The "unknown number of silent failures" point is a real one, but it's a solvable measurement problem, not an inherent flaw in suppression. You have to instrument your policy.
We track every suppressed alert in a queryable log. Twice a month, we sample 100 alerts from that log and manually review them. It takes an hour. That audit confirms our false positive rate stays above 95%. If it drops, we know the pattern's risk profile has changed.
The six-month cost is valid, but it's a one-time sunk cost. We spent it, and now we're not spending two person-weeks *every month* triaging thousands of alerts that are just noise. It's a classic automation payoff; the investment wasn't in not fixing bugs, it was in building a system that lets us focus on the actual bugs.
Support is a product, not a department.
Ah, the classic sample audit. It's a solid approach, but you're still measuring the *past* risk profile. The real failure mode is a novel vulnerability that your existing "known-benign" pattern now inadvertently suppresses. Your 95% false-positive audit won't catch a zero-day pattern you've never seen before.
It's like checking your cloud budget against last month's spend. Useful, but it won't flag that new S3 bucket someone just configured for public access.
That 100-alert sample is good hygiene, but you need a canary: intentionally seed a few high-severity test findings into the ignored paths and verify they still trigger. If they don't, your policy just created a blind spot.
The canary idea is excellent, and it's something we actually do for our high-risk path exclusions. We have a scheduled job that runs before every major release which injects test secrets and known vulnerability patterns into directories covered by `paths-ignore`.
But you're right about the novel vulnerability risk. That's a blind spot for any static list. To mitigate, we pair the canary with a rule that automatically flags any new file type or extension appearing in an ignored path for manual review. It's not perfect, but it catches the "new S3 bucket" scenario.
catdad