如何在Fortify扫描中排除特定文件或文件类型
Hey there! Excluding specific files or file types (like config or XML files) from Fortify scans is a super common task—here are the most straightforward, reliable methods depending on how you're executing your scans:
You can define exclusion rules in Fortify's core configuration files or pass them as JVM arguments during scanning. This works across all scan types (command-line, UI, CI/CD pipelines).
- Global configuration: Add your exclusions to the
fortify-sca.propertiesfile (usually located in your Fortify installation directory underCore/config). For example:# Exclude all XML files com.fortify.sca.excludedFiles=**/*.xml # Exclude specific config files and directories com.fortify.sca.excludedFiles=**/config/*.properties, **/settings.xml, src/main/resources/config/** - Per-scan configuration: Pass the exclusion directly as a JVM argument when running
sourceanalyzer:sourceanalyzer -b myProjectBuild -Dcom.fortify.sca.excludedFiles="**/*.xml, **/config/**" <your-build-command>
If you prefer not to mess with properties files, you can use the -exclude flag directly in your sourceanalyzer command. This is great for one-off scans or CI/CD scripts where you want explicit control:
# Exclude a single file sourceanalyzer -b myBuild -exclude src/main/resources/app-config.xml <build-command> # Exclude all files of a type sourceanalyzer -b myBuild -exclude "**/*.xml" <build-command> # Exclude multiple patterns (use commas to separate) sourceanalyzer -b myBuild -exclude "**/*.xml, **/config/**, *.properties" <build-command>
If you're using Fortify's graphical tools (like Static Code Analyzer UI, VS Code Extension, or Eclipse Plugin), you can set up exclusions through the UI:
- Fortify Static Code Analyzer UI:
- Open your scan configuration
- Navigate to the File Filters or Exclusions tab
- Click "Add" and enter your glob pattern (e.g.,
**/*.xml,**/config/**) - Save the configuration and run your scan
- VS Code/Eclipse Plugins:
- Open the plugin settings
- Look for "Fortify: Excluded Files" or similar options
- Add your exclusion patterns as an array of globs (e.g.,
["**/*.xml", "**/config/**"])
Pro Tips to Verify Your Exclusions
- Before running a full scan, use the
-list-filesflag to check which files Fortify will process:
This will output all files included in the scan—double-check that your excluded files don't appear here.sourceanalyzer -b myBuild -list-files - Remember that Fortify uses standard glob syntax:
**= Recursively matches any subdirectory*= Matches any characters (except/) in the current directory?= Matches a single character
内容的提问来源于stack exchange,提问作者Abdul Azeez

