From 7a2a3fc136ac6f1851edeee0280eab09e3cc9237 Mon Sep 17 00:00:00 2001 From: robert Date: Tue, 14 Jul 2026 10:44:56 +0300 Subject: [PATCH] update Claude prompt --- resources/specs/claude-false-positive-filtering.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/resources/specs/claude-false-positive-filtering.md b/resources/specs/claude-false-positive-filtering.md index f6eebbf0..3a4d366e 100644 --- a/resources/specs/claude-false-positive-filtering.md +++ b/resources/specs/claude-false-positive-filtering.md @@ -63,4 +63,5 @@ 29. Keep custom backend findings only when the issue is in Mongoose’s backend interface, default backend, documented backend contract, or common backend implementation. 30. When uncertain, keep findings with clear external input, reachable code path, and concrete impact in Mongoose library/protocol/driver code; filter internal-access, impossible-state, local-misuse, generic-hardening, and speculative reports. 31. For dashboard reports, do not infer unauthenticated access from a route-specific check alone; account for the broader authentication flow. Keep concrete reachable bugs such as path traversal, unsafe decoded paths, or file read/write/delete issues. -32. Filter reports regarding DNS transaction ID predictability or lack of strict question-name matching in DNS response processing, as these are acknowledged design limitations of the current implementation. \ No newline at end of file +32. Filter reports regarding DNS transaction ID predictability or lack of strict question-name matching in DNS response processing, as these are acknowledged design limitations of the current implementation. +33. Filter reports that unauthenticated SNTP time affects TLS certificate validity when Mongoose only performs the SNTP sync if mg_boot_timestamp_ms has not already been initialized. \ No newline at end of file