| 1 | # CodeQL configuration for code scanning. |
| 2 | # |
| 3 | # Test code is out of scope for security alerts: it runs only in CI, talks to |
| 4 | # in-process loopback servers, and routinely prints fixture secrets in |
| 5 | # assertion messages to prove they are redacted elsewhere. Those paths are |
| 6 | # excluded here so alerts point at product code. |
| 7 | # |
| 8 | # Inline `#[cfg(test)] mod tests` blocks inside product files cannot be |
| 9 | # excluded by path; alerts there are dismissed as "used in tests". |
| 10 | # |
| 11 | # This file takes effect only with CodeQL advanced setup: |
| 12 | # .github/workflows/codeql.yml passes it to `github/codeql-action/init`. |
| 13 | # Default setup ignores it, so the repository's code scanning setting must be |
| 14 | # switched from Default to Advanced for either to apply. |
| 15 | name: codewhale-codeql |
| 16 | |
| 17 | paths-ignore: |
| 18 | # Rust integration tests and split-out unit test modules. |
| 19 | - "**/tests/**" |
| 20 | - "**/tests.rs" |
| 21 | - "**/*_tests.rs" |
| 22 | - "**/test_support.rs" |
| 23 | - "**/*_test_support.rs" |
| 24 | # JavaScript / TypeScript test suites. |
| 25 | - "**/test/**" |
| 26 | - "**/__tests__/**" |
| 27 | - "**/*.test.js" |
| 28 | - "**/*.test.mjs" |
| 29 | - "**/*.test.ts" |
| 30 | - "**/*.test.tsx" |
| 31 | - "**/*.spec.js" |
| 32 | - "**/*.spec.ts" |
| 33 | - "**/*.spec.tsx" |
| 34 |