Own product name/domain/deploy-path self-references, the maintainer's
public contact address, the bogon-detection feature's hardcoded RFC
5735/6890 range constants, and one already-reviewed home-LAN DB_HOST
default -- all previously confirmed false positives that forced a
manual --no-verify judgment call on every single push to this repo.
Verified against the actual scanner (~/.claude/hooks/lib/security-scan-core.sh):
0 findings remain.