Skip to main content

Checkmarx SAST Vulnerability Integration with ServiceNow - Change Log

The following table lists the features and changes implemented for the plugin with the relevant version release. To obtain the plugin, go to the ServiceNow store.

Plugin Version

Changes / Features

Additional Information

1.0.21

March 2024

  • Addition of a SCA deltas result API. Risks that have been closed or marked as Not Exploitable in SCA will appear as Closed in ServiceNow.

  • Bugs Fixed:

    • CxSAST results - Duplicate entry of node information appears in Vulnerability Explanation Field in the AVIT Table.

    • CxSAST results - Project data is not imported if the token expires during the fetching of the project batch.

    • CxSAST results - AVITs were not created in ServiceNow due to missing snippet details in XML.

    • SCA results – SCA API using MID Server to establish a connection.

    • SCA results - Integrations picking the deleted project details.

  • Washington DC support.

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF14 or later, 9.6 HF 5

SCA Support: Supported

SNOW Compatibility: Washington, Vancouver, Utah, and Tokyo

1.0.19

February 2024

  • LOC (Lines of Code) information in the SNOW Static Scan Size column of theApplication Vulnerability Scan Summaries table

  • SAST Unique Identifier, Similarity Id , and Hash of PathNode (Line + Column + FileName), mapped into the Source AVIT ID in SNOW.

    • Existing AVITs in SNOW were updated to the new unique identifier.

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF14 or later, 9.6

SCA Support: Supported

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.18

January 2024

  • In ServiceNow, the vulnerabilities result state changes to closed when resolved in SAST.

    • Available on SAST 9.5

  • If there is a Business Application or Application in the SAST project’s Custom Fields, this information will be mapped to the Business Application column of the Discovered Application and Application Vulnerability Item tables on SNOW.

  • SAST project’s Custom Fields are mapped to the Source Additional Info column in the Discovered Application table on SNOW.

  • You may filter up to 10 custom Result States when synchronizing between SAST and SNOW.

  • Added support for SCA Standalone. Three new integrations were added to synchronize SCA projects, scans, and results to SNOW.

    • Checkmarx SCA Application List Integration: Synchronize the project details and map them to the Discovered Application table on SNOW

    • Checkmarx SCA Scan Summary Integration: Synchronize the last scan of a project and map it to the Application Vulnerability Scan Summaries table on SNOW

    • Checkmarx SCA Application Vulnerable Item Integration: Synchronize the results of the last scan of a project and map them to the Application Vulnerability Item table on SNOW

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF14 or later, 9.6

SCA Support: Supported

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.17

January 2024

  • Bug fixes

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.16

December 2023

  • Added new DevOps Integration which will permit users with the DevOps Change Velocity license to view third-party scan summaries from Security Operations in DevOps.

    • This integration is listed in the Vulnerability Integrations [sn_vul_integration_list] table.

    • There is no impact on existing Application Vulnerability Response.

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.15

December 2023

  • Bug fixes

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.14

December 2023

  • Bug fixes

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.13

  • Synchronization of a specific list of projects ( You can add up to 10 projects at a time on the Configuration page to filter out projects in the Application Release Table)

  • Addition of branch project in the plugin (Branched project is now mapped to a project list)

  • Custom States will be mapped to SNOW.

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.12

  • Bug fixes

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.11

  • SNOW Vancouver compatibility

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: Vancouver, Utah, and Tokyo

1.0.10

  • The Scan Summary Name column includes scanId , the Last Scan date in AVIT, and the Scan Summary Table.

  • Added OWSAP Top 10 and SANS 25 information for SAST vulnerabilities in OWASP and Short Description column of Application Vulnerability Entry Table (sn_vul_app_vul_entry.LIST)

Supported SAST Versions: 9.4 HF23 or later, 9.5 HF5 or later, 9.6

SNOW Compatibility: San Diego, Utah, and Tokyo