DocumentationSearch docs
  1. 01Getting started
  2. 02Scanning
  3. 03Checks
  4. 04Services
  5. 05Configuration
  6. 06Ignoring checks
  7. 07CI
  8. 08Agent skill
  9. 09Dashboard
  10. 10Supported stacks

Ignoring checks

Ignoring checks

Not every check fits every project. A static site has no health endpoint; an internal tool needs no sitemap. Silence what doesn’t apply, so a scan that passes means something.

Ignore a check or a service

preflight ignore sitemap      # ignore the sitemap check
preflight ignore sentry       # ignore Sentry's service check
preflight unignore sitemap    # turn it back on
preflight checks              # list every ID you can ignore

preflight ignore adds the ID to the ignore: list in preflight.yml, and unignore takes it out. To leave a check out of one run only, use --skip instead.

Allowlisting one secret

Allowing one finding is better than silencing the whole secrets check. Add an exception from the command line:

preflight ignore secrets web/js/golden-hour.js

That adds an entry under checks.secrets.allowlist in preflight.yml. Its path is a doublestar glob (** matches across directories), matched against the file’s path in the project.

checks:
  secrets:
    allowlist:
      - path: web/js/golden-hour.js
        fingerprint: "sha256:<hex>"  # recommended: pins the exact secret
        reason: "HTTP-referrer-restricted Google Timezone key"
      - path: "web/tools/**/*.php"

Pin the fingerprint

A path alone accepts any secret that ever lands in that file. Add fingerprint: "sha256:<hex>", the SHA-256 of the secret’s value, and only that secret is allowed: rotate the key or drop a different one in the same file, and Preflight reports it again.

Findings match on path and fingerprint together, never the whole file, so an allowed secret on one line does not hide another on the next.