[Sencha23 (accepted answer)] Hope I'm not too late. I've encountered the same problem and what resolved it for me was to delete the space between the excluded paths. Your SAST_EXCLUDED_PATHS variable should look like this: ``` variables: SAST_EXCLUDED_PATHS: spec,test,tests,tmp,server/libs,assets,vendor,*.min.js ```

Context: Stack Overflow #70887133 (accepted answer, 10 votes, 2 answers): I have enabled SAST scanning in GitLab CI (GitLab Community Edition) 14.5.2. The SAST runs tools like semgrep and ESLint run over the source code and scan for vulnerabilities. This works... except it's not excluding paths and files from the results that I tell it to so my reports are filled with junk from 3rd party libs. Since I don't want test code or 3rd party stuff in the report I use the GitLab provided variable for this purpose called SAST_EXCLUDED_PATHS that I use to exclude some dirs. My value is like this: ``` variables: SAST_EXCLUDED_PATHS: spec, test, tests, tmp, server

## Matched source
Source: Published skill
Original query: "Why is GitLab CI SAST not exluding directories that I ask it to exclude?"
Key terms: directories, exclude, exluding, gitlab, sast, that
