Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

There is no universal directory-exclusion syntax for static code analysis. Configure the specific analyzer—or the hook or workflow that chooses its inputs—and confirm whether the setting skips files, hides diagnostics, or filters only one invocation. The examples below reflect tool documentation checked on September 24, 2026; pin them to the versions your project runs.

Decide what you need to exclude

First identify the problem: generated output or vendored code may not belong in a particular analyzer’s target set; a directory may produce noisy diagnostics that still need to be filtered; or a pre-commit hook may need to receive fewer files. Those are different operations, and a setting for one does not necessarily change the others.

  • Skip file selection: Use the analyzer’s native path-exclusion setting when files should not be targets for that analyzer.
  • Filter reported diagnostics: Use a diagnostic filter when the tool still analyzes files but should not display certain findings.
  • Filter one wrapper’s inputs: Configure the hook or CI wrapper if only that invocation should omit files.
  • Stop a workflow from starting: Workflow trigger filters affect whether the workflow runs, not necessarily which files an analyzer scans after it starts.

Before adding a pattern, check its pattern language, path base, recursion behavior, and whether explicit file arguments bypass it. Do not assume a shared ignore file is honored by every analyzer.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common directory-exclusion settings

Tool or layer Setting and pattern type Important distinction
Ruff exclude or extend-exclude in Ruff configuration; patterns Use extend-exclude to add patterns without replacing defaults. Explicit command-line paths are still analyzed unless force-exclude is enabled.
ESLint flat config globalIgnores(); glob patterns Global ignores can match directories. An object-level ignores matches file names, not directories.
mypy exclude in configuration; regular expression Applies to recursive discovery. Verify behavior for explicitly named files and imported modules.
Semgrep .semgrepignore; gitignore-style patterns Used to identify scan targets. Negation support varies by implementation.
Bandit exclude_dirs in YAML/TOML, or exclude in INI YAML/TOML configuration must be specified with -c.
PHPStan excludePaths; fnmatch() patterns Separate options exclude from analysis and from analysis plus symbol discovery.
CodeQL code scanning paths and paths-ignore Applicability depends on language, build mode, and setup type.
pre-commit Hook-level exclude; Python regular expression Filters paths passed to that hook, not separate direct analyzer or CI runs.
clang-tidy --header-filter and --exclude-header-filter; regular expressions Filters displayed header diagnostics; it is not a general directory skip.

Configure the analyzer

Ruff

Add directories with extend-exclude in pyproject.toml or Ruff’s configuration. Ruff also respects common ignore files by default. Set force-exclude when callers such as CI or an editor may pass matching paths explicitly.

[tool.ruff]
extend-exclude = ["generated", "vendor"]
force-exclude = true

Ruff supports tool-specific exclusions, so linting and formatting can use different path sets. Check the Ruff configuration and Ruff settings for the configuration and command you use.

ESLint

For the current flat-config system, use globalIgnores() in eslint.config.js. A pattern such as .config/ matches that directory beside the configuration file; use **/.config/ for directories with that name at multiple levels.

import { defineConfig, globalIgnores } from "eslint/config";

export default defineConfig([
  globalIgnores(["build/"]),
]);

There is a traversal nuance when restoring selected files from an ignored directory: build/** prevents traversal, while build/**/* allows later patterns to unignore selected contents. See ESLint’s ignore documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

mypy

mypy’s exclude is a regular expression used during recursive discovery. Use forward slashes on all platforms:

[mypy]
exclude = ^(build|generated|vendor)/

The setting does not establish that every explicitly named file or imported module will be skipped. The separate exclude_gitignore option can add paths from .gitignore; it defaults to False. See the mypy configuration reference and mypy documentation on running and managing imports.

Semgrep

Put directory patterns in .semgrepignore; for example:

# .semgrepignore
dist/
vendor/

Semgrep uses these patterns to identify scan targets rather than simply concealing results afterward. Its repository documentation describes gitignore-style behavior, but negation patterns such as !kept/ are not supported by all implementations; check the implementation and version before relying on re-inclusion. See the Semgrep ignore-file documentation and its explanation of file targeting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bandit

For YAML or TOML configuration, use exclude_dirs and pass the configuration path with -c:

# bandit.yaml
exclude_dirs:
  - tests
  - vendor
bandit -c bandit.yaml -r .

INI configuration uses the different key exclude. Bandit’s CLI also supports an exclusion option described as accepting comma-separated glob patterns. Keep the file format and option spelling aligned with your installed version; consult the Bandit 1.8.0 configuration guide and current command-line reference.

PHPStan

PHPStan distinguishes files omitted from analysis from files omitted from both analysis and symbol discovery. Its excludePaths patterns use fnmatch().

parameters:
    paths:
        - src
    excludePaths:
        analyse:
            - src/thirdparty
        analyseAndScan:
            - src/broken

Use analyse when files should not be analyzed but may still be needed for symbol discovery. Use analyseAndScan only when they should also be omitted from that discovery process. See the PHPStan configuration reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure distinct layers carefully

CodeQL code scanning

CodeQL configuration supports paths and paths-ignore for applicable analysis modes, including documented cases for interpreted languages and compiled-language analysis without a build. For example:

paths:
  - src
paths-ignore:
  - src/node_modules
  - '**/*.test.js'

Check that the language and build mode match the configuration you are using. GitHub workflow trigger filters such as on.push.paths determine whether a workflow runs; they do not select source files for a scan that runs. Hidden-directory defaults also vary: current documentation notes that Python extraction includes hidden directories by default and gives paths-ignore: ["**/.*/**"] as an exclusion. See GitHub’s CodeQL workflow configuration options and the CodeQL CLI 2.21.4 release notes.

clang-tidy header diagnostics

clang-tidy’s --header-filter and --exclude-header-filter control which header diagnostics are displayed. The exclusion option must be used with the header filter, and diagnostics in each translation unit’s main file are always displayed. This is not a general way to skip source-file analysis.

clang-tidy source.cpp \
  --header-filter='.*' \
  --exclude-header-filter='.*/third_party/.*' \
  -- -Iinclude

Confirm the actual path spelling and regular-expression behavior in your environment. See the clang-tidy documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

pre-commit hook inputs

pre-commit’s hook-level exclude is a Python regular expression matched against file paths. It controls which files are passed to that hook. For example:

repos:
  - repo: https://github.com/pycqa/flake8
    rev: <pinned-revision>
    hooks:
      - id: flake8
        exclude: ^(generated|vendor)/

The revision placeholder must be replaced with the revision pinned by your project. Flake8 documents that pre-commit passes file paths positionally, so Flake8’s own --exclude does not affect those explicit arguments. Use pre-commit’s filter for that hook, and configure any direct or separate CI invocation independently. See the pre-commit configuration reference and Flake8’s hook documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the exclusion in the invocation that matters

  1. Check the analyzer version and confirm which configuration file the command actually loads.
  2. Add one narrow pattern, then run the same command used in CI.
  3. Inspect verbose output or a target summary to confirm the directory’s files are no longer targets. An empty findings list alone does not prove files were skipped.
  4. If the tool accepts explicit file arguments, test both recursive discovery and a direct file path.
  5. Check editor integrations, pre-commit, CI jobs, and scheduled full scans separately; each may select inputs differently.
  6. Recheck the pattern when directory contents, build layout, or tool versions change.

Troubleshoot a pattern that does not work

  • Pattern language mismatch: Globs, regular expressions, trailing slashes, **, and negation do not mean the same thing in every tool.
  • Wrong path base: A relative pattern may be interpreted from the config directory, repository root, or process working directory. Confirm the tool’s documented base.
  • Explicit path bypass: A file supplied directly may still be analyzed. Ruff documents this behavior unless force-exclude is enabled; verify other tools with your actual invocation.
  • Defaults replaced: Replacing a default exclusion list can bring unwanted files back into scope. Use an additive setting such as Ruff’s extend-exclude where appropriate.
  • Re-inclusion fails: A tool may stop traversing an ignored directory before it can reach a file named by a later negation pattern.
  • Only one hook is filtered: A pre-commit setting does not necessarily affect direct CLI use or a separate CI job.
  • Symbols are still needed: Excluding analysis does not always remove files from parsing, compilation, imports, or symbol discovery. PHPStan’s separate exclusion modes make that distinction explicit.

When a directory-wide exclusion is the wrong fix

An exclusion can reduce noise or remove generated output from a tool’s targets, but it creates a coverage blind spot. A broad vendor or generated-code directory can later contain hand-written code, and a dependency folder can contain code that still matters to a security review. Keep exclusions narrow, document why each path is omitted, and revisit them when directory contents change.

  • Restrict analysis roots to source directories the team owns.
  • Prevent generated artifacts from entering discovery at the generation or file-selection stage.
  • Use a rule-specific ignore for a known benign pattern rather than excluding all checks in a directory.
  • Use a baseline to manage existing findings while keeping analysis coverage.
  • Configure dependency or library handling so third-party code can supply needed symbols without receiving the same checks as first-party code.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.