github / github/codeql

Better explain how to exclude paths for compiled languages

Aperta
#8,689 9 commenti 10 reazioni 0 assegnatari Vedi su GitHub
question
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

the current explanation in github's FAQ says:

> For compiled languages, if you want to limit code scanning to specific directories in your project, you must specify appropriate build steps in the workflow. The commands you need to use to exclude a directory from the build will depend on your build system. For more information, see "[Configuring the CodeQL workflow for compiled languages](https://docs.github.com/en/code-security/secure-coding/configuring-the-codeql-workflow-for-compiled-languages#adding-build-steps-for-a-compiled-language)."

however, there's no example or explanation how to actually do it.
inside codeql's runner there is an exclude configuration for java code:
```
$ ./codeql resolve extractor --language=java --format=betterjson
{
"extractor_root" : "/Users/me/codeql/codeql/java",
"extractor_options" : {
"exclude" : {
"title" : "A glob excluding files from analysis.",
"description" : "A glob indicating what files to exclude from the analysis.\n",
"type" : "string"
}
}
}
```
however, i couldn't find a way to send this configuration to codeql workflow.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.