Combined Container Vulnerability Response release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Container Vulnerability Response Release Notes for Upgrades from Yokohama to Zurich
This consolidated release notes document summarizes the key updates, new features, changes, and important upgrade information for ServiceNow's Container Vulnerability Response application from the Yokohama release family to the Zurich release family. It is designed to help ServiceNow customers prepare for and understand the enhancements and modifications introduced in Zurich, including integration with third-party tools like Wiz, workspace improvements, and configuration changes.
Show less
Important Upgrade Information
- If upgrading directly to Zurich and not transitioning to Unified Security Exposure Management (USEM), customers should install a Container Vulnerability Response version below v30.x and the supported third-party integration apps accordingly.
- The Missing Assets [snvulwizmissingasset] table used in the Vulnerability Response Integration with Wiz is deprecated. After upgrading to version 1.1, existing Wiz integrations must be backdated by three days and re-run to ensure data consistency.
- Refer to the Vulnerability Response Compatibility Matrix and Release Schema Changes article in Now Support for detailed compatibility and version information.
New Features and Enhancements
- Workspace Enhancements (from Yokohama onwards):
- Support for an Unassign workflow for container vulnerable items (CVITs) and remediation tasks, enabling easier reassignment and triage management within Vulnerability Manager and IT Remediation workspaces.
- Manual creation of container remediation tasks in both Vulnerability Manager Workspace (roles:
snvulcontainer.vulnerabilityanalyst,snvulcontainer.vulnerabilityadmin) and IT Remediation Workspace (role:snvulcontainer.remediationowner), with grouping based on selected criteria. - Configurable granularity of CVITs using Registry and data source information, allowing customers to view image or Kubernetes-specific data.
- Additional CVIT table columns to track precise discovery, resolution, and last found timestamps for improved clarity and time zone accuracy.
- Optional logging of risk score changes to the Work Notes section to facilitate audit and tracking when enabled.
- Vulnerability Response Integration with Wiz (Zurich):
- Updated image repository name format to
registry/repositoryfor both new and existing container images to maintain consistency. - Enhanced repository field to include all repositories associated with an image.
- Added
sourceidcolumn to the Container Image Finding table for better mapping of Wiz imports. - Backfill integrations are activated by default; after upgrading to v1.1, related older backfill integrations become unnecessary.
- Import of test results from Wiz to detect cloud configuration compliance, mapping findings to Configuration Compliance application test results.
- Enhancements allow importing richer scanner data including namespaces and cluster hierarchy for discovered container images.
- Improved mapping and roll-up of fix information and vendor severity from Wiz findings to CVITs and Container Image Findings.
- Updated image repository name format to
Changes
- Introduction of a system property (
snvulcmn.relatedlist.setmaxrow) to configure maximum rows displayed in related lists on forms, improving readability and performance.
Removed and Deprecated Features
No features or functionality were removed or deprecated between Yokohama and Zurich beyond the noted deprecation of the Missing Assets table in the Wiz integration.
Activation and Installation
- Container Vulnerability Response and its third-party integrations are available through the ServiceNow Store. Customers should request installation from the Store and refer to the Store’s version history for cumulative release notes.
Accessibility and Usability Updates
- The Zurich release introduces the new Coral theme, which includes a dark theme option for both web and mobile, enhancing user comfort and readability.
Practical Implications for ServiceNow Customers
- You can streamline vulnerability management with enhanced workspace features such as unassign workflows and manual remediation task creation.
- Integration with Wiz is more robust, providing improved accuracy in vulnerability data import, cloud compliance insights, and remediation tracking.
- Configuration options now allow finer control over CVIT granularity and related list displays to optimize performance and user experience.
- Before upgrading, ensure that Wiz integrations are backdated and rerun as specified to maintain data integrity.
- Consider the new dark theme option to improve accessibility for users.
Consolidated page of all release notes for Container Vulnerability Response from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Container Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Container Vulnerability Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
If you are currently using Container Vulnerability Response, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Container Vulnerability Response and for upgrades to supported third-party integration applications. The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community. For more information about the released versions of the Container Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base. |
New features
Between your current release family and Zurich, new features were introduced for Container Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Container Vulnerability Response features.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Removed
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Container Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Container Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
Install Container Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Container Vulnerability Response and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Container Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Container Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Container Vulnerability Response for more information. |
Zurich |
See Container Vulnerability Response for more information. |