← all writing

81 detections we were silently throwing away

The line-scan engine treated # and // as comment markers in every language — truncating URLs in Bash and private fields in TypeScript. Language-aware stripping recovered 81 real findings across 2,915 files, with zero new false positives.

The line-scan engine treated # and // as comment markers in every language. That sounds harmless until you notice what it was cutting off: Bash URLs with # fragments, TypeScript private fields starting with #, and PowerShell comments that weren't comments at all.

Language-aware stripping recovered 81 real findings across 2,915 files, with zero new false positives.

What broke

A single shared comment stripper ran before pattern matching. It knew two markers. Real codebases use more — and they use those markers for things that aren't comments.

The fix

Each language plugin now owns its own comment syntax. The shared stripper consults the language config, not a hard-coded pair of characters. The recovery landed as a pure precision win: more true positives, same false-positive floor.

See the tiers that classify what we do with those findings in Why three tiers?.

truemend · code, made truemore from the workbench →
Read enough. Point it at a repo.
· truemend.ai · code, made true