File exclusion

Last updated: Oct 7, 2026


You configure the exclusions in the platform, in the Exclusions field of the Git root. The patterns use gitignore syntax. The review of the pull request obeys them: if an exclusion covers a file, the assistant does not report that file. This is true also when the pull request adds a vulnerable line to the file.

Refer to Exclude subpaths in Git repositories to edit them.

Examples

PatternWhat it excludes
*.min.jsAll the minified JavaScript files
node_modules/The node_modules directory and all its content
test/fixtures/*All the files below test/fixtures
src/legacy/The src/legacy directory
config/local.*config/local.yaml, config/local.json, and so on

Obsolete: the exclusion files of the repository

The assistant continues to read two files in the root directory of the repository:

  • .fluidattacksignore
  • fluidattacks-exclude.txt

If the two files are in the repository, the assistant uses .fluidattacksignore. In the two files, a line that starts with # is a comment, and the assistant ignores an empty line.

How to move the patterns

  1. Open the file and copy its patterns.
  2. Go to the Scope section of the group.
  3. Open the Git root of that repository.
  4. Add the patterns in the Exclusions field.
  5. Delete the file from the repository.

On this page