Skip to content

docs: explain how Consistent Ignores match Snyk Code findings and where they can move - #1942

Open
sebsnyk wants to merge 2 commits into
mainfrom
docs/coin-2733-ignore-matching-limits
Open

sebsnyk wants to merge 2 commits into
mainfrom
docs/coin-2733-ignore-matching-limits

Conversation

@sebsnyk

@sebsnyk sebsnyk commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The Consistent Ignores page says an ignore is respected wherever a test runs. A finding can appear as open again after tests of one repository start from different directories, or when the repository holds duplicate copies of its source files. The page gives no cause and no steps for either case.

Solution

  • Explain that Snyk Code records paths relative to the directory a test starts from and uses the path when it matches a finding.
  • Name the two setups that cause an ignore to attach to a different path, and state that the finding at the other path is suppressed.
  • Add a review step for ignored findings in duplicate directories.

Notes

Builds on the commit already on this branch's base, docs/coin-2733-consistent-ignores-matching. No dates or release promises are on the page.

🤖 Generated with Claude Code


Note

Low Risk
Documentation-only updates to user-facing guides; no product code or configuration changes.

Overview
Expands Snyk Code Consistent Ignores documentation so readers understand how ignores attach to findings and why an ignored issue can show as open again.

The main README now states that ignores bind to the repository-level snyk/asset/finding/v1 identifier (not file/line), how Snyk rematches findings across branches, CLI, IDE, and PR checks, and that paths are relative to the test working directory. It adds troubleshooting for mismatches when tests start from different directories or when duplicate source trees exist, including steps to re-ignore, retest, review duplicate dirs, and contact support.

The CLI page adds guidance to run snyk code test from the Git repo root for consistent paths, and corrects the JSON fingerprint path to runs[0].results[n].fingerprints["snyk/asset/finding/v1"] with a link to the new matching section. The PR checks page fixes the same identifier string (asset vs assets).

Reviewed by Cursor Bugbot for commit db46ec6. Bugbot is set up for automated code reviews on this repo. Configure here.

ahmed-agabani-snyk and others added 2 commits September 28, 2026 15:00
Correct the overpromise in the Consistent Ignores introduction, explain
that ignores attach to the repository-level finding identifier, state
that deleting a branch Project or target does not delete or reopen
Consistent Ignores, and add steps for when an ignored finding appears as
open again. Recommend running snyk code test from the repository root.
Fix the fingerprint key (snyk/asset/finding/v1) and JSON path in the CLI
and pull request check pages, and replace a dangling cross-reference.

Co-authored-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@snyk-io

snyk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@sebsnyk
sebsnyk marked this pull request as ready for review October 6, 2026 22:39
@sebsnyk
sebsnyk requested a review from a team as a code owner October 6, 2026 22:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants