-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcodeql-config.yml
More file actions
35 lines (31 loc) · 1.37 KB
/
Copy pathcodeql-config.yml
File metadata and controls
35 lines (31 loc) · 1.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
name: "AllSource CodeQL config"
# Why this file exists
# -------------------
# CodeQL was running with `language: [go]` only. JavaScript/TypeScript analysis
# had been dropped, which left ~89 JS alerts from 2026-01-29 permanently "open":
# nothing re-analysed those files, so CodeQL could never mark them fixed. Most
# pointed at files that no longer exist (deleted demo components) or at a
# generated Playwright report that is not even tracked in git.
#
# Re-enabling JS analysis lets those zombie alerts close. This config stops us
# re-importing the same noise, by keeping build output and vendored code out of
# the analysis entirely.
paths-ignore:
# Generated test reports — 78 of the 89 zombie alerts came from one bundled,
# minified Playwright report. It is gitignored and untracked; scanning it
# only ever produced style findings about generated code.
- "tooling/e2e/playwright-report/**"
- "tooling/e2e/test-results/**"
- "**/playwright-report/**"
# Build output — analysing compiled/bundled artefacts reports issues in code
# we did not write and cannot fix at the source.
- "**/.next/**"
- "**/dist/**"
- "**/build/**"
- "**/target/**"
- "**/node_modules/**"
- "**/_build/**"
- "**/deps/**"
# Elixir/Phoenix static assets are vendored, minified third-party bundles.
- "apps/query-service/priv/static/**"
- "apps/mcp-server-elixir/priv/static/**"