github / github/codeql

Better explain how to exclude paths for compiled languages

Open
#8,689 9 comments 10 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

the current explanation in github's FAQ says:

> For compiled languages, if you want to limit code scanning to specific directories in your project, you must specify appropriate build steps in the workflow. The commands you need to use to exclude a directory from the build will depend on your build system. For more information, see "[Configuring the CodeQL workflow for compiled languages](https://docs.github.com/en/code-security/secure-coding/configuring-the-codeql-workflow-for-compiled-languages#adding-build-steps-for-a-compiled-language)."

however, there's no example or explanation how to actually do it.
inside codeql's runner there is an exclude configuration for java code:
```
$ ./codeql resolve extractor --language=java --format=betterjson
{
"extractor_root" : "/Users/me/codeql/codeql/java",
"extractor_options" : {
"exclude" : {
"title" : "A glob excluding files from analysis.",
"description" : "A glob indicating what files to exclude from the analysis.\n",
"type" : "string"
}
}
}
```
however, i couldn't find a way to send this configuration to codeql workflow.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.