S
2

My 2am false alarm made me question every scanner I trust

Last Tuesday in the Denver SOC, our SAST flagged a null pointer that turned out to be a decorator pattern, and I spent 6 hours chasing a phantom while the real SQL injection sat in the dependency graph, so has anyone else had to build their own rule overrides just to get sane output?
1 comments

Log in to join the discussion

Log In
1 Comment
sam_murphy39
Used to trust the noise over my own eyes, but now I get why you build those overrides.
3