Ignoring checks
Ignoring checks
Not every check fits every project. A static site has no health endpoint; an internal tool needs no sitemap. Silence what doesn’t apply, so a scan that passes means something.
Ignore a check or a service
preflight ignore sitemap # ignore the sitemap check
preflight ignore sentry # ignore Sentry's service check
preflight unignore sitemap # turn it back on
preflight checks # list every ID you can ignorepreflight ignore adds the ID to the ignore: list in preflight.yml, and unignore takes it out. To leave a check out of one run only, use --skip instead.
Allowlisting one secret
Allowing one finding is better than silencing the whole secrets check. Add an exception from the command line:
preflight ignore secrets web/js/golden-hour.jsThat adds an entry under checks.secrets.allowlist in preflight.yml. Its path is a doublestar glob (** matches across directories), matched against the file’s path in the project.
checks:
secrets:
allowlist:
- path: web/js/golden-hour.js
fingerprint: "sha256:<hex>" # recommended: pins the exact secret
reason: "HTTP-referrer-restricted Google Timezone key"
- path: "web/tools/**/*.php"Pin the fingerprint
A path alone accepts any secret that ever lands in that file. Add fingerprint: "sha256:<hex>", the SHA-256 of the secret’s value, and only that secret is allowed: rotate the key or drop a different one in the same file, and Preflight reports it again.
Findings match on path and fingerprint together, never the whole file, so an allowed secret on one line does not hide another on the next.