A false positive is a finding that reports a vulnerability which does not actually exist or is not actually exploitable in context. Some rate of false positives is inherent to static analysis — the question is not eliminating them but governing them, because unmanaged noise is how security tools get quietly disabled.
Why false positives happen
- Static analysis over-approximates: it must flag what might be reachable.
- Context blindness: the scanner cannot see compensating controls or dead configuration.
- Version lag: findings against code paths already fixed or removed.
Governance beats suppression
The failure mode is per-developer, per-pipeline suppression: inline ignores and local config that silently accumulate into unaudited policy. The sustainable pattern is centralized exception handling — recorded, reviewed, expiring — so a dismissed finding is a decision with an owner, not a comment in a YAML file.
Thresholds as a noise valve
Enforcement thresholds are the other lever: block on critical while the noise floor is being tuned, then tighten. Monitor-mode data shows exactly what a stricter threshold would have blocked — before anyone is blocked.

