Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config

Aberta Para iniciantes
#22,766 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
66/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
csharp
Domínio
backend

Direção de pesquisa

Leia FeedManager.cs em csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching, especialmente GetReachableNuGetFeeds e seus chamadores em NugetPackageRestorer.Restore(). Verifique como conjuntos de feeds vazios são tratados e execute os testes relevantes do extractor de C#. O trabalho estará concluído quando as verificações de reachability sem feeds para verificar não produzirem mais o aviso enganoso, enquanto as verificações de feeds reais mantiverem seu comportamento.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config

Problem

With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:

[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json

The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).

Root cause

NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):

var reachableFeeds = feedsToCheck
    .Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
    .ToList();

if (reachableFeeds.Count == 0)
{
    logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}

Reproduction

  1. Create a repository with any C# project that restores a package from nuget.org and has no nuget.config.
  2. Run the default CodeQL setup or github/codeql-action/init@v4 with languages: csharp and build-mode: none.
  3. The Perform CodeQL Analysis log contains Checking NuGet feed reachability on feeds: (empty) followed by Warning: No NuGet feeds are reachable.

Workaround

A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):

[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.

The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:

- uses: github/codeql-action/analyze@v4
  env:
    CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'

linksplatform/Interfaces does this in PR #151.

Suggested fix

Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:

if (feedsToCheck.Count == 0)
{
    logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
    return [];
}
Linguagem predominante
CodeQL
Estrelas
10.2k
Forks
2.1k
Merge médio
2d 14h
PRs com merge (30d)
142

Preparar o ambiente

Abrir no Codespaces

Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/codeql

Todas as issues de github/codeql

Issues semelhantes

Mais issues de Backend & API Design

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.