C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 66/100
Research direction
Read FeedManager.cs in csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching, especially GetReachableNuGetFeeds and its callers in NugetPackageRestorer.Restore(). Check how empty feed sets are handled and run the relevant C# extractor tests. Done when reachability checks with no feeds to check no longer produce the misleading warning, while checks for actual feeds retain their behavior.
Written by the indexing model from the issue text.
Description
C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config
Problem
With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:
[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json
The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).
Root cause
NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):
var reachableFeeds = feedsToCheck
.Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
.ToList();
if (reachableFeeds.Count == 0)
{
logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}
Reproduction
- Create a repository with any C# project that restores a package from nuget.org and has no
nuget.config. - Run the default CodeQL setup or
github/codeql-action/init@v4withlanguages: csharpandbuild-mode: none. - The
Perform CodeQL Analysislog containsChecking NuGet feed reachability on feeds:(empty) followed byWarning: No NuGet feeds are reachable.
Workaround
A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):
[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:
- uses: github/codeql-action/analyze@v4
env:
CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'
linksplatform/Interfaces does this in PR #151.
Suggested fix
Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:
if (feedsToCheck.Count == 0)
{
logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
return [];
}
- Dominant language
- CodeQL
- Stars
- 10.2k
- Forks
- 2.1k
- Avg merge
- 2d 14h
- Merged PRs (30d)
- 142
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/codeql
-
Python: trailing comma in a PEP 695 type parameter list causes a parse errorPossibly taken @jketema claimed this 5 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
github/codeql#22739 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
false-positive javascript
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
github/codeql#22632 · 1 comment ·
Maintainers usually reply within 1 day
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Possibly taken @cnuss claimed this 187 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
github/codeql#21637 · 2 comments ·
Maintainers usually reply within 1 day
-
false-positive
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
github/codeql#21076 · 3 comments · 3 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 62/100
github/codeql#22755 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Effect-TS/effect#8881 · 1 comment ·
Maintainers usually reply within 1 day
-
mail processing verified
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 7 days
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
-
L: github:actions L: php:composer
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
dependabot/dependabot-core#16493 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
api-platform/core#8649 ·
Maintainers usually reply within 1 day