Why is GitLab CI SAST not exluding directories that I ask it to exclude?
Why is GitLab CI SAST not exluding directories that I ask it to exclude?: Hope I'm not too late.
[Sencha23 (accepted answer)] Hope I'm not too late. I've encountered the same problem and what resolved it for me was to delete the space between the excluded paths. Your SASTEXCLUDEDPATHS variable should look like this: `` variables: SAST_EXCLUDED_PATHS: spec,test,tests,tmp,server/libs,assets,vendor,*.min.js
Context: Stack Overflow #70887133 (accepted answer, 10 votes, 2 answers): I have enabled SAST scanning in GitLab CI (GitLab Community Edition) 14.5.2. The SAST runs tools like semgrep and ESLint run over the source code and scan for vulnerabilities. This works... except it's not excluding paths and files from the results that I tell it to so my reports are filled with junk from 3rd party libs. Since I don't want test code or 3rd party stuff in the report I use the GitLab provided variable for this purpose called SASTEXCLUDEDPATHS that I use to exclude some dirs. My value is like this: ``` variables: SASTEXCLUDEDPATHS: spec, test, tests, tmp, server
Matched source
Source: Published skill Original query: "Why is GitLab CI SAST not exluding directories that I ask it to exclude?" Key terms: directories, exclude, exluding, gitlab, sast, that
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.