Skip to content

Baselines and suppressions

Review the existing findings before recording them:

Terminal window
kaev check --verbose
kaev baseline
git add .kaev-baseline.json
git commit -m "chore: establish KAEV baseline"

Future checks show and gate findings that are not recorded in the baseline. Fingerprints contain finding identity, not source code.

Use .kaevrc.json when a specific rule or file pattern has been deliberately accepted:

{
"version": 1,
"suppressions": [
{
"ruleId": "KAEV-PERF-001",
"file": "webapp/local/**",
"reason": "Dataset is contractually limited to 20 local records",
"expires": "2027-03-31"
}
]
}

Reasons are mandatory. Expired suppressions automatically stop matching. Commit policy files so changes receive normal code review.