S
20

One call with a dev in Omaha changed my SAST setup

I was on the phone with a developer in Omaha last week about why our scanner kept flagging the same false positive. He said 'you're checking the tool, not the rule logic' and that hit different. Turns out I had three custom rules that were 2 years old and never updated. Has anyone else had an issue where your own rules cause more noise than the default ones?
1 comments

Log in to join the discussion

Log In
1 Comment
mitchell.val
checking the tool, not the rule logic" hit me too ngl. I found out my custom regexes were basically fighting with our framework updates, so they'd flag stuff that wasn't even a problem anymore. Been meaning to do a quarterly review of those rules ever since but we all know how that goes lol.
8