The exception that got written twice — silencing an alarm is not defining policy
On August 11 I put a secret scanner on this blog's pipeline. The next day it flagged a build cache file as if it were a key. I silenced it with an entry pinned to that finding's exact fingerprint. Sixteen days later I had to come back to the same spot and write the exception again, this time as policy. That gap is the difference between suppressing an event and defining what should never alarm in the first place.