---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Configuring Software Bill of Materials {#ariaid-title1}

* Release version: Australia
* 
* Updated April 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Download and activate the required applications for the Software Bill of Materials (SBOM) application prior to uploading SBOM files.

## Configuration overview {#vr-sbom-configuring__cf-config-parent-checklist}

1. Download the required SBOM applications and any additional supported applications and integrations you want from the ServiceNow Store into your ServiceNow instance. See [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") and [Download an application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.") for more information about supported applications.

   The Vulnerability Response application is required for SBOM Response. Install The Vulnerability Response application prior to installing SBOM Response.
2. Locate the SBOM applications that you downloaded and select Install to activate them along with their dependencies in the following order. See [Install the supported applications for Software Bill of Materials](https://servicenow-prod.fluidtopics.net/eRMz24JKdGCJ15Mk0regPg "Download and activate the required applications for the Software Bill of Materials (SBOM) application prior to uploading files.").  
   * Vulnerability Response and its dependencies
   * Vulnerability Response Integration with NVD
   * Data Model for SBOM
   * SBOM Core
   * SBOM Response, which includes the OSV.dev and Deps.dev integrations and access to the capabilities of Policy as Code Engine (PaCE) in the SBOM Workspace.
   {#vr-sbom-configuring__ul_kdp_kzh_scc}
3. Configure the Deps.dev and OSV.dev integrations. These integrations are included with the SBOM Response application and are installed and activated automatically. You must initiate the OSV.dev Integration - Comprehensive on-demand from its integration record. See [Configuring the Deps.dev, OSV.dev, and PaCE integrations for Software Bill of Materials](https://servicenow-prod.fluidtopics.net/pT6RGXKjAqqpjOdiID8GCg "You can edit some of the parameters for the Deps.dev and OSV.dev integrations. There are also two code trigger versions of these integrations that are used strictly for internal workflows, and you should not initiate these integrations on-demand. Additionally, you can activate a scheduled job to create policies using Policy as Code Engine (PaCE).") and [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") for more information.

   The Deps.dev Integration provides you with information about components that are in Stale and Abandoned states for a given version of a
   package or library that you upload in your SBOM files.

   OSV.dev pulls vulnerability data from an open source database for a version of a package or library you upload in your SBOM files.
4. Refer to product documentation to configure any additional supported applications and integrations you installed. See [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/5tRtjEBZLs~2Uym3WljEBw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") and [Integrating Application Vulnerability Response with other applications](https://servicenow-prod.fluidtopics.net/r93WHsyNRy7m1s7pRtbYpw "Vulnerability Response includes support for third-party integrations.").
{#vr-sbom-configuring__cf-config-parent-tasks-ol}

