logo

NJP

Instance Scan in Quebec - Live Coding Happy Hour for 2021-03-12

Import · Mar 13, 2021 · video

[Music] um hello and welcome to live coding happy hour glad you could join us all you happy developers builders and admins and everybody of every skill level this is the fun show of the week we are glad to be here this is the end of the week before we get started let's get into our intros we'll start with our very special guest you can see we've got a couple of new faces here well maybe new to you but some of these people are veterans mark why don't you go ahead and introduce yourself um yeah good evening mark mark rudolph i'm working for quint technology based in the netherlands quintus servicenow partner and yeah working on serves now for now almost four and a half years yeah and enjoying it a lot yeah community mp member and a proud member of the developer m3 program as well i need my applause sound effect [Applause] glad to have you here uh brad hello my name is brad kai i'm a developer from a core platform on the fitness team uh based in san diego uh yeah i work on instant scan that sounds promising that doesn't look like a san diego background to me yeah it's actually an image uh that i took from japan when i traveled there a year or two ago so very nice i was going to say the northeast like connecticut or new hampshire or something that no very nice i'd look forward to going to japan sometime where in japan was that uh it was new york's kyoto very cool well thank you for joining us we hope that we don't make too many mistakes but we've got uh the subject matter expert here to to get us going and last but not least one of our oldest dearest advocates andrew uh hello everybody i'm andrew barnes developer advocate here at servicenow i've been in this role for two and a half years uh prior to that i was a platform owner and enterprise architect for two customers um and then an implementation partner so i've been in the ecosystem for about six and a half years um specialize in development at scale so managing large scale development teams and deployment through the platform and integrations and custom apps and my name is chuck tomasi senior developer advocate been with servicenow since 2010 customer for a couple of years before that and i think i'm coming up on close to 40 years in i.t in one way shape or form old man looking to see the light at the end of the tunnel [Laughter] it's out there it's getting closer every year and every year i ask myself how much longer do you want the fun to last with that in mind now that the cast of characters has been introduced let's turn it over to our drinks in the same order so mark what have you got today um i've got uh in my uh australian study holder i've got a nice coopers paleo so uh yeah it's a nice beer from uh yeah from australia from down under all right sounds good brad what have you got today i brought a uh ipa uh from a brewery called stone it's local to the san diego stone right there in the area yeah and a customer [Laughter] yeah even better so that's is that the stone which ipa they make a whole bunch uh i think it's basil for the stone delicious but it's just cold stone ipa on this can that is the most generic name i've ever heard out of stone [Laughter] they're usually very creative like arrogant bastard right how about you andrew what have you got i do like arrogant bastard um i have got a what is this this is a sour boysenberry plum sour beer today from uh my friends over at edmonds host and what do you have chuck i have an old favorite from back in my wisconsin days a little bit of light glare on that the oh it's not even in focus i've got the f-stop cranked down the line in kugel's berry vice from chippewa falls wisconsin or if you're local and you just want to ask for it you say i'll have a line we send it to a lady we said that to a lady on the airplane and she had no idea like lady there's only one beer in this menu that starts with the word liney i think it was a summer shandy or something at the time so with our beers introduced i'm going to turn it over to you mark i think you're going to be doing the driving and showing us what introduced the topic and what your objective is today um the topic for today um yeah instant scan the new application officially with the quebec release so yeah i don't know how much the audience already saw of instant scan but assume nothing well i like it a lot it's the scan engine is amazing you can just interrogate your whole instance um scanning yeah things like manageability performance delivering cleaner code having a more four-eyes principle oh i can well i can i can't stop about it so so what you're gonna do mark is you're gonna help us build some checks um why don't we let brad uh since brad helped uh build an instant scan uh give us a little overview of uh instant scan why it's useful why i should use it as a servicenow developer yeah so uh instant scan as mark touched on is an engine to help uh interrogate your instance for potential issues uh it's helpful for stuff like platform issues where someone might be using like a deprecated api uh you can search for script fields for that um but it's also like it's an engine in the sense that it's a platform so any team could write their own checks and check for things that they know might be bad or like maybe a wrong state for their application so that way customers know a customer can run a scan and with your check and then check if their app is doing okay or not so and this is different than atf which does the functional testing when i set this field i want to see this result that sort of thing this checks not the function of the application but more of the function of the developer are you doing it right or is there something on here that could cause an issue with an upgrade or as mark said performance or possibly security and i love the fact that it's extensible that you can write your own checks into there say we may have style guides i mean you could get down to the nitty gritty if you're a crafty regex or par scripter parser person you could say look our comments have to be all star slash slash star and star slash format no slash slash comments if i see any of that i'm going to create a finding i mean that's as as fine granular as you can get and probably even more use cases that i haven't thought of but this this application actually has roots back to 2011 2012. i remember when i was brought on to the expert services team originally led by jonathan sparks years ago some of you may remember uh mark stanger from snc guru fame he started cross views and then moved on he's actually back at service now that's a weird circle of events but rabbit hole there we were using scripts to do a lot of this hard-coded javascript and customers would say hey i want to check my instance before my upgrade to make sure that it's not going to break or i want to check this app before i deploy it and we would have scripts and that turned into more of this definition and finding and we had an internal version of that that we would run and then it migrated over to high now support where uh customer service or a professional services slash customer outcomes person could launch it and it's really matured nicely but there's always been this holding back of well why don't we let customers run this whenever they want and there's there's been this reservation of well if i had a partner implementation in 2012 and i run this in 2016 i'm going to have some findings and go after that partner for implementing things wrong and and that was always kind of a fear factor political factor we had to get over because standards change we learn we discover i i liken this to building codes when my house was built in 1970 they placed outlets where building codes said you need outlets if the building inspector came by today and said hey you're trying to sell your house that's not up to code you have to fix that i can't go back to the builder from 1970 and say put in some new outlets for free that's not going to happen so i think we've cleared that hurdle and there's there's there still may be some misunderstanding but you i love the fact and i'll let mark show some of this up that you can run it from various places on demand while you're developing before you deploy an update set check a check a specific scoped app lots of different scale that's some new functionality that hasn't existed in previous iterations of this application so very cool stuff i'm going to turn it over to mark now because i can go on for the rest of the hour just exciting new stuff we are uh you know we get excited about things so and that is fun so uh go ahead and share your screen whenever you're ready mark and and we'll start building some checks yeah yeah and i think it's also good to mention uh like like chuck also touched on it uh just now it's like these scans will also get results from from yeah objects from years ago but years ago it could be fine it could be up to standard but yeah things change over time so it's really not like this instant scan is to hit on someone's fingers or uh or whatever it's not for that's not the purpose it's to make your instance better to bring it up to a higher level to yeah get potential issues [Music] onto the surface surface or what i also like of instant scan is uh we're pretty quickly thinking and scripting business rules client scripts and checking all those kind of things but you can also check for data so task records users groups or well running workflows on closed tasks or whatever so you can do also a lot of things for the operational side and that's also really interesting of of insert scan yeah i'll just try and share my screen [Music] i think my instance is shared now yes i see it on zoom and we're bringing it up on there we are nice yeah andrew's much better driving than i am the instant scan application menu open here already and um well the the scan results lists you i ran some uh scans uh today or yesterday this is on the yeah quebec release patch one so i upgraded my my instance yesterday so can you give us just a quick you know touch on what these different uh modules in under instant scan are mark uh you know what what are the checks what are sweets like i i you know i feel like i could probably guess but why don't we open up each of the lists and and explain what what the purpose is yeah yeah that's fine um i am cheating a little bit uh because well i've built already a lot of checks the past few months all right stuff so it's yeah we're not building everything live today but uh but yeah i would just start with the suites actually um yes the scans uh oh look at this guy oh well you see a lot more here already because i also activated the instance troubleshooter which is a store yeah store application since i don't know a few weeks or something um yeah you can just activate it and you'll get uh well some sweets but also i think 41 additional scan checks from the top okay and there are there are 86 checks out of the box last i checked but i might have patch zero patchwork it wasn't bad but on patch one it's actually uh 20 less they took some out yeah oh boy and i actually have a pretty uh i have an opinion about that because i'm sure you do um and and i actually am not uh so i think that once that we ship from servicenow should not even try to be anything near comprehensive they should be examples of how to use this tool and not a gold standard or anything approaching that because that's not the intent behind this um the idea is for every individual or to decide what is the things that they want to care about when they want to care about and how they want to care about it so i actually am not sad that there's less uh available in batch one i am a bit i noticed some gaps that that we have i i would like to see them aligned closer to the technical best practices that we publish we have we say the technical best practices that shall not do dom manipulation in your client scripts and we have a very good check for that but we also say you really don't want to be using global business rules either we don't have a check for that and it's a very simple thing to check for too so yeah it should be mentioned here we're not on the checks i know but we don't check against the out-of-box thing so you will find global business rules from servicenow from 2006 getting back to the building codes thing we don't flag those as findings on your instance these are things that you have created slash modified yeah yeah and i think it's also indeed good to mention like um you're creating a lot of scan checks because if you don't and you run this these scans then you almost have no findings and then you think oh my instance is perfectly fine i have no issues whatever but what are you actually scanning so add as much as possible checks um serves now best practices javascript practices right and your company standards because every company has some standards so just add them because it also makes like you don't have to do all those checks manually anymore this is already a part of your yeah way of working i could see an opportunity here for uh sharing these checks i may not be the greatest scripter but mark is and he says i wrote this thing that goes through and make sure that you know even if you comment out a document.getelement id or a gel call that's good i mean i i built that because it's really hard to find comments trust me there's so many variants of comment commenting out but uh he could put that on share and say this is my collection of what i think are useful checks and then i can download that as a starting point and modify to my heart's content so that might be something we want to look at in the future is sharing and swapping these things around how about uh instead of just looking at it in the future i uh i will say i will create a repository in our servicenow dev program git repo and get us started and anyone who would like to can contribute to that directly [Laughter] interesting yeah yeah um yeah about the scan suites um basically the scan suite is just an umbrella and under the scan switch you attach the scan checks um so it's so it's very much like the uh suites in automated tests framework um yeah that's a similar concept of the checks um yeah and a scan suite can also be attached to other scan suites so you can create a larger umbrella that's that's the same behavior as atf yeah so what i what i for example did i made um i was thinking in in line of well we've got core instance settings we've got best practices like global business rules not using client record queries on other tables in before business rules things like that but also data because well i think data is really really interesting so i created these uh yeah sweets and attached them to the umbrella all well you see a lot of other sweets here but those are just coming from the instance troubleshooter so those are all from that store plugin and the one that is already out of the box and on everyone's instance is this one the scan suite for instance security center definitions and this one contains well 6162 something like that scan checks at least with patch one uh but zero it was a bit more but yeah um yeah let's just have a look at one of those suites i wanna see your data one what do you i wanna see what the things you're looking for in data i think that's a fascinating concept because bad data could potentially disrupt reports um yeah reports but also for example one of the checks is about um uh well i'll just like okay here's here's another one an active active change task attached to an inactive change yeah okay yeah for example i've highlighted it here well looky there probably that's a really strange situation how should that be possible in your instance in my opinion that should not be possible so yeah you it could have impact on reporting but well you probably have to fix something with the data but it also probably has some underlying technical issue or true maybe an admin did something manually but but probably it's a technical issue lying underneath so also that will pop up to the surface with with checks like these so this is really interesting to have on a production instance checks like like these um or what about something like this an active user with an inactive manager you might maybe well you you might think it's just something i built that yeah so it's not that uh interesting but what if you have an approval yeah close with approvals and those are using that manager they're going into a black hole and that's the layout yeah you were auto approved yeah you could potentially have a serious issue there so this is really really interesting put that in the repo looking now at script includes or business rules or whatever it's just data but yeah these are great you've clearly thought about this and what sorts of scenarios uh you might run into or you have run into this sounds like voice of experience here mark yeah yeah it's a mix in indeed some some are based on experience uh because i was doing operational work at customers or um yeah just situations you encountered but also some where you just yeah were thinking brainstorming out loud and thought hey maybe we could do something with did you create that category manageability or was that out of the box well that's a good one these are just out of the box there are five or six uh from the top of my mind but it was like performance and upgradeability and yeah okay yeah so i'll just open uh this one this scan check also as example so you can just see like this is a table check but then you also see if it yeah that comes you they see how basic it could be because the table check you could use a a yeah you could use a condition builder there you could also use scripting there are three other scan check types as well but those you do need scripting for so well this one the table check you can also use the condition builder and then it can be already this simple like you're just clicking together actually and not working to the manager activists uh is false um you can build these in your sleep i mean this is you get an idea the table scan is awesome because yeah easy to build yeah um well in here you asked about the manageability well here are the the yeah out of the box categories these are just out of the works upgradability performance security manageability user experience so i think that's perfectly fine that's uh i don't see a reason to change this so this is this is nice so hey brad um you know we've we've covered up uh you know uh this uh fairly broadly already um but have uh you know have you noticed that we uh have missed a a gap of something that's it in here or that we just haven't mentioned or you know what what do you think what are your thoughts what would you like to share at this point um i mean so far just going through checks and uh suites is pretty good um definitely instant scan is a lot about the content so you want to make sure that you write good checks and that you bundle them up in appropriate suites so far this looks good and in fact the table check in this condition builder is probably around the majority like at least about fifty percent of the kind of checks you wanna write the condition builders is really powerful and the script is there if you need it but really like this is already a huge uh chunk of the work or of the use case that you need so i noticed in the in the script field mark if you could go check the advanced again yeah there's two objects that are passed into this one finding and current oh that's a that's a good one to touch on uh chuck because um i created this can check already in the palace release contains these two objects but if you create a new scan check it will actually only contain this object yes i was going to point that out and we don't have much i couldn't find much documentation on any of that it is pretty new to quebec and i believe the documentation is rolling its way out but we decided to uh consolidate the things that we pass into this function through just a single engine object so if you do engine.finding like you saw earlier then you'll get that finding that you saw uh engine.com so okay yeah it's nice for other kinds of checks like mentor check because in linter check it basically builds a parse tree of script that you want to look through and that parse tree exists in the engine object as engine dot root node so that's that's sort of the reason why that's uh awesome to share brad why don't we actually um mark do you think we could create a linting check right now and dive into that a bit because brad is actually the expert on the linting and that's that's what i want to take out of this show today is is how to to do the lenting so um i know that you're probably not familiar with it but but brad is uh going to help you uh make your first linting check if that's okay with you mark yeah that would be really nice because the lintel check is also um yeah one of the parts that's it's not described yet and there are no examples um available so it's really the unknown so that would be a really nice one if we can make one working we are creating enablement content here yeah that that's the goal from today um and i will be releasing a blog um that will walk through uh some of the examples um i'm gonna work on it over the weekend and i'll probably release it on something like tuesday um but uh but but let's build one live right now yeah um so yeah we can just go to the checks and just hit new we'll get this inceptor page and the four different scan checks that are available and the bottom one is uh yeah it's the lintec check so let's just hit this one and yeah here you indeed see that you only have the script field so you don't have a condition builder or whatever so you really have to script it out um there's actually a good question from phil and i had the same one and i believe i know the answer but hey brad can you uh tell us um the old objects um from the paris ones uh do we need to go update those uh to or or will they continue to work with the uh the current and uh what is the vibe that starts with p f finding um they are deprecated but so long as you pass those into that function that um that self-running function then it should work so either using function or that engine object engine not finding or passing and finding red one works but um so i don't have to go update them yeah my existing ones that are created in pairs another question from the chat if uh if we modify an out of the box event let's say we go do a business rule incident.events and and do we have to will the scan start checking that yes okay so it's the same rule once you modify it you own it you're responsible for good or bad practices yeah and i think it's also good to mention if you look at these scan checks and we've got these four types the table check only checks for well custom scripting like well you touched it uh that will that will be scanned out of the box uh business rules or whatever won't be checked right able check but if you use for example the script only check that will also scan out of books because you can script anything you want in there you can do any glide record query anything you want in that script only check interesting thing to note about this screen with this interceptor it's very much like if you go to task.list and click new it's saying what kind of task do you want this is actually determining which of the extended tables because each check is in a special table i went to the list of checks and said i want to see the ones where advanced is true and realized advanced is actually on one of those lower class tables it's kind of like looking for caller id when you're looking at the task list it ain't there it's an incident so advanced is in the table check so you you gotta you gotta kind of familiarize yourself with the way that the checks table is set up when was the last time you created an interceptor chuck um a few years ago but they're still very useful oh they're still very useful but it's it's been at least a year since i created an interceptor there's there's a lot of power in interceptors most people just use this though it's like hey i'm going to ask you what kind of table you want and move on but you can do a lot more with interceptors and it's not documented either they were almost they were almost removed from the documentation until i fought to get them back in let's get started with our lenter yes way too much fun we are having fun so i've got the lintel check here well try to add as much as possible here of course also the resolution details really important so anyone else can fix your issue as well don't just put rtfm yeah the scripting part will be the most important one here um yeah i just don't know yet how this linda check works and also that's why we've got brad he's gonna brad you've got an idea of what we should check for don't you all right um so like a really basic use case would be to check for a deprecated api um though i mean it could be really anything that's like uh like uh kind of messy in the script yeah um let's check for the old mark you've you've used the uh uh flow apis haven't you you've got some deprecated flow apis that uh should be used in favor of the new ones let's the new one ss new one sn underscore flow api well wouldn't you do that with like a script check or uh not the script check the uh field column type check why would we use a linter over the column check yeah because with the column type check that you can scan all script fields or all xml or all html yeah so fred tell us yeah so that's actually a really good point uh and you can actually do this exact same thing uh search for a specific string of the deprecated api but what's interesting about linter check is that it actually parses the code using the rhino engine in the back end of servicenow so for example if you were to have this function in a comment then you could skip that because you could have the parse tree know that it's in a comment and then not actually scan for it that's what i was looking for if somebody comments it out like the dom checker is a table check and it just says hey if you've got gel or document.getelement id or whatever in there and i just go comment it out it still comes up in the findings so this is even better if it acknowledges commented out stuff sweet this is where we want to be yeah there's one other so will this um linda check then just go to all script fields or do we have to perform a glide record query first or something or this runs on all script fields in the instance okay so yeah there's other things in uh in the scan engine for specifically targeting down a certain scope of records like if you wanted to scan a scope app for an update set and so then you can run this check on that specific scope but when you say all script fields is that really all script fields because when you when do we do a code search out of studio it's not searching all script fields it's missing a lot of them well as far as i know it should be all script shields but okay it skips all like you said it skips all out of box uh scripts so it's just customized and customer written scripts cool okay really nice yeah um so for example if we i i don't know all the api names from the top of my mind but i know this one is for example deprecated with quebec so how can we check on this one with the linte check all right so um there is some documentation that's coming in soon that talks about what this uh linter uh check includes in the engine object but um for now uh if you actually check in the chat um i wrote out a kind of like a simple template that you can copy and paste just to save us some time oh let me check where the chat went the zoom chat yeah um where did it ah okay if it's easier i can send it to you in slack let me check no pun intended let me check so this is kind of like a baseline for finding a in this case i just wrote in quotes a bad function but basically what we pass in from the engine is the root node of the parse tree of the script that we're on so a parse tree basically just looks like a tree representation of the code so if it's like an if statement the root node would be if and then the lines of code inside that if statement would be the next nodes and then it would just keep on uh uh indenting from there so in this case um the documentation talks more about what these node types are but in this case we're looking for a a name as in uh like a function name and we're checking for three things if it's a name node um [Music] if then the identifier of that name specifically is this mad function or whatever we want to call it yeah and also if it if this function name is being called so um in this parse tree it could also be something like it could be like a class name or it could be uh like a variable but in this case it knows specifically that it got called uh and so that's what this kind of looks like and so after that uh so long as if statement um is is truthy then it'll do engine.finding and then increment and we have some actual logic where it increments with the node that you're on so it'll know which line it actually found the violation on nice yeah so bad function should be the the name of the deprecated api okay [Music] um so we've got a bundle of questions um that are probably really easy uh bullet shots to you and if you don't know that's fine i'll answer them in the blog next week um do you know uh domain separation and then encryption uh like can this operate in domain separation and uh yes or no and then uh can it work against uh you know edge encrypted type instances yes or no and it's very okay if you don't know brad because that's not necessarily something you should need to know all right um as far as i know it instant scan is a core platform uh plugin so it exists in the global scope and so when it comes to domain separation that's basically the extent of what i understand of what how the interaction might be so yeah uh short answer is i'm not quite sure that's fine i'll i'll get that for sure answers and i'll put them in the blog sorry and then what was the other one uh encryption encryption edge encryption specifically yeah right i'm not too sure on how that might work i'll get the i'll get the for sure answers on those i can take a stab at that knowing a little bit about edge encryption traditionally you're not going to edge encrypt a script field because it's got to run on the server the server doesn't have access to edge encrypted data it's only available on the client when you surf it up to that person that's the whole point of edge encryption is you could take a description field for example an encrypt part or all of it and it's not it's encrypted on the server that's the point of edge encryption it's encrypted at rest it's encrypted in flight the only time it's decrypted is when it goes through your proxy at your organization well if the code is running on your server and it's encrypted you're kind of hosed it's like encrypting a ssid you've just bashed everything okay so but if you're looking at say some of mark's data scanners you would not be able to run this because it's running on the server if i'm not mistaken right brad the engine is on the server so it's not running anything through your proxy your edge encryption proxy to decrypt it and then check you would have to be running the scanner outside of your proxy which isn't possible here so it won't be able to scan edge encrypted data is the short answer based on the way that that technology ties into the platform and the way it's used i mean that seems right oh yeah the the scan code does run on the server side verified phil says note to self don't encrypt script fields yeah no don't don't equip much beyond string fields if you have if if you're if you're curious ask more so well and the the point is is that will limit what you can do with the table type searches because they can't actually uh introspect the the data on those so you can't do for example uh the inactive incidents if you don't have access to them uh that that field you'd have access to uh because the boolean is is something you'd have access to but i know a broader sense uh you know if you're doing a condition against a encrypted field uh it's it's not gonna work brad is the is the lint checker building the nodes at runtime they are okay it's not like a scheduled job that you have to wait four hours or run manually to up refresh and then run your scan okay good to know [Music] so if we were to click on the uh the test track button then we can run it within a few minutes but [Music] i think here's also a nice example of the engineers finding notation that's already a good one so i just put in this um yeah deprecated api um i know from the top of my mind that that one is uh deprecated at least are you using it on this instance uh no i just uh refreshed it yesterday so maybe i have to uh yeah maybe i have to duplicate a script include or whatever but i don't know how long this one will run but like the the table checks and the script only checks generally go really fast that's just seconds of work and the column type check that could take some minutes but also depending on how large your instance is how many plugins you activated stuff like that so i guess it's for the linte check as well uh depending on yeah the size of your instance i think one thing that the scan engine is kind of bottlenecked by is uh querying for each record uh and what happens if you run multiple checks at the same time is that each check will be run on that record uh at once over the iteration so in this case this might take a couple minutes but if you were to all right i'm not really sure how long this might take but uh if you were to bundle a couple of column type checks and lint your checks together then it shouldn't take like maybe four or five times longer if you had four or five times more checks it should be around the same amount ah okay that's good yeah yeah that's good to know so yep um and that's when you're so that is the advantage of using sweets then yeah we're running uh any uh group of checks at once for example if you turn off all scan noodles though i have a group of checks but did it run or did you cancel mark yeah it's still it's just uh running you can just uh click out of the the model and it will just uh so it's not holding your session which is great yeah that's a huge approach so um why don't we uh go to um a business role mark could you could you take us to a business role and i want to walk us through a little scenario that i see happening for you know things that will be really advantageous for developers which is uh say i'm working on one of these business rules uh so just just open up one of them and we're going to say we're working on this business rule you want to show off the point scan don't you well uh not just the point scan but i want to talk about how to to pull this in programmatically into your development pipeline so the sooner that you learn about uh something that you need to adjust the better so um for and there's been a lot of talk in the chat about you know how does this pair with atf and and other things that i'm doing and what i want to point out here is the sooner the faster you get a developer to know that there's something that they need to address with what they're working on the cheaper that is right so the the less universe they have to recreate in their mind of what they were doing and why they were doing it and how to make the adjustment so the earlier you do that the better so the point check uh you know so scanning an individual file um should be on here except for this isn't out of the box so it's not visible somewhere there's an api that knows the active check because this one was yeah disabled somehow out of the box um oh and so that ui action is nice and it's good for a developer to be able to click that um but i uh would take that a step further on my teams and in my organizations uh is um i want to run uh you know automated test uh framework stuff and any of the instance scan stuff um automatically that's what we're doing and provide that information to the developers while they're still you know close to the work so the earlier and sooner you can set up that sort of automation so that you know you know when they when they hit update perhaps you're doing the automation to run then and then you can present those findings to the users much sooner um you may not be at the maturity level where every update is is the appropriate amount it might be every commit they make um to a repo but but figure out what that looks like for your organization and leverage the apis that are available to do these things in a programmatic way so kick off your atf tests run your instant scan and present that finding uh from either of those to your developer if there's something they need to address as early as possible so that's the power of these things for a developer while they're developing to me is get that information to them early and often uh so they can address it um you know so don't wait until you're ready to deploy to the test instance uh to run these things right so don't wait till release time to to run atf and instant scan run them during the development so you can address them early and then in your production instance um or in a clone of it you can do those uh you know monthly or quarterly or whatever that pattern looks like uh health checks with these things to address long-term uh and like we said earlier with the you know the the 1997 uh code for building is different i think you're talking about building code not building code like who is doing service now in 97 nobody um uh and so you can do address those but uh figure out what is right for your organization and get those uh run as early as you can do you have any any uh anything to elaborate on that kind of uh thought about how to use your tool brad i think you actually sums it up pretty well awesome um so yeah mark you can show that you can run that point scan there what are some of the other options i can remember some of them but um yeah what are the other triggers so we've got api we've got a ui action what are the other things that are available to me well let's first just do this uh one point check of our one point scan and you'll just see immediately this in this case is business rule will be scanned you can go to the results from here what this one does it actually actually executes or scans all scan checks that are active so it's not limited to any of your check suites for example well if i go to this one for example um let me do the yeah i thought the point scan was really interesting because it just goes out and says you've got all these checks some of them apply to this table for the example business rule it would say what checks do you have on cis underscore script and it will run those and report any findings marked sorry brad does it also check any other tests besides the table checks [Music] i believe yeah if it's the column and to check that are on the table then it should also run those nice cool good to know yeah you can also well scan update sets you can scan applications so scoped applications and obviously the yeah the check suites you can also schedule um yeah so that's really easy you can just schedule daily weekly whatever yeah also just an execute full scan so you can just easily scan everything this schedule button actually is not aligned with the because this one is i think from from paris this one generates this piece of code and this one goes to another table so i do want to show this one so well i guess that will be changed in the future because this one will really go to the sys auto scan table i guess yeah and here you got the the nice model with well a full instant scan or one or multiple scoped apps or one or multiple update sets so that's that's really uh really great um and just well schedule the scan to see ya well daily weekly whatever it's so easy it's amazing brad has earned his paycheck can we take a look at the uh the dashboard um yeah this dashboard is a bit limited i hope there will be some work on this in the future but what i found is more useful mark is actually the dashboard in the results this one yeah yeah this one will be presented if you open a result you've got the related link results dashboard and that's really a nice one indeed yeah for sure in this case i only run this scan once now but if you would have run it twice already then you would also see the previous scanner so this full instant scan will then be compared with the same or similar previous full instascan well you've got the findings some nice breakdown so that's really really nice it's really nice you can just click through to the findings or these scan so this is uh really nicely done do me a favor and click to the findings because i wanted to point something else out about muting a finding have you played with that yet mark yeah yeah um that's what oh that's also a pretty nice one um yeah let's just open one it doesn't really want that yeah come on okay walk us through muting a finding jack i wanted to go to the finding um yeah so here i'm in the finding and indeed you have the the mute option and it opens a new modal and ah this is nice you can just select the reason also these are out of the box reasons and they are stored in [Music] a table i don't know s can mute reason something so you can just if you want to add another reason you can just do that but this these are out of the box really nice if you think it's it's not applicable fine muted and in a future scan this will not be addressed again as yeah finding it will show up as a finding but it will remember your muted reason so if you see it again and again and again you go okay this is a high risk this is high risk is a high risk eventually i would assume you would click that task magnifying glass and get somebody to fix this thing so you can assign a task this way as a finding task i think that's that's also searching for the way of working with this are you going to work with these scan tasks or or not so yeah that's right how are you going to work on this um and that muting is also pretty interesting because well what we already mentioned is like you will also get findings from five years ago ten years ago some will only be priority four or five and maybe not that interesting to do to pick up now so maybe you want to mute them um if they're from five years ago and they're priority one you do might want to have a look at them but but yeah so the muting is it's really nice and and those tasks um you know is a way for you know the central person managing this to assign uh it out to uh you know another team member to keep track of them actually you know either remediating or you know understanding the risk behind the finding and deciding to mute it or not so you know that's that's what those those tasks are for they're for um they're fixing the scan findings themselves and alongside of the uh scan results dashboard that we saw earlier there were other uh visualizations that we had for other parts of instant scan and they'll probably come out as a different scope app but uh there's another visualization that shows you how many tasks are completed uh how many you've been being able to burn down through a developer breakdown that kind of thing oh nice oh that's nice yeah yeah well um that uh is there anything else that you wanted to show on the screen before we wrap up mark oh well i want to explore a lot of undocumented things but well you've got 30 seconds we might have to have a part two on this one it's just a really nice subject and ah it uh we could talk for another few hours on this for sure so grant anything that you're particularly proud of that you want to show off or spotlight real quick i mean i'm just i'm glad for your warm words mark um and i mean i got to show uh linter check which is basically the thing i was working on the most uh so yeah i'm glad we got the show today nicely done awesome well we can uh stop the screen share then whenever you're ready oh you are ready look at you i wasn't quite ready i was almost ready but i wasn't quite ready caught me on that too what um that was great mark uh thanks so much for uh you know joining us today and and walking us through that uh so that that was a ton of fun uh and i learned some things uh even though i've been uh getting up to speed on the instant scan uh so this this has been a ton of fun uh for me so uh i i just wanna we're not done i just wanna get quite yet but i do want to thank you mark that that your excitement is a joy to me um it helps me uh be excited uh when i see our customer and partner developers be excited about you know uh servicenow features and functionality uh and how it's making their lives better as developers like that's that's that's the gold right there so uh and the chat has been awesome today thank you for all your questions um some of them we haven't been able to address just because we don't have the right expert but i will try and address most of the ones that we missed uh in the blog for next week and uh but not uh chuck what do we got sir i'm distracted by the canada geese that are somewhere in the background of somebody's microphone sorry that's mine i was curious to who that was that's awesome my previous team used to call me snow white uh because when it's springtime i've got all the windows open and i've got a lot of birds right outside the window you bet no it's that time of year it's wonderful thank you very much i think it's time to raid our beers uh mark you went first so how do you rate your your coopers my australian cooper's paleo it's empty and it's it's definitely for me it's definitely a five and uh and we had success today that's a quarter point so it's five points that's awesome that's the highest rating we've ever had i figured it had to be good because the presenter really doesn't get to drink all that often yeah you're busy you're busy typing and you finished it that's awesome brad how did you do yeah i mean i've had this beer before quite a few times um but yeah it's pretty good i like it a lot uh probably around a four out of five very nice good good and andrew my sour boysenberry plum that's a mouthful right there this is good um so i if you've seen this show before um i've gone through most of the edmond zo's sour collection uh which is quite quite prolific um this this one's a four five this is excellent and uh my line is berry vice oh that went down like kool-aid it was gone in like the first 20 minutes like glug glug glug glug glug that's that's too easy going down but very delicious nice refreshing fruit flavor i don't even know what kind of berries it is raspberries boysenberries blueberries who knows it was good i'm gonna give that a 4.75 so with the ratings in the can or bottle as it were we are we are done thank you very much brad nice work on instant scan uh any hints of what's on the road map um well our team is currently paused on instagram hopefully we get to work on it soon because we all love instant scan um but in rome there should be a few new features one of which is reactive scan you kind of saw how you could schedule a scan or how you could run one uh yourself but we have a feature where if the execution tracker failure event happens then you can run a scan you can trigger a scan off of that event so right oh i'm i'm i'm wondering if there's a future feature that says if you have a finding go and run this other script to fix it and we can have auto fixing a self-correcting code [Laughter] you shouldn't use global businesses i'll go put that script included in place for you done it could happen it could happen yeah as folks are you know getting familiar with instant scan and learning how to use it and they they start to have feedback um please use the idea community um so that's where our product managers go to uh you know pick up things that to prioritize for inclusion into their roadmaps so go do that um or uh you know put a comment on the blog post about instant scan that'll be coming out next week and and i can help you know get it prioritized with the product management team um uh you know because that's what that's what chuck and i do uh here at servicenow we are your advocates to service now as well as servicenow's advocate to you uh so we act as that bridge so i'm curious to see what's going to show up i'm going to see what i want to know what shows up in that findings repo or the checks repo yeah i think that's going to be a lot of fun that's going to be a lot of fun so thank you very much viewers for watching everybody who hung out with us live in youtube if you missed it you can always obviously check later but if you want to join us we invite you to turn on those notifications subscribe do whatever you do on youtube on the servicenow developer program channel and we will see you again next time on live coding happy hour thanks bye everybody bye [Music] you

View original source

https://www.youtube.com/watch?v=_cPlWnh1Z68