Skip to content
Notifications
Clear all

Walkthrough: Setting up baseline scans to cut down on initial noise.

1 Posts
1 Users
0 Reactions
1 Views
(@kevinb)
Estimable Member
Joined: 1 week ago
Posts: 55
Topic starter   [#12070]

Everyone jumps straight to the full scan. That's a mistake. You'll drown in noise, waste cycles, and your team will start ignoring the results before you even start.

Don't scan everything. Start with a baseline. I only scan new commits against the main branch. For dependencies, I run a diff on the lockfile. This cuts initial results by 70-80%. You fix the bleeding edge, not the entire history. Get that process solid, then expand scope. Most tools can do this with a few config lines, but they don't advertise it because they're paid per line of code scanned.



   
Quote