security - preventing false positices in fortify scan -
we consistently see lot of false positives in our fortify results. there way can make fortify ignore sections of code? example can add comment in block of code overlooked fortify.
you did not specify language scanning can change answer little bit.
you can exclude files , directories either @ command line "-exclude" switch. once figure out syntax can include in build configuration, such pom.xml.
look @ url examples:
Comments
Post a Comment