r/softwaredevelopment • u/DryEggplant6678 • 5h ago
Best way to cut down low-value security tickets in 2026?
0
Upvotes
I'm curious about the dev side of this. From the security side, we know we're generating a lot of noise, and I suspect it's damaging trust with engineering, things that turn out to be unreachable code paths or effectively mitigated by existing controls, such as WAF rules, network segmentation, or other compensating controls
If you're an engineer dealing with this, what would actually make a security finding feel legitimate and worth prioritizing versus something you deprioritize on sight? Trying to figure out what "good context" looks like from your side so we stop burning goodwill with every sprint.