security - preventing false positices in fortify scan -


we consistently see lot of false positives in our fortify results. there way can make fortify ignore sections of code? example can add comment in block of code overlooked fortify.

you did not specify language scanning can change answer little bit.

you can exclude files , directories either @ command line "-exclude" switch. once figure out syntax can include in build configuration, such pom.xml.

look @ url examples:

http://h30499.www3.hp.com/t5/fortify-software-security-center/how-to-exclude-source-files-from-scan/td-p/6574900


Comments

Popular posts from this blog

html - Outlook 2010 Anchor (url/address/link) -

javascript - Why does running this loop 9 times take 100x longer than running it 8 times? -

Getting gateway time-out Rails app with Nginx + Puma running on Digital Ocean -