Reviewing the Components module in the Software Bill of Materials Workspace
Summarize
Summary of Reviewing the Components module in the Software Bill of Materials Workspace
The Components module in the Software Bill of Materials (SBOM) Workspace provides insights into components you import, highlighting vulnerabilities, stale and abandoned statuses, and high-risk combinations. Users must have the role ofsnsbomresp.sbomanalystto access this module, which displays data based on installed applications.
Show less
Key Features
- Current Information: Displays details about vulnerable, stale, and abandoned components.
- Performance Enhancements: Daily updates improve load times for scorecards, enhancing reporting efficiency.
- Installed Applications:
- SBOM Core: Lists all uploaded components with their name, description, version, and BOM entity count.
- SBOM Response: Allows interaction with graphs to view associated records and vulnerabilities.
- Risk Assessment: Identifies stale (outdated) and abandoned components, along with those with high or critical vulnerabilities.
- Fixability Status: Indicates whether vulnerabilities can be completely or partially fixed.
- License Classification: Breaks down components by their license types, assisting in compliance assessments.
Key Outcomes
Utilizing the Components module enables ServiceNow customers to effectively manage software risks by identifying outdated and vulnerable components, understanding their fixability status, and ensuring compliance with licensing requirements. This proactive approach helps maintain a secure and compliant software environment.
The Components module in the Software Bill of Materials (SBOM) Workspace displays current information about vulnerable, stale, abandoned, and high-risk combinations for the components you import.
Viewing the Components module
Role required: sn_sbom_resp.sbom_analyst
Navigate to .
What you can see in the module depends on the applications you have installed.
Imported data is not calculated and populated by live queries. Scores on the Home and Components pages are updated once daily with performance enhancements for reporting. This enhancement might provide you with faster load times for the scorecards on the Home and Components modules in the SBOM Workspace.
These enhancements have no impact on how or where data is stored.
| Installed application | Description |
|---|---|
| If you have installed SBOM Core | An inventory of all uploaded components that includes the following information:
|
| If you have installed SBOM Response | Select a graph or a number on the graph to view a list of associated records.
The Component List under the visualizations enables you to see the name, description, version, and entity counts. In the right panel, you can view a version history. The current version is highlighted in the version history. The Common Vulnerabilities and Exposure (CVE) and Fixability columns are also displayed. |
Assessing your risk with vulnerability intelligence
See Checking a Software Bill of Materials entity for vulnerabilities for more information about how to review vulnerability intelligence data in the workspace.
Assessing your risk with license compliance
See Classifying licenses and resolving component licenses in the Software Bill of Materials workspace for more information about how to license data your import with your components and viewing your over-all license compliance in the workspace.