Behavior of implicit osv-scanner.toml
when doing recursive scans
#1640
Labels
documentation
Improvements or additions to documentation
When configuring osv-scanner there's implicit and explicit
osv-scanner.toml
detection:osv-scanner/docs/configuration.md
Lines 8 to 10 in 3d964a5
How is this supposed to interact with
--recursive
? I'm seeing the following in ossf/scorecard#4530:implicit top-level
osv-scanner.toml
, with vulns in a subdirectory, still show those vulns which are ignored by the top-level config.When
--config osv-scanner.toml
is provided, the manually specified top-level config is applied to all subdirectories and they're all ignoredThe text was updated successfully, but these errors were encountered: