Sometimes projects move around their code a lot which makes false positive declaration via CWE and position in the code difficult. Findings that were previously merked as false positive might show up again if the code is moved to another file or part position.
Solution
It should be possible to mark false positives in the code via comments.
Situation
Sometimes projects move around their code a lot which makes false positive declaration via CWE and position in the code difficult. Findings that were previously merked as false positive might show up again if the code is moved to another file or part position.
Solution
It should be possible to mark false positives in the code via comments.
See concept here: #23