C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 66/100
Direção de pesquisa
Leia FeedManager.cs em csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching, especialmente GetReachableNuGetFeeds e seus chamadores em NugetPackageRestorer.Restore(). Verifique como conjuntos de feeds vazios são tratados e execute os testes relevantes do extractor de C#. O trabalho estará concluído quando as verificações de reachability sem feeds para verificar não produzirem mais o aviso enganoso, enquanto as verificações de feeds reais mantiverem seu comportamento.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config
Problem
With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:
[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json
The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).
Root cause
NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):
var reachableFeeds = feedsToCheck
.Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
.ToList();
if (reachableFeeds.Count == 0)
{
logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}
Reproduction
- Create a repository with any C# project that restores a package from nuget.org and has no
nuget.config. - Run the default CodeQL setup or
github/codeql-action/init@v4withlanguages: csharpandbuild-mode: none. - The
Perform CodeQL Analysislog containsChecking NuGet feed reachability on feeds:(empty) followed byWarning: No NuGet feeds are reachable.
Workaround
A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):
[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds:
[build-stdout] [001] Warning: No NuGet feeds are reachable.
The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:
- uses: github/codeql-action/analyze@v4
env:
CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'
linksplatform/Interfaces does this in PR #151.
Suggested fix
Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:
if (feedsToCheck.Count == 0)
{
logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
return [];
}
- Linguagem predominante
- CodeQL
- Estrelas
- 10.2k
- Forks
- 2.1k
- Merge médio
- 2d 14h
- PRs com merge (30d)
- 142
Preparar o ambiente
Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/codeql
-
Python: trailing comma in a PEP 695 type parameter list causes a parse errorTalvez já em andamento @jketema assumiu há 5 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
github/codeql#22739 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
-
false-positive javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
github/codeql#22632 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Talvez já em andamento @cnuss assumiu há 188 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
github/codeql#21637 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
false-positive
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
github/codeql#21076 · 3 comentários · 3 reações ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 62/100
github/codeql#22755 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
Todas as issues de github/codeql
Issues semelhantes
-
Bug Enhancement Performance
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
needs-triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
flashinfer-ai/flashinfer#6212 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
zenstackhq/zenstack#2873 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
activescott/lessmsi#306 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Jason-Vaughan/TangleClaw#2195 ·
Mantenedores costumam responder em até 1 dia