Skip to main content

Ignore paths

Keep vendored code, build output and test fixtures out of scans with gitignore-style patterns on a repository or a whole git workspace.

Ignore paths are gitignore-style glob patterns that keep files out of your scans. You can set them on a single repository, on a whole git workspace, or both, and Vulnara applies every pattern that matches before any scanner runs.

What it is for

Some files produce findings nobody needs to act on: third-party code in vendor/, installed packages in node_modules/, minified bundles, build output and test fixtures full of fake credentials. Ignoring them keeps your findings list to the code you own and makes scans faster.

How it works

  • Patterns use gitignore syntax. vendor/ matches a directory anywhere in the tree, *.min.js matches files by name, and **/test/** matches everything under any test directory.
  • When a scan starts, the repository's patterns and its git workspace's patterns are combined. A file matching either list is ignored.
  • For every commit scanned, matching files and directories are removed from the checkout before the scanner runs, so no scanner sees them.
  • Patterns are cleaned up when you save them: surrounding spaces are trimmed, blank entries are dropped and duplicates are removed, keeping the first occurrence in order.

What you can set

  • Repository ignore paths: apply to that repository only.
  • Workspace ignore paths: apply to every repository in the git workspace, including repositories imported later.

The editor offers one-click suggestions for common patterns, such as node_modules/, dist/, build/, vendor/, __pycache__/, .venv/, *.min.js, *.lock and **/test/**. You can also paste a .gitignore file or a comma-separated list to add several patterns at once.

Do it

On a repository

  1. On the Repositories screen, open the repository's actions and choose Edit ignore paths.
  2. Add patterns, or pick from the suggestions.
  3. Choose Save ignore paths.

You can also set them in the Ignore paths field when you add a repository.

On a git workspace

  1. On the Workspaces screen, open the git workspace's actions and choose Edit ignore paths.
  2. Add patterns.
  3. Choose Save ignore paths.

You can also set them in the Ignore paths field when you add a git workspace.

With the API

Use setRepositoryIgnorePaths or setGitEntityIgnorePaths. Each call replaces the whole list, so send every pattern you want to keep.

graphql
mutation IgnoreVendored {
  setRepositoryIgnorePaths(
    input: { repositoryId: "<repository-id>", ignorePaths: ["vendor/", "*.min.js", "**/fixtures/**"] }
  ) {
    id
    ignorePaths
  }
}

The ignorePaths field is also accepted by createRepository and createGitEntity.

Good to know

  • A list can hold up to 200 patterns, and each pattern can be up to 500 characters. Longer lists or patterns are refused and nothing is saved.
  • A new pattern takes effect from the next scan. Findings from earlier scans are not removed.
  • If the patterns cannot be read as valid gitignore syntax when a scan runs, the scan goes ahead without removing anything.
  • Save an empty list to scan every file again.

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy