Workbench 26.2 has landed, building on the Audit, Review, Report workflow released in 26.1 to help you answer, “after scanning, how do I address the risks present and manage new ones on an ongoing basis?”
To this end, 26.2 focuses on the Audit and Review stages and improves Onboarding with new permissions and support for SAML SSO. Let’s dive into what’s new, what changed, and where we’re going from here!
A Revamped Security UX
As organizations prepare for the EU CRA’s vulnerability handling and disclosure requirement, a key goal for 26.2 was to simplify CVE triage and VEX creation. To that end, the Vulnerabilities and Security Review pages get a facelift.
More CVE Intelligence inside the UI
Where before you had to leave Workbench for CVE context, 26.2 brings that context directly into the UI of Workbench. Expanding a CVE now shows its description, affected versions, patch or fix versions, and other data points:
- the CVSS section adds support for CVSS 4.0 and switching between CVSS versions for researching impact metrics
- CVEs with published GitHub Security Advisories will show a GHSA section with CVE data enriched by GitHub’s Security Team
- EPSS Scores and CISA KEV indicators for each CVE provide markers to highlight vulnerabilities with increased exploit risk
These data points power filters that allow you to isolate CVEs needing immediate attention, reducing research time and helping you action on CVEs faster.
A Refreshed, More Intuitive, VEX Workflow
Since introducing VEX in 24.3, users have asked questions such as “which Status do I use” or “when do I set a Justification”. To simplify those decisions, 26.2 introduces a questionnaire-like VEX authoring experience that guides users through creating the VEX for each CVE.
As new versions of a codebase are scanned, sometimes vulnerable components carry across versions. To save on repeated triage effort, the VEX Reuse mechanism was improved to first propose scans inside the existing project so you can arrive at the VEX reuse source faster.
Component Aggregation of CVEs
Security Review now has two views: a CVE List and a Vulnerable Components view. Where the CVE list answers “am I affected by this CVE”, the Vulnerable Components view groups CVEs by Component to answer, “which components are vulnerable?”.
While remediation guidance and VEX creation are on a per-CVE basis, the Vulnerable Components view shows you opportunities to fix many CVEs at once. In 26.3, we will add component-level remediation guidance and component-wide VEX actions. Stay tuned!
New Notification Controls
Workbench 26.2 adds a Notification Settings page under the User menu, where you adjust the notifications that you receive from Workbench both in-application and by e-mail.
Besides controlling the types of notifications, you can adjust your new CVE notifications based on severity and affected projects. This grants you more control over what Workbench notifies you about. Notification settings are personal, so your settings don’t affect other users.
Improvements to the Audit Process
The Audit stage of the Audit-Review-Report workflow also got some love in 26.2, fixing quirks from its migration to React in 26.1. As we fixed those, we took the opportunity to make a few improvements.
Global Settings for Ignores and String Matches
Users with permissions to edit Global Ignore and String Match Rules now have two new dedicated settings pages to do so without having to go into the Scan Configuration.
Simplifying Review of Identified Components
For components identified with the signature scan, there are two new behaviors in the Identified Tab aimed at reducing time spent reviewing and undoing identifications:
- clicking an identified Component highlights in the file tree all files where that component was identified to quickly show you a component’s associated files
- two new bulk actions – remove component id clears component identifications and unmark identified unmarks files as identified preserving component identifications
Further reducing the time spent to perform and review identifications is a key focus for 26.3.
“Include in Report” Reuse for Dependencies
For Dependencies found with Dependency Analysis, you can now carry over the “Include in Report” decision to new scans. This employs a mechanism like Identification Reuse, where you choose which Project and Scan to reuse this setting from.
New Permissions and Support for SAML SSO
SAML is now supported in Workbench for SSO, and works together with User Groups and SCIM synchronization to provide more complete support for enterprise access management.
Looking Ahead
These are the highlights of Workbench 26.2. For a complete breakdown of everything included in this release, see the Release Notes.
To learn more about Workbench 26.2 or discuss how to maximize these capabilities to move toward ongoing third-party risk management, open a support ticket, contact your account manager, or visit www.fossid.com/contact. We’re here to help.