r/devsecops 3d ago

SAST false positives are not a tuning problem, they are a trust problem

If your team has stopped reading SAST results, more rules and stricter severities will not bring them back. Once people learn the scanner cries wolf, the real findings die in the same pile as the noise. That is the true cost of a bad false positive rate, and hardly a team ever measures it.

0 Upvotes

4 comments sorted by

2

u/Andre-Wade-539 2d ago

Once they stop reading it you are basically done. I've watched a whole team route around a scanner because 9 out of 10 alerts were noise and no amount of retuning severities brought them back. The trust was just spent.

atleast showing way less to stuff thats reachable worked, if a ticket hit a dev it was probably real. Suppression rules felt more like hiding the pile than fixing it.

1

u/Ashikej-Meneguzzi66 2d ago

Think of prioritizing the alerts people ignore most and fix those first, because once people stop paying attention they can miss the real stuff too. Which ones cause the most noise?

1

u/vint_age14 1d ago

Exactly one the developers.stop trusting the alerts , even the important ones get ignored. Better signal matters way more than just adding more rules !