Diese Seite ist nur auf Englisch verfügbar.
Ignore paths
Keep vendored code, build output and test fixtures out of scans with gitignore-style patterns on a repository or a whole git workspace.
Ignore paths are gitignore-style glob patterns that keep files out of your scans. You can set them on a single repository, on a whole git workspace, or both, and Vulnara applies every pattern that matches before any scanner runs.
What it is for
Some files produce findings nobody needs to act on: third-party code in vendor/, installed packages in node_modules/, minified bundles, build output and test fixtures full of fake credentials. Ignoring them keeps your findings list to the code you own and makes scans faster.
How it works
- Patterns use gitignore syntax.
vendor/matches a directory anywhere in the tree,*.min.jsmatches files by name, and**/test/**matches everything under anytestdirectory. - When a scan starts, the repository's patterns and its git workspace's patterns are combined. A file matching either list is ignored.
- For every commit scanned, matching files and directories are removed from the checkout before the scanner runs, so no scanner sees them.
- Patterns are cleaned up when you save them: surrounding spaces are trimmed, blank entries are dropped and duplicates are removed, keeping the first occurrence in order.
What you can set
- Repository ignore paths: apply to that repository only.
- Workspace ignore paths: apply to every repository in the git workspace, including repositories imported later.
The editor offers one-click suggestions for common patterns, such as node_modules/, dist/, build/, vendor/, __pycache__/, .venv/, *.min.js, *.lock and **/test/**. You can also paste a .gitignore file or a comma-separated list to add several patterns at once.
Do it
On a repository
- On the Repositories screen, open the repository's actions and choose Edit ignore paths.
- Add patterns, or pick from the suggestions.
- Choose Save ignore paths.
You can also set them in the Ignore paths field when you add a repository.
On a git workspace
- On the Workspaces screen, open the git workspace's actions and choose Edit ignore paths.
- Add patterns.
- Choose Save ignore paths.
You can also set them in the Ignore paths field when you add a git workspace.
With the API
Use setRepositoryIgnorePaths or setGitEntityIgnorePaths. Each call replaces the whole list, so send every pattern you want to keep.
mutation IgnoreVendored {
setRepositoryIgnorePaths(
input: { repositoryId: "<repository-id>", ignorePaths: ["vendor/", "*.min.js", "**/fixtures/**"] }
) {
id
ignorePaths
}
}The ignorePaths field is also accepted by createRepository and createGitEntity.
Good to know
- A list can hold up to 200 patterns, and each pattern can be up to 500 characters. Longer lists or patterns are refused and nothing is saved.
- A new pattern takes effect from the next scan. Findings from earlier scans are not removed.
- If the patterns cannot be read as valid gitignore syntax when a scan runs, the scan goes ahead without removing anything.
- Save an empty list to scan every file again.