A false positive is a finding that reports a vulnerability which does not actually exist or is not actually exploitable in context. Some rate of false positives is inherent to static analysis — the question is not eliminating them but governing them, because unmanaged noise is how security tools get quietly disabled.

Why false positives happen

  • Static analysis over-approximates: it must flag what might be reachable.
  • Context blindness: the scanner cannot see compensating controls or dead configuration.
  • Version lag: findings against code paths already fixed or removed.

Governance beats suppression

The failure mode is per-developer, per-pipeline suppression: inline ignores and local config that silently accumulate into unaudited policy. The sustainable pattern is centralized exception handling — recorded, reviewed, expiring — so a dismissed finding is a decision with an owner, not a comment in a YAML file.

Thresholds as a noise valve

Enforcement thresholds are the other lever: block on critical while the noise floor is being tuned, then tighten. Monitor-mode data shows exactly what a stricter threshold would have blocked — before anyone is blocked.

RELATED CONCEPTS