Per Aikido docs: use literal path substrings in .aikido (no wildcards or regex) and record CVE ignores with a reason.

Context: Problem: Exclusions in the .aikido file do not match the files you expected. Path matching in .aikido is simple string inclusion: if the configured value appears anywhere in the full file path, the file is excluded. Wildcards and regular expressions are not supported. Place the .aikido file in the repository root. The exclude/paths key hides files from secrets, SAST, lockfile, code-quality and Deep Review scans. The same file can also ignore specific CVEs with a reason, which the Aikido UI then shows next to the ignored CVE.