Reviewing the Components module in the Software Bill of Materials Workspace
Summarize
Summary of Reviewing the Components module in the Software Bill of Materials Workspace
The Components module in the Software Bill of Materials (SBOM) Workspace provides ServiceNow customers with detailed, up-to-date information on the components imported into their software inventory. It highlights vulnerable, stale, abandoned, and high-risk components to help prioritize remediation efforts. The module supports role-based access (snsbomresp.sbomanalyst) and is accessible via Workspaces > SBOM Workspace > Components.
Show less
Data shown in the module depends on installed applications and is imported rather than calculated via live queries. Scores on the Home and Components pages are updated daily with performance enhancements for faster load times without impacting data storage.
Key Features
- SBOM Core Application: Provides an inventory of all uploaded components, including name, description, version, and BOM entity count.
- SBOM Response Application: Adds interactive graphs and detailed lists of components that are stale, abandoned, or vulnerable, helping identify components needing attention.
- Component Status Definitions:
- Stale: Versions more than two major releases and two years behind the latest.
- Abandoned: Components not updated for over two years.
- Vulnerable: Components with at least one high or greater severity vulnerability.
- High-Risk Combinations: Identifies stale and abandoned components with critical or high vulnerabilities, emphasizing those that can be fixed via updates or replacements.
- Fixability Status: Indicates whether vulnerabilities in components are completely fixable, partially fixable, or not fixable, helping prioritize remediation.
- License Classification: Breaks down components by license type to help assess license compliance risks.
- Version History and Details: Displays component version histories, Common Vulnerabilities and Exposures (CVE) data, and fixability information for each component.
Practical Use and Next Steps
ServiceNow customers can use the Components module to quickly identify and prioritize vulnerable or outdated software components within their inventories. By leveraging detailed vulnerability intelligence and license classification, they can better manage security and compliance risks.
To deepen understanding and improve risk management, customers are encouraged to review related resources on checking SBOM entities for vulnerabilities and classifying licenses within the workspace.
The Components module in the Software Bill of Materials (SBOM) Workspace displays current information about vulnerable, stale, abandoned, and high-risk combinations for the components you import.
Viewing the Components module
Role required: sn_sbom_resp.sbom_analyst
Navigate to .
What you can see in the module depends on the applications you have installed.
Imported data is not calculated and populated by live queries. Scores on the Home and Components pages are updated once daily with performance enhancements for reporting. This enhancement might provide you with faster load times for the scorecards on the Home and Components modules in the SBOM Workspace.
These enhancements have no impact on how or where data is stored.
| Installed application | Description |
|---|---|
| If you have installed SBOM Core | An inventory of all uploaded components that includes the following information:
|
| If you have installed SBOM Response | Select a graph or a number on the graph to view a list of associated records.
The Component List under the visualizations enables you to see the name, description, version, and entity counts. In the right panel, you can view a version history. The current version is highlighted in the version history. The Common Vulnerabilities and Exposure (CVE) and Fixability columns are also displayed. |
Assessing your risk with vulnerability intelligence
See Checking a Software Bill of Materials entity for vulnerabilities for more information about how to review vulnerability intelligence data in the workspace.
Assessing your risk with license compliance
See Classifying licenses and resolving component licenses in the Software Bill of Materials workspace for more information about how to license data your import with your components and viewing your over-all license compliance in the workspace.