You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Fortify扫描中排除特定文件或文件类型

Hey there! Excluding specific files or file types (like config or XML files) from Fortify scans is a super common task—here are the most straightforward, reliable methods depending on how you're executing your scans:

1. Use Fortify's Configuration Properties

You can define exclusion rules in Fortify's core configuration files or pass them as JVM arguments during scanning. This works across all scan types (command-line, UI, CI/CD pipelines).

  • Global configuration: Add your exclusions to the fortify-sca.properties file (usually located in your Fortify installation directory under Core/config). For example:
    # Exclude all XML files
    com.fortify.sca.excludedFiles=**/*.xml
    # Exclude specific config files and directories
    com.fortify.sca.excludedFiles=**/config/*.properties, **/settings.xml, src/main/resources/config/**
    
  • Per-scan configuration: Pass the exclusion directly as a JVM argument when running sourceanalyzer:
    sourceanalyzer -b myProjectBuild -Dcom.fortify.sca.excludedFiles="**/*.xml, **/config/**" <your-build-command>
    
2. Command-Line Exclusions (Direct Flag)

If you prefer not to mess with properties files, you can use the -exclude flag directly in your sourceanalyzer command. This is great for one-off scans or CI/CD scripts where you want explicit control:

# Exclude a single file
sourceanalyzer -b myBuild -exclude src/main/resources/app-config.xml <build-command>

# Exclude all files of a type
sourceanalyzer -b myBuild -exclude "**/*.xml" <build-command>

# Exclude multiple patterns (use commas to separate)
sourceanalyzer -b myBuild -exclude "**/*.xml, **/config/**, *.properties" <build-command>
3. Exclude via Fortify UI Tools

If you're using Fortify's graphical tools (like Static Code Analyzer UI, VS Code Extension, or Eclipse Plugin), you can set up exclusions through the UI:

  • Fortify Static Code Analyzer UI:
    1. Open your scan configuration
    2. Navigate to the File Filters or Exclusions tab
    3. Click "Add" and enter your glob pattern (e.g., **/*.xml, **/config/**)
    4. Save the configuration and run your scan
  • VS Code/Eclipse Plugins:
    1. Open the plugin settings
    2. Look for "Fortify: Excluded Files" or similar options
    3. Add your exclusion patterns as an array of globs (e.g., ["**/*.xml", "**/config/**"])

Pro Tips to Verify Your Exclusions

  • Before running a full scan, use the -list-files flag to check which files Fortify will process:
    sourceanalyzer -b myBuild -list-files
    
    This will output all files included in the scan—double-check that your excluded files don't appear here.
  • Remember that Fortify uses standard glob syntax:
    • ** = Recursively matches any subdirectory
    • * = Matches any characters (except /) in the current directory
    • ? = Matches a single character

内容的提问来源于stack exchange,提问作者Abdul Azeez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:42:39