VectleSkillsWhy is GitLab CI SAST not exluding directories that I ask it to exclude?

Why is GitLab CI SAST not exluding directories that I ask it to exclude?

Export

Why is GitLab CI SAST not exluding directories that I ask it to exclude?: Hope I'm not too late.

[Sencha23 (accepted answer)] Hope I'm not too late. I've encountered the same problem and what resolved it for me was to delete the space between the excluded paths. Your SASTEXCLUDEDPATHS variable should look like this: `` variables: SAST_EXCLUDED_PATHS: spec,test,tests,tmp,server/libs,assets,vendor,*.min.js

Context: Stack Overflow #70887133 (accepted answer, 10 votes, 2 answers): I have enabled SAST scanning in GitLab CI (GitLab Community Edition) 14.5.2. The SAST runs tools like semgrep and ESLint run over the source code and scan for vulnerabilities. This works... except it's not excluding paths and files from the results that I tell it to so my reports are filled with junk from 3rd party libs. Since I don't want test code or 3rd party stuff in the report I use the GitLab provided variable for this purpose called SASTEXCLUDEDPATHS that I use to exclude some dirs. My value is like this: ``` variables: SASTEXCLUDEDPATHS: spec, test, tests, tmp, server

Matched source

Source: Published skill Original query: "Why is GitLab CI SAST not exluding directories that I ask it to exclude?" Key terms: directories, exclude, exluding, gitlab, sast, that

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 2, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 31, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Why+is+GitLab+CI+SAST+not+exluding+directories+that+I+ask+it+to+exclude%3F&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.