Skip to main content
Scan Configuration controls what a scan does before and after it runs: which files it reads, how it handles pull requests, and what it saves for next time. It’s a project- and organisation-level settings area with several sections; this page covers only Skip patterns, the section that keeps files out of a scan. Before you start: Changing Scan Configuration needs the Operator or Admin role. See Team & Roles.

The Other Sections

Scan Configuration also has sections documented elsewhere:
  • Pull-request feedback — which pull requests Earnie checks, and how much it writes. See Merge Gate.
  • Component overrides — saved corrections that settle a package’s findings automatically on every scan. See Triaging Findings.
  • AI provenance — opting a project in to fetching Git LFS-pointed models. See AI Provenance.
  • Self-check — how long a Self-check waits before returning a result. See Earnie CLI.
  • Automatic scanning and Pre-commit, on a project’s own page — whether a push to the default branch scans automatically, and whether a technical failure in the pre-commit hook blocks a commit. See Your First Scan and Earnie CLI.

Three Layers

Skip patterns and size rules can come from three layers:
  1. The repository’s own scanoss.json file, when it has one.
  2. The project’s Scan Configuration, set from the project’s own Scan Configuration page.
  3. The organisation’s Scan Configuration, set at Settings → Scan Configuration.
These rules accumulate rather than override one another: a file skipped by any layer is skipped, whichever layer added the rule. This is different from a component override, where the project, scanoss.json, and the organisation are read in a strict precedence order and only the most specific one wins. Keep rules simply add up; nothing here is overridden. A project’s Inherited layers view lists the rules coming from scanoss.json and from the organisation, so it’s clear where a rule that isn’t in the project’s own list actually came from.

Keeping Files Out of a Scan

Earnie applies keep rules before fingerprinting: a set of patterns and, now, size limits that decide which files are worth scanning. See How Your Source Reaches Earnie for where this fits in a scan.

Skip Patterns

A skip pattern excludes files or directories by path, gitignore-style, for example vendor/** or **/*.min.js.

Size Rules

A size rule excludes files by size instead of, or in addition to, path. This matters most for large binary files, such as AI model weights, that can push a scan’s memory usage far past what a source file would. Add or edit a size rule from a Size rules table, under Skip patterns, on either the project’s or the organisation’s Scan Configuration page:
  1. Select Add rule, or open an existing one.
  2. Enter one or more patterns the rule applies to.
  3. Enter an amount and a unit (for example 50 MB; 1 MB = 1024 KB) for minimum, maximum, or both.
A matching file is skipped when it’s smaller than the minimum, or larger than the maximum. Leaving a bound blank means no bound on that side. A rule needs at least one pattern and at least one bound; the minimum can’t be larger than the maximum.
Changing a size rule can trigger a full rescan. Earnie fingerprints your effective configuration, including size rules, so that a change in what’s kept is never mistaken for a change in your code. Editing a size rule plans the project’s next scan as full rather than incremental.

What’s Next

With scan configuration set, revisit Your First Scan to see how these rules fit into a run, or AI Provenance if the files you’re keeping out are model weights.