---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# Vulnerability Response Integration with Black Duck release notes

# Vulnerability Response Integration with Black Duck release notes {#ariaid-title1}

Release version: Store  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read  
Version history for the Vulnerability Response Integration with Black Duck application on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## Version history

Version 30.5.1 - September 2026 (USEM)
:
    * Fixed:
      * An issue with Black Duck vulnerability scan results import failures if the CVSS v3 impact sub-score returned by Black Duck was null or empty. By including the impact sub-score in the imported record only when Black Duck provides a valid, non-empty value, records without one now are imported as expected. This correction ensures all reported Black Duck vulnerability items import successfully.
      * An issue with CVE-based vulnerabilities identified by Black Duck that were being stored as Application Vulnerability Entry records instead of NVD entry records and potentially impacted severity and CVSS impact scoring. By treating records that contain a CVE prefix as NVD entry records and storing them accordingly, entries without a CVE prefix continue to be recorded as Application Vulnerability Entry records. This correction restores the proper classification so CVE metadata and impact scoring are associated with the appropriate NVD entries.
      {#store-secops-rn-vr-int-blackduck__ul_w4b_q5p_lkc}

Version 1.1.5 - September 2026
:
    * Fixed:
      * An issue with Black Duck vulnerability scan results import failures if the CVSS v3 impact sub-score returned by Black Duck was null or empty. By including the impact sub-score in the imported record only when Black Duck provides a valid, non-empty value, records without one now are imported as expected. This correction ensures all reported Black Duck vulnerability items import successfully.
      * An issue with CVE-based vulnerabilities identified by Black Duck that were being stored as Application Vulnerability Entry records instead of NVD entry records and potentially impacted severity and CVSS impact scoring. By treating records that contain a CVE prefix as NVD entry records and storing them accordingly, entries without a CVE prefix continue to be recorded as Application Vulnerability Entry records. This correction restores the proper classification so CVE metadata and impact scoring are associated with the appropriate NVD entries.
      {#store-secops-rn-vr-int-blackduck__ul_qxl_q5p_lkc}

Version 30.2.1 - June 2026 (USEM)
:
    * The following enhancements and changes support internal security directives:
      * Query ACLs added to Black Duck configuration and project tables: sn_vul_blackduck_config and sn_vul_blackduck_project, plus narrow field-specific ACLs for u_source on the Black Duck app-import and project-import staging tables to align with ServiceNow Platform Security guidance.
      * Fix scripts run exactly once per upgrade.
      * Fix script renamed to a per-plugin name to prevent update set conflicts with other Security Operations plugins.
      {#store-secops-rn-vr-int-blackduck__ul_pbx_y5f_kjc}
    * Fixed: CVDB framework alignment --- Four missing columns added to sn_vul_blackduck_cvd_attributes: short_description, source_risk_score, v3_impact_subscore, status_updated_on so the CVD attributes table fully matches what the Black Duck integration produces. The UI list and form sections now expose these values.

Version 30.1.1 - April 2026 (USEM)
:
    * New: Enhancements to Black Duck AVIT mapping to include componentVersionName.
    * Fixed:
      * Black Duck integration configuration so it correctly stores the MID Server name instead of the internal sys_id when saving credentials. This enhancement resolves ECC queue entries that are stuck in the "Ready" state with the error message,"No response for ECC message request after waiting for 30 seconds in ECC Queue."
      * Integration now gracefully handles deleted or archived projects. Integration runs continue processing remaining projects even when individual projects return 404 errors. Activate the sn_vul_blackduck.mark_unseen_projects_inactive property to automatically deactivate projects no longer present in Black Duck.
      {#store-secops-rn-vr-int-blackduck__ul_smr_vr4_53c}
    {#store-secops-rn-vr-int-blackduck__ul_rmr_vr4_53c}

Version 1.1.2 - April 2026
:
    * New: Enhancements to Black Duck AVIT mapping to include componentVersionName.
    * Fixed:
      * Black Duck integration configuration so it correctly stores the MID Server name instead of the internal sys_id when saving credentials. This enhancement resolves ECC queue entries that are stuck in the "Ready" state with the error message,"No response for ECC message request after waiting for 30 seconds in ECC Queue."
      * Integration now gracefully handles deleted or archived projects. Integration runs continue processing remaining projects even when individual projects return 404 errors. Activate the sn_vul_blackduck.mark_unseen_projects_inactive property to automatically deactivate projects no longer present in Black Duck.
      {#store-secops-rn-vr-int-blackduck__ul_lz3_vr4_53c}
    {#store-secops-rn-vr-int-blackduck__ul_urs_5r4_53c}

Version 1.1.1 - December 2025
:   Removed: Admin override check has been removed from the ACLs.

Version 1.0.5 - May 2024
:   Integrate your Black Duck account with ServiceNow Vulnerability Response to prioritize and remediate application vulnerabilities.{#store-secops-rn-vr-int-blackduck__latest-store-secops-rn-vr-int-blackduck}
{#store-secops-rn-vr-int-blackduck__latest-store-secops-rn-vr-int-blackduck}

