C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 66/100
Rechercherichtung
Lies FeedManager.cs in csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching, insbesondere GetReachableNuGetFeeds und dessen Aufrufer in NugetPackageRestorer.Restore(). Prüfe, wie leere Feed-Mengen behandelt werden, und führe die relevanten C#-Extractor-Tests aus. Erledigt ist die Aufgabe, wenn Reachability-Prüfungen ohne zu prüfende Feeds nicht mehr die irreführende Warnung ausgeben, während Prüfungen für tatsächlich vorhandene Feeds ihr Verhalten beibehalten.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config
Problem
With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:
[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json
The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).
Root cause
NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):
var reachableFeeds = feedsToCheck
.Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
.ToList();
if (reachableFeeds.Count == 0)
{
logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}
Reproduction
- Create a repository with any C# project that restores a package from nuget.org and has no
nuget.config. - Run the default CodeQL setup or
github/codeql-action/init@v4withlanguages: csharpandbuild-mode: none. - The
Perform CodeQL Analysislog containsChecking NuGet feed reachability on feeds:(empty) followed byWarning: No NuGet feeds are reachable.
Workaround
A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):
[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:
- uses: github/codeql-action/analyze@v4
env:
CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'
linksplatform/Interfaces does this in PR #151.
Suggested fix
Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:
if (feedsToCheck.Count == 0)
{
logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
return [];
}
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.2k
- Forks
- 2.1k
- Ø Merge
- 2 T. 13 Std.
- Gemergte PRs (30 T.)
- 144
Entwicklungsumgebung
Startet den Dev-Container des Projekts im Browser, mit Ihrem eigenen GitHub-Konto.
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/codeql
-
Python: trailing comma in a PEP 695 type parameter list causes a parse errorEvtl. vergeben @jketema hat das vor 6 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
github/codeql#22739 · 1 Kommentar · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
false-positive javascript
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
github/codeql#22632 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Evtl. vergeben @cnuss hat das vor 188 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
github/codeql#21637 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
false-positive
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
github/codeql#21076 · 3 Kommentare · 3 Reaktionen ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 54/100
github/codeql#22770 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Ähnliche Issues
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded configOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag
-
kind/bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
status: team-only type: dependency-upgrade
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
spring-projects/spring-boot#52099 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 69/100
PrestaShop/PrestaShop#43140 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Round video messages start gray and blocky with libx264: encoder is configured for 1,000,000 fpsOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
telegramdesktop/tdesktop#31422 ·
Maintainer antworten meist innerhalb von 9 Tagen