Log confirmed false positives for server-auth-actions (genAccessToken, the session-validation endpoint itself) and exhaustive-deps (intentional minimal-deps effects where adding deps would cause re-render loops) so future triage skips them. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>