3 ms·
The pretty well describes pretty much every static analysis, automated security scanning tool I've ever used. They generally work ok if you use a common framewo
by thinkharderdev 6y ago
The pretty well describes pretty much every static analysis, automated security scanning tool I've ever used. They generally work ok if you use a common framework in a standard configuration using a standard project layout (once tuned properly to filter out false positives). Once you get to that point you can actually pay attention to the alerts and may even catch some significant issues.