Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config

クローズ 初心者向け
#22,766 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
66/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
csharp
領域
backend

調査の方向性

csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching の FeedManager.cs を読み、特に GetReachableNuGetFeeds と NugetPackageRestorer.Restore() 内の呼び出し元を確認してください。空の feed セットがどのように処理されるかを確認し、関連する C# extractor のテストを実行してください。確認対象の feed がない場合の reachability チェックで誤解を招く警告が出なくなり、実際の feed に対するチェックでは従来の動作が維持されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config

Problem

With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:

[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json

The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).

Root cause

NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):

var reachableFeeds = feedsToCheck
    .Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
    .ToList();

if (reachableFeeds.Count == 0)
{
    logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}

Reproduction

  1. Create a repository with any C# project that restores a package from nuget.org and has no nuget.config.
  2. Run the default CodeQL setup or github/codeql-action/init@v4 with languages: csharp and build-mode: none.
  3. The Perform CodeQL Analysis log contains Checking NuGet feed reachability on feeds: (empty) followed by Warning: No NuGet feeds are reachable.

Workaround

A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):

[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.

The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:

- uses: github/codeql-action/analyze@v4
  env:
    CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'

linksplatform/Interfaces does this in PR #151.

Suggested fix

Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:

if (feedsToCheck.Count == 0)
{
    logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
    return [];
}
主要言語
CodeQL
スター
10.2k
フォーク
2.1k
平均マージ
2日 11時間
マージ済み PR(30日)
160

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/codeql のほかの issue

github/codeql の issue をすべて見る

似ている issue

Backend & API Design の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。