Fantastic approach... π€¦ββοΈ Actually, I've seen that a lot with penetration testing or SAST tools. With the latter it's partially justified by the fact that a scanner that is not tuned will instead flood the dev team with tons of irrelevant findings...
@kravietz I've seen it too, so I manually validate each finding to be sure they are not false positives, like when some macOS certificates get caught as malware, even when they came brand new. But what they want is a reason to not spend money on a threat they can't see ππππ