Re: False positives
Doing a test on a different SAST scanner that picked up 16 issues in pbcore, where the paper said they picked up over 1000. Yes, I would say there is tons of FPs or they are looking at coding practices rather than actual security issues.