AntiPattern
Toolchain Exclusion Mismatch
security-scan-exclusion-mismatch
SCA/SAST scans run with different exclusion semantics (e.g., .snyk vs Snyk Open Source vs SCM imports), so flagged issues persist or appear in the wrong analysis stage even after dependency updates. This misroutes remediation and wastes CI signal.