audit
2 posts · all writing
The ignore file is where security programs go to die
Every scanner ships a way to make findings disappear, and every team uses it. The problem is not that risk gets accepted. It always does, but that the record of who accepted it, and why, and until when, does not survive the commit that added the line.
Your CI logs are not evidence
The first time somebody asks you to prove a release was checked, the instinct is a screenshot of a green build. It will not survive the follow-up questions, which version, which checks, against what data, and would it produce the same answer twice.