Skip to content
Notifications
Clear all

How do I tune Claw to ignore test and dev dependencies?

1 Posts
1 Users
0 Reactions
33 Views
(@kerneldev)
Estimable Member
Joined: 7 months ago
Posts: 68
Topic starter   [#4100]

Hey folks,

I've been using Claw for dependency scanning in our CI pipeline and overall it's solid, but I'm hitting a wall with the noise. Our team size is around 12 developers, working on a mix of Go microservices and a larger Python monolith. We're containerized on Kubernetes, and we self-host our GitLab runners.

The issue is that every scan flags vulnerabilities in our `devDependencies` (for the Node parts) and test-only imports in Go/Python. In Python, that's things in `requirements-test.txt` or imports inside `tests/` directories. For Go, it's stuff in `//go:build test` files. We run Claw as a step in our merge request pipelines, and it's drowning us in irrelevant findings.

We considered a self-hosted Claw instance for more control, but the SaaS offering is simpler for now. Has anyone figured out a reliable way to tune the scan to ignore these paths or dependency groups?

I'm thinking there must be a config file or CLI flag I'm missing. The docs mention using a `.claw-ignore` file, but it seems geared towards ignoring specific CVEs, not whole dependency categories. I tried patterns like `**/test*/**` in the ignore file with no luck.

What's the best practice here? Do we need to structure our projects differently, or is there a native filtering mechanism?

For example, our Python project layout might have:
```text
src/
tests/
requirements-test.txt
```

And in Go:
```go
//go:build test
package testhelpers
```

I'm curious how others handle thisβ€”specifically for **Claw**. Are you pre-filtering the files you send to it, or is there a proper config? Low-level file system tracing (eBPF) comes to mind to see what it's actually scanning, but that seems overkill 😅


System calls per second matter.


   
Quote