculated using Created, Opened, or First Found dates.
- Workspace Enhancements (Yokohama and Zurich):
- Open search results automatically in Vulnerability Manager or IT Remediation Workspaces instead of Classic UI.
- Role-based access to container vulnerable items and remediation tasks within these workspaces.
- UI improvements such as hiding record counts, auto-refreshing dashboards, and streamlined navigation.
- Support for unassigning and reassigning CVITs to improve assignment accuracy.
- Manual creation of container remediation tasks in both Vulnerability Manager and IT Remediation Workspaces.
- Granularity Configuration: Set CVIT granularity using Registry and data source information to better reflect image or Kubernetes data.
- Risk Score Tracking: Optionally log changes to container vulnerable item risk scores in Work Notes.
- Performance Improvements: Enhanced multithreaded processing of scheduled jobs for faster rollup of CVIT data.
- Prisma Registry Integration: Import static image findings from Prisma registry scans into CVR.
- Vulnerability Response Integration with Wiz (Zurich):
- Updated image repository naming conventions for consistency.
- Backfill integrations now default active; existing integrations require backdating and rerunning post-upgrade.
- Improved mapping of fix status, vendor severity, and cluster/namespace data to strengthen vulnerability insights.
- Import of cloud configuration test results from Wiz to enforce security policies through Configuration Compliance application.
- Dark Theme Support: Introduction of a dark theme option to improve readability and reduce eye strain in web and mobile experiences (Zurich).
Changes
- Privilege Updates: Admin role no longer has deletion rights for CVITs; this is now managed via a dedicated granular role.
- Related Lists Configuration: Ability to limit maximum rows shown on related lists for improved UI performance and readability.
Removed Features
- The Close button for remediation tasks has been removed from Classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.
Upgrade Considerations
- Review deprecated components—specifically the Missing Assets table for Wiz integration—and perform necessary backdating and reruns as detailed.
- For customers not upgrading to Unified Security Exposure Management (USEM), ensure installation of Container Vulnerability Response versions below v30.x and compatible third-party integrations.
- Post-upgrade, run quick start tests to verify expected functionality; customize tests if CVR has been tailored.
Activation and Installation
Container Vulnerability Response and related third-party integrations can be requested and installed via the ServiceNow Store. Customers should refer to the Store for app availability and submission guidelines.
Practical Benefits for ServiceNow Customers
- Enhanced automation and workflow efficiency through auto-close rules, improved assignment management, and workspace usability enhancements.
- Greater flexibility in configuring vulnerability item attributes and risk scoring for tailored vulnerability management.
- Improved integration and data fidelity with external scanners and cloud security tools such as Wiz and Prisma Registry.
- Performance optimizations that reduce processing time for vulnerability data aggregation.
- Modernized UI experience with workspace enhancements and optional dark theme for user comfort.
These improvements empower security and operations teams to better identify, triage, and remediate container vulnerabilities within the ServiceNow platform, contributing to a stronger security posture and more efficient vulnerability response workflows.
Consolidated page of all release notes for Container Vulnerability Response from Xanadu to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Container Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.
Important information for upgrading Container Vulnerability Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
If you are currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications. The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community. For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base. |
New features
Between your current release family and Zurich, new features were introduced for Container Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Container Vulnerability Response features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
No updates for this release. |
Zurich |
|
Removed
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
The Close button has been removed for a remediation task in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Container Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
Install Container Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Container Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Container Vulnerability Response for more information. |
Yokohama |
See Container Vulnerability Response for more information. |
Zurich |
See Container Vulnerability Response for more information. |