I have been working on an automated release review product, and the hardest problem has not been finding more issues. It has been knowing when the system has enough evidence to make a claim. The incentives are backwards. A report with 80 findings looks more comprehensive than one with 12. But if 30 of those findings are guesses, the longer report creates more work and less trust. I now think every automated finding needs four things: Observed evidence: the request, response, DOM state, screenshot or behaviour that triggered it. Claim boundary: exactly what the evidence proves and what it does not. Confidence: confirmed, likely, or needs manual review. Disproof path: the condition that would show the finding is wrong or already mitigated. For example, a missing public security header can us


  • 情报分类:技术价值
  • 命中依据:扫描器可靠性问题讨论,明确技术对象
  • 来源:Reddit · SaaS
  • 原作者:/u/pagelensai https://www.reddit.com/user/pagelensai
  • 发布时间:2026/9/10 23:33:03