File exclusion
Last updated: Oct 7, 2026
You configure the exclusions in the platform, in the Exclusions field of the Git root. The patterns use gitignore syntax. The review of the pull request obeys them: if an exclusion covers a file, the assistant does not report that file. This is true also when the pull request adds a vulnerable line to the file.
Refer to Exclude subpaths in Git repositories to edit them.
Fluid Attacks recommends that you do not exclude parts of your repository. An exclusion can hide a vulnerability that puts your security in danger.
Examples
| Pattern | What it excludes |
|---|---|
*.min.js | All the minified JavaScript files |
node_modules/ | The node_modules directory and all its content |
test/fixtures/* | All the files below test/fixtures |
src/legacy/ | The src/legacy directory |
config/local.* | config/local.yaml, config/local.json, and so on |
A change to the exclusions becomes effective on the next scan. A re-run of the check does not do a scan again, thus it does not obey a new exclusion. Push a commit to the pull request.
Obsolete: the exclusion files of the repository
The assistant continues to read two files in the root directory of the repository:
.fluidattacksignorefluidattacks-exclude.txt
These two files are obsolete, and the assistant will stop to read them. When the review finds one of these files, the summary comment tells you so. Move the patterns of the file to the Exclusions of the root in Fluid Attacks.
If the two files are in the repository,
the assistant uses .fluidattacksignore.
In the two files, a line that starts with # is a comment,
and the assistant ignores an empty line.
How to move the patterns
- Open the file and copy its patterns.
- Go to the Scope section of the group.
- Open the Git root of that repository.
- Add the patterns in the Exclusions field.
- Delete the file from the repository.
In the platform, the patterns belong to the root, and not to a branch. To edit them, you must have the permission to update the exclusions of a root.
Related information
Review in the platform
Find the reviews of your pull requests in the DevSecOps section of a group, and read the detail of one review: its vulnerabilities, its exceptions, and its pushes.
Troubleshooting
Correct the usual problems of the Peer Reviewer Assistant: a pull request without a review, a check that does not change, and the expiration of the GitLab token.