Re: Don't Mind The Fire
From a technical perspective I agree, if you're not using the vulnerable code paths, then it is of no concern. What I take issue with is the idea of stripping away known vulnerable design pattern alerts for the sake of not bothering the developer. The point of these curated CVEs is basically "developers aren't actually fixing the bugs, because there's so many of them, so let's pretend there's less so they actually fix them"