From 4911965953743784bc09db8e07213fa391eb01fc Mon Sep 17 00:00:00 2001 From: Ahmed Agabani <70949530+ahmed-agabani-snyk@users.noreply.github.com> Date: Mon, 28 Sep 2026 14:04:16 +0100 Subject: [PATCH 1/3] docs: explain how Consistent Ignores match Snyk Code findings Correct the overpromise in the Consistent Ignores introduction, explain that ignores attach to the repository-level finding identifier, state that deleting a branch Project or target does not delete or reopen Consistent Ignores, and add steps for when an ignored finding appears as open again. Recommend running snyk code test from the repository root. Fix the fingerprint key (snyk/asset/finding/v1) and JSON path in the CLI and pull request check pages, and replace a dangling cross-reference. Co-authored-by: Claude --- .../consistent-ignores-for-snyk-code/README.md | 18 +++++++++++++++++- .../snyk-cli.md | 4 +++- .../snyk-pull-request-checks.md | 2 +- 3 files changed, 21 insertions(+), 3 deletions(-) diff --git a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md index 0358ff452587..67689c101106 100644 --- a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md +++ b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md @@ -7,7 +7,7 @@ nav_context: classic # Consistent Ignores for Snyk Code -Snyk Code Consistent Ignores helps your teams focus on important tasks by filtering out distractions. It ensures that once an ignore is created, it is consistently respected regardless of how and where the test is run and what branch is being tested. +Snyk Code Consistent Ignores helps your teams focus on important tasks by filtering out distractions. After you ignore a finding, Snyk applies the ignore to that finding across the repository: in every branch and integration, in the Snyk CLI and Snyk IDE plugins, and in pull request checks. By filtering out false positives, inapplicable threats, and accepted risks, your security teams can prioritize fixing real problems, and developers can code without interruptions. @@ -19,6 +19,22 @@ Enable Snyk Code Consistent Ignores for your Group or Organization in the Snyk W Any ignores created or converted with the feature enabled will not be automatically converted back to Project-based ignores. You can recreate them manually after disabling the feature. +## How Consistent Ignores match findings + +Snyk attaches a Consistent Ignore to the repository-level identifier of a finding (`snyk/asset/finding/v1`), not to a file path and line number. + +Each time Snyk Code tests the repository, Snyk matches the results to the findings it already tracks for that repository. This applies to tests from every branch, the Snyk CLI, Snyk IDE plugins, and pull request checks. When code moves or changes, Snyk matches the finding to its existing identifier where it can, so the ignore continues to apply. + +Deleting a branch Project or a target does not delete Consistent Ignores and does not reopen ignored findings. The ignores remain in place for the repository. + +## If an ignored finding appears as open again + +In some cases, Snyk cannot match a finding to the identifier that its ignore is attached to, and the finding appears as **Open** again. The original ignore is not deleted. + +1. [Ignore the finding again](./#create-an-ignore) from its issue card. +2. [Retest the Project](../../../../scan-with-snyk/snyk-code/manage-code-vulnerabilities/#retesting-code-repository) to update the issue status. +3. If ignored findings reappear repeatedly, contact Snyk Support with the Organization, the Project, and the URLs of the affected issues. + ## User roles To create, edit and remove ignores, you need to have a user role assigned with Ignore management permissions. Only Group Admins can set these permissions (see [User role management](https://docs.snyk.io/platform-administration/user-management/user-role-management)). diff --git a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-cli.md b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-cli.md index f40a53000559..77b6f038bb22 100644 --- a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-cli.md +++ b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-cli.md @@ -23,6 +23,8 @@ Repository context is required for asset-scoped ignores to take effect. Policy-b `snyk code test` automatically detects the repository context if a .git directory is present. If not, you can explicitly specify it using the `--remote-repo-url` option. To verify the Git URL, run `git remote -v`. +Run `snyk code test` from the root of the Git repository, without a subdirectory path argument. Snyk records file paths relative to the directory you test, so testing from the root keeps paths consistent with other tests of the repository, such as tests of Projects imported through an SCM integration. + ## Snyk CLI default ignore behavior The CLI display output hides ignored results by default when you run `snyk code test`. It displays only unignored results and a summary table with the total number of issues (open and ignored). @@ -43,7 +45,7 @@ You can find the ignore metadata in the suppressions module of the SARIF output. ## Access the finding identifier in JSON and SARIF output -The finding identifier is included in the JSON and SARIF output of Snyk CLI. To view it, run `snyk code test --json` and navigate to `runs.results[n].fingerprints.snyk/assets/finding/v1` in the JSON output. See How Snyk Code identifies and tracks issues. +The Snyk CLI includes the finding identifier in its JSON and SARIF output. To view it, run `snyk code test --json` and navigate to `runs[0].results[n].fingerprints["snyk/asset/finding/v1"]` in the JSON output. To learn how Snyk uses this identifier, visit [How Consistent Ignores match findings](./#how-consistent-ignores-match-findings). You can use this identifier to [create new ignores using API calls](api.md). diff --git a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md index c6c9d2a0629c..0548edf7a7a5 100644 --- a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md +++ b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md @@ -15,7 +15,7 @@ If a finding is ignored after a PR check has already been completed, the PR chec • The inline comment for the ignored finding is collapsed by default and marked as resolved. -Ignores are respected in[ Snyk Code Pull Request Checks](../../../../scan-with-snyk/pull-requests/pull-request-checks/) regardless of whether they are created through [policy](./#manage-ignores-at-the-group-level-through-snyk-code-security-policies) or for an [individual `snyk/assets/finding/v1` value](./#manage-ignores-in-snyk-projects). +Ignores are respected in[ Snyk Code Pull Request Checks](../../../../scan-with-snyk/pull-requests/pull-request-checks/) regardless of whether they are created through [policy](./#manage-ignores-at-the-group-level-through-snyk-code-security-policies) or for an [individual `snyk/asset/finding/v1` value](./#manage-ignores-in-snyk-projects). ## Example: Snyk Pull Request Check with ignored finding From db46ec65a29e3a8e5c569a6bf98ccf896cd0fe41 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Tue, 6 Oct 2026 23:33:06 +0100 Subject: [PATCH 2/3] docs: describe path-based matching limits for Consistent Ignores Co-Authored-By: Claude Sonnet 5.5 --- .../consistent-ignores-for-snyk-code/README.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md index 67689c101106..b01b74cecae4 100644 --- a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md +++ b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/README.md @@ -25,15 +25,23 @@ Snyk attaches a Consistent Ignore to the repository-level identifier of a findin Each time Snyk Code tests the repository, Snyk matches the results to the findings it already tracks for that repository. This applies to tests from every branch, the Snyk CLI, Snyk IDE plugins, and pull request checks. When code moves or changes, Snyk matches the finding to its existing identifier where it can, so the ignore continues to apply. +Snyk Code records file paths relative to the directory that a test starts from, and uses the path as one of the signals when it matches a finding. Tests of one repository that start from different directories report the same file under different paths. + Deleting a branch Project or a target does not delete Consistent Ignores and does not reopen ignored findings. The ignores remain in place for the repository. ## If an ignored finding appears as open again -In some cases, Snyk cannot match a finding to the identifier that its ignore is attached to, and the finding appears as **Open** again. The original ignore is not deleted. +Snyk cannot always match a finding to the identifier that its ignore is attached to. Two setups cause this most often: + +* Tests of one repository that start from different directories, for example the repository root in a pipeline and a module directory on a developer machine. +* Repositories that contain duplicate copies of their source files, such as a baseline or build output directory. + +In these cases, Snyk can attach the ignore to the finding at a different path. The original finding appears as **Open** again, and the finding at the other path is suppressed. Snyk does not move the ignore back automatically. The original ignore is not deleted. 1. [Ignore the finding again](./#create-an-ignore) from its issue card. 2. [Retest the Project](../../../../scan-with-snyk/snyk-code/manage-code-vulnerabilities/#retesting-code-repository) to update the issue status. -3. If ignored findings reappear repeatedly, contact Snyk Support with the Organization, the Project, and the URLs of the affected issues. +3. Review ignored findings in duplicate directories, and exclude those directories from tests where possible. +4. If ignored findings reappear repeatedly, contact Snyk Support with the Organization, the Project, and the URLs of the affected issues. ## User roles From a25d6779520c054a541a9de4cfe9415fa49d0426 Mon Sep 17 00:00:00 2001 From: Sebastian Roth <97243337+sebsnyk@users.noreply.github.com> Date: Wed, 7 Oct 2026 07:42:53 +0100 Subject: [PATCH 3/3] Update scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md Co-authored-by: cursor[bot] <206951365+cursor[bot]@users.noreply.github.com> --- .../snyk-pull-request-checks.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md index 0548edf7a7a5..1d5669ff2b3b 100644 --- a/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md +++ b/scan-fix-and-prevent/manage-risk/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/snyk-pull-request-checks.md @@ -15,7 +15,7 @@ If a finding is ignored after a PR check has already been completed, the PR chec • The inline comment for the ignored finding is collapsed by default and marked as resolved. -Ignores are respected in[ Snyk Code Pull Request Checks](../../../../scan-with-snyk/pull-requests/pull-request-checks/) regardless of whether they are created through [policy](./#manage-ignores-at-the-group-level-through-snyk-code-security-policies) or for an [individual `snyk/asset/finding/v1` value](./#manage-ignores-in-snyk-projects). +Ignores are respected in [Snyk Code Pull Request Checks](../../../../scan-with-snyk/pull-requests/pull-request-checks/) regardless of whether they are created through [policy](./#manage-ignores-at-the-group-level-through-snyk-code-security-policies) or for an [individual `snyk/asset/finding/v1` value](./#manage-ignores-in-snyk-projects). ## Example: Snyk Pull Request Check with ignored finding