I built a deliberately vulnerable app and ran it through a real security pipeline. The default scan found 7 of the 18 issues a properly configured local run surfaced. Six lessons on what scanners find, what they miss, and what to do about it.
Written by Jay Srinivasan, application security engineer, jaysrinivasan.dev