|
|
|
|
|
by HideousKojima
861 days ago
|
|
>I would disagree that you can replace scanning tools with just human review though. You need both. If any of the scanning tools I've used were actually fit for purpose, I might actually agree with you, but they aren't. The amount of noise they generate makes them a distraction and a net negative. |
|
I'm all in favour of empowering developers to deal with stuff earlier, but the amount of false positives these tools generate seem like it would just distract.
I think some kind of review and filtering of them before the average dev sees them would actually work better. Do you have an opinion on that?