| ▲ | lousken 5 hours ago | |
They see their dashboard, when the number is high, they want to get the number low as fast as possible. If the number is close to zero, they want to see zero. It is that simple. They do not care if the issue is in a piece of code that is never executed and would require full access to the machine. It is there and tool X reports it. Even security audits are terrible, when they don't find anything major they start reporting stuff that few percent of companies have implemented just to stuff their reports, it is ridiculous. | ||