-
Notifications
You must be signed in to change notification settings - Fork 8
/
codeql.yml
43 lines (43 loc) · 893 Bytes
/
codeql.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
paths:
- app
- config
- lib
- components
- project_gems
paths-ignore:
- hugo
- node_modules
- "**/*.yml"
- "**/*.yaml"
- codeql
- project_gems/effective_datatables-2.6.14/effective_datatables-2.6.14.gemspec
- components/benefit_sponsors/spec/dummy
disable-default-queries: true
packs:
ruby:
- codeql/ruby-queries
javascript:
- codeql/javascript-queries
query-filters:
- exclude:
id: rb/csrf-protection-disabled
- exclude:
id: rb/csrf-protection-not-enabled
- exclude:
id: rb/incomplete-hostname-regexp
- exclude:
id: rb/redos
- exclude:
id: rb/reflected-xss
- exclude:
id: rb/regexp-injection
- exclude:
id: js/incomplete-sanitization
- exclude:
id: js/redos
- exclude:
id: js/cross-window-information-leak
- exclude:
id: js/unsafe-jquery-plugin
- exclude:
id: js/xss-through-dom