Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with Container Vulnerability Response

Several types of components are installed with activation of the Container Vulnerability Response application, including tables, user roles, and scheduled jobs.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Demo data is available for this feature.

Starting with v2.11 of Container Vulnerability Response, the most frequently used system properties are now accessible within the Container Vulnerability Response application. To view these system properties, navigate to All > Container Vulnerability Response > Properties.

Parent Topic:Container Vulnerability Response reference

Roles installed with Container Vulnerability Response

Roles are added with activation of Container Vulnerability Response.

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.

Note:

If you are an upgrade customer, access for the users and groups you assigned with the sn_vul.vulnerability_read and sn_vul.vulnerability_write permissions prior to v10.3 has not changed. Users and groups remain assigned with these roles until you change them. However, starting with v10.3, you may prefer assigning granular roles for more control over what users and groups can do and see in the Vulnerability Response application. For an overview and more information about managing these roles, see Vulnerability Response personas and granular roles and Manage persona and granular roles for Vulnerability Response.

Role title \[name\]Description
sn\_vul\_container.deleteDeletes source records. Contains the sn\_vul\_cmn.delete, and sn\_vul\_container.delete\_vi roles.
sn\_vul\_container.ci\_managerManages reclassification of unmatched configuration items \(CIs\).
sn\_vul\_container.configure\_integrationsConfigures container integrations.
sn\_vul\_container.configure\_vi\_granularityConfigures container vulnerable item granularity.
sn\_vul\_container.create\_viCan create container vulnerable items manually.
sn\_vul\_container.delete\_viCan delete manually created container vulnerable items.
sn\_vul\_container.exception\_approverApproves exceptions, deferrals, and closures of container vulnerable items. Contains sn\_vul.view\_manager\_workspace role. Starting with v2.3, the granular role, sn\_vul\_container.read\_all, has been removed for this role so that you can access the container vulnerable items and remediation tasks assigned to you and your group instead of all the container vulnerable items and remediation tasks.
sn\_vul\_container.false\_positive\_approverApproves or rejects closing container vulnerable items as a false positive.Contains the sn\_vul.view\_manager\_workspace role.
sn\_vul\_container.manage\_assignment\_rulesDefines and updates container vulnerable items assignment rules.
sn\_vul\_container.manage\_auto\_close\_stale\_viConfigure the auto-close stale container vulnerable items
sn\_vul\_container.manage\_auto\_exception\_ruleManage \(create/read/update/delete\) exception rules
sn\_vul\_container.manage\_normalized\_severityCan update the mapping to normalize the severity.
sn\_vul\_container.manage\_permissionsCan assign container vulnerability response roles to users.
sn\_vul\_container.manage\_remediation\_target\_rulesDefines and updates container remediation target rules.
sn\_vul\_container.manage\_risk\_score\_configurationDefines and updates risk score Calculators, risk rules, and vulnerability Rollup Calculators for Container Vulnerable Items.
sn\_vul\_container.read\_allCan view all container vulnerable items and related information.Contains the sn\_vul.view\_manager\_workspace role
sn\_vul\_container.read\_assigned

Can view container vulnerable items assigned to you or your groups either in the Classic UI or IT Remediation Workspace.Contains the sn_vul.view_rem_workspace role.

Important: Starting with v24.0 of Vulnerability Response, the sn_vul_container.read_assigned role has the privilege to access the IT Remediation Workspace.

sn\_vul\_container.read\_assignment\_rulesCan view container vulnerable items Assignment Rules.
sn\_vul\_container.read\_auto\_exception\_ruleRead Exception rules
sn\_vul\_container.read\_discovered\_imageCan view discovered items.
sn\_vul\_container.read\_integrationsCan view results from integration runs.
sn\_vul\_container.read\_normalized\_severityCan view the normalized severity mapping.
sn\_vul\_container.read\_remediation\_target\_rulesCan view Remediation Target Rules.
sn\_vul\_container.read\_risk\_score\_configurationCan view risk score calculators, risk rules, and vulnerability rollup calculators for Container Vulnerable Items.
sn\_vul\_container.remediation\_ownerReads and writes container vulnerable items assigned to them. Vulnerability records are also readable by a user with this role.
sn\_vul\_container.update\_assigned\_toCan update assignment of container vulnerable items. Requires sn\_vul\_container.write\_all or sn\_vul\_container.write\_assigned.
sn\_vul\_container.update\_assignment\_groupCan update assignment group for container vulnerable items. Requires sn\_vul\_container.write\_all or sn\_vul\_container.write\_assigned.
sn\_vul\_container.update\_stateCan update states of vulnerable items. Requires sn\_vul\_container.write\_all or sn\_vul\_container.write\_assigned.
sn\_vul\_container.vulnerability\_adminConfigures all rules, integrations, and so on for the Container Vulnerability Response product.
sn\_vul\_container.vulnerability\_analystMonitors remediation of all container vulnerable items.
sn\_vul\_container.write\_allCan update all container vulnerable items and remediation tasks.
sn\_vul\_container.write\_assignedCan update container vulnerable items or remediation tasks assigned to me or my groups.
sn\_vul\_container.read\_watch\_topicCan read Watch Topics for container vulnerabilities.
sn\_vul\_container.create\_watch\_topicCan create Watch Topics for container vulnerabilities.
sn\_vul\_container.edit\_watch\_topicCan edit Watch Topics for container vulnerabilities.
sn\_vul\_container.manage\_exception\_configurationCan manage exception management configurations.

Tables installed with Container Vulnerability Response

Tables are added with activation of Container Vulnerability Response (CVR).

TableDescription
Container image findingsn\_vul\_container\_image\_findingsStores information on the associated vulnerabilities, image layer, docker image,image repository, and discovered image.Starting with v2.11.3 of Container Vulnerability Response, you can also view the path where the finding is shown.
Container Image Layersn\_vul\_container\_image\_layerContains the information of each image layer. An image is a static file with executable code that can create a container on a computing system.
Container Image Packagesn\_vul\_container\_image\_packageProvides information about the packages where the vulnerabilities exist. The Binary package details are also provided as a comma-separated value.Starting with v2.11.3 of Container Vulnerability Response, you can also view the package URL \(PURL\).
Container vulnerable itemsn\_vul\_container\_image\_vulnerable\_itemContains details of each finding and the corresponding vulnerability.Starting with v2.11.3 of Container Vulnerability Response, you can also view information on the last scan date of an image running as a container.
Vulnerability Entry sn\_vul\_entryProvides information on the severity of a CVE and any additional information sent by Prisma.
Discovered container imagesn\_vul\_container\_imageProvides information on the image ID, Docker image, and the image repository. It also stores the layer information and associates it with the discovered image.Starting with v2.11.3 of Container Vulnerability Response, it also provides information on Image digest of a docker image and last scan date of an image running as a container and a registry.
Finding Mappingssn\_vul\_container\_finding\_m2m\_vul\_itemM2M relationship of the container image findings and the container vulnerable items \(CVITs\).
Auto-close Vulnerable Itemssn\_vul\_container\_image\_auto\_close\_configContains the information on how to close the stale container image findings and roll up the state to the CVITs.
Container Image Vulnerability Keyssn\_vul\_container\_image\_vulnerability\_keysContains the granularity configuration for creation of CVITs from the container image findings.
Docker Related Servicessn\_vul\_cmn\_m2m\_ci\_servicesContains all the business services related with a container image.
VR Container Countssn\_vul\_container\_vr\_container\_countsContains the rolling average of container instances spun off from a container image over the last 90 days.
Container Remediation Task Item sn\_vul\_container\_m2m\_vul\_group\_itemM2M table between CVIT and container remediation tasks.
Container Remediation Task sn\_vul\_container\_vulnerabilityContains container remediation tasks.
Container Remediation Task Manifestsn\_vul\_container\_rt\_manifestAny updates on remediation task will be done by using this manifest table by scheduled jobs.

Scheduled jobs installed with Container Vulnerability Response

Scheduled jobs are added with activation of Container Vulnerability Response.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Demo data is available for this feature.

Scheduled jobDescription
Associate existing Container VIs with Auto Exception RuleAutomatically associates the Auto Exception Rule with existing container vulnerable items \(CVITs\).
Check Container Vulnerable Item Deferment ExpirationSends notifications if container vulnerable items or container vulnerabilities have expired \(and if they expire in one week\).
Vulnerability Response Container Count \(Application - Vulnerability Response and Configuration Compliance for Containers\)Runs daily to populate the sn\_vul\_container\_vr\_container\_counts table that calculates the 90-day rolling average for containers.
Auto-Close CVITsAutomatically closes container vulnerability items that match the condition defined in the auto-close configuration. Their status is changed to 'fixed'.
Calculate Business Criticality for CVITProcesses all active CVITs and updates the Business Criticality field, based on the affected services of the docker image of the CVIT.
Close cancel CVITs that do not have a Docker Image associatedAutomatically expires CVITs that don’t have a CI associated with. Their state is set to Closed, and substate to Canceled.
Calculate Related VI Counts for Container Remediation TaskCalculates the counts on Container Remediation Task records.
Rollup container vulnerable item values to vulnerability and groupCalculates vulnerabilities and group roll ups for container vulnerable items.Note: Starting with v2.10 of Container Vulnerability Response, the scheduled job is enhanced to create background jobs with multithreading capabilities. This upgrade involves segmenting the job into several smaller child jobs, which are executed either in parallel or concurrently. This modification enables processing of multiple records simultaneously, thus significantly speeding up the overall task.