I was that kind of person that would run off-the-shelf tools on open source projects and report the findings (you know, those with a high false positive rate) hoping to help.
Now I'm kind of person that will run tools made by myself on open source projects and report the findings hoping to help.
What changed was that I learned enough to develop tools to help. What remains the same is that I often struggle to understand the findings (but I'm improving at this)






