From 28cd3439dd33b9dfe2364bb213db2914d9430da9 Mon Sep 17 00:00:00 2001 From: robert Date: Thu, 2 Jul 2026 11:12:43 +0300 Subject: [PATCH] Update false-positive filtering --- resources/specs/claude-false-positive-filtering.md | 1 + 1 file changed, 1 insertion(+) diff --git a/resources/specs/claude-false-positive-filtering.md b/resources/specs/claude-false-positive-filtering.md index 384e1d48..f6eebbf0 100644 --- a/resources/specs/claude-false-positive-filtering.md +++ b/resources/specs/claude-false-positive-filtering.md @@ -63,3 +63,4 @@ 29. Keep custom backend findings only when the issue is in Mongoose’s backend interface, default backend, documented backend contract, or common backend implementation. 30. When uncertain, keep findings with clear external input, reachable code path, and concrete impact in Mongoose library/protocol/driver code; filter internal-access, impossible-state, local-misuse, generic-hardening, and speculative reports. 31. For dashboard reports, do not infer unauthenticated access from a route-specific check alone; account for the broader authentication flow. Keep concrete reachable bugs such as path traversal, unsafe decoded paths, or file read/write/delete issues. +32. Filter reports regarding DNS transaction ID predictability or lack of strict question-name matching in DNS response processing, as these are acknowledged design limitations of the current implementation. \ No newline at end of file