C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching の FeedManager.cs を読み、特に GetReachableNuGetFeeds と NugetPackageRestorer.Restore() 内の呼び出し元を確認してください。空の feed セットがどのように処理されるかを確認し、関連する C# extractor のテストを実行してください。確認対象の feed がない場合の reachability チェックで誤解を招く警告が出なくなり、実際の feed に対するチェックでは従来の動作が維持されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config
Problem
With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:
[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json
The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).
Root cause
NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):
var reachableFeeds = feedsToCheck
.Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
.ToList();
if (reachableFeeds.Count == 0)
{
logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}
Reproduction
- Create a repository with any C# project that restores a package from nuget.org and has no
nuget.config. - Run the default CodeQL setup or
github/codeql-action/init@v4withlanguages: csharpandbuild-mode: none. - The
Perform CodeQL Analysislog containsChecking NuGet feed reachability on feeds:(empty) followed byWarning: No NuGet feeds are reachable.
Workaround
A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):
[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:
- uses: github/codeql-action/analyze@v4
env:
CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'
linksplatform/Interfaces does this in PR #151.
Suggested fix
Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:
if (feedsToCheck.Count == 0)
{
logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
return [];
}
- 主要言語
- CodeQL
- スター
- 10.2k
- フォーク
- 2.1k
- 平均マージ
- 2日 11時間
- マージ済み PR(30日)
- 160
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/codeql のほかの issue
-
false-positive javascript
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
github/codeql#22632 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)対応中かも @cnuss が 191 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
github/codeql#21637 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
false-positive
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
github/codeql#21076 · コメント 3 件 · リアクション 3 件 ·
メンテナーはふだん 1 日以内に返信
-
Rust: extraction succeeds with missing proc-macro output when the project's `rust-version` exceeds the forced toolchain対応中かも @paldepind が 1 日前に担当しました。 オープン
github/codeql#22793 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
Actions: `uses: $/…` self-repository references are not resolved to local reusable workflows or composite actions (false positives and downgraded severity)対応中かも @WilliamBerryiii が 1 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
github/codeql#22755 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
supadata-ai/mcp#27 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
objectionary/sodg.rs#300 ·
-
lane: fast
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
unicef/adt-studio#946 ·
メンテナーはふだん 2 日以内に返信
-
good first issue help wanted track:code
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
Sara-Managed-Projects/space-radar#755 ·
メンテナーはふだん 1 日以内に返信
-
buffer translateToString()/getChars() return '' for empty cells, collapsing cursor-positioned textオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
coder/ghostty-web#205 ·