Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

C#: buildless extraction warns "No NuGet feeds are reachable" when the repository has no nuget.config

未關閉 適合新手
#22,766 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
66/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
csharp
領域
backend

研究方向

閱讀 csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching 中的 FeedManager.cs,尤其是 GetReachableNuGetFeeds 及其在 NugetPackageRestorer.Restore() 中的呼叫端。檢查空 feed 集合的處理方式,並執行相關的 C# extractor 測試。當沒有 feed 需要檢查時,reachability 檢查不再產生誤導性警告,而對實際 feed 的檢查仍維持原有行為,即為完成。

由索引模型根據 Issue 內容生成。

描述

C# buildless extraction logs "No NuGet feeds are reachable" when the repository has no nuget.config

Problem

With build-mode: none for C#, a repository that has no nuget.config gets this warning in every analysis log, even though nuget.org is reachable and is used a moment later:

[build-stdout] [001] Found 0 nuget.config files in /home/runner/work/Interfaces/Interfaces.
[build-stdout] [001] Found 1 NuGet feeds (with inherited ones) in nuget.config files: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.
...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Querying NuGet feed 'https://api.nuget.org/v3/index.json' succeeded.
[build-stdout] [001] Reachable NuGet feeds: https://api.nuget.org/v3/index.json

The list after "on feeds:" is empty. CodeQL CLI 2.27.1, github/codeql-action@v4, ubuntu-24.04. Full log: run 37528763774, line 3483. The same warning is in the earlier scheduled CodeQL runs of linksplatform/Interfaces, for example run 36213154910 (2026-09-26) and run 37194208178 (2026-10-04).

Root cause

NugetPackageRestorer.Restore() always evaluates feedManager.ReachableExplicitFeeds when the responsiveness check is on. That calls CheckSpecifiedFeeds(ExplicitFeeds), and ExplicitFeeds comes from the nuget.config files in the source tree, so it is empty here. GetReachableNuGetFeeds then warns whenever the result is empty, including when there was nothing to check (FeedManager.cs on main):

var reachableFeeds = feedsToCheck
    .Where(feed => feedManagerIo.IsFeedReachable(feed, initialTimeout, tryCount))
    .ToList();

if (reachableFeeds.Count == 0)
{
    logger.LogWarning($"No {fallbackStr}NuGet feeds are reachable.");
}

Reproduction

  1. Create a repository with any C# project that restores a package from nuget.org and has no nuget.config.
  2. Run the default CodeQL setup or github/codeql-action/init@v4 with languages: csharp and build-mode: none.
  3. The Perform CodeQL Analysis log contains Checking NuGet feed reachability on feeds: (empty) followed by Warning: No NuGet feeds are reachable.

Workaround

A nuget.config does not help. With one, the explicit set is {nuget.org}, but the inherited set (AllFeeds minus ExplicitFeeds) is now empty, and CheckSpecifiedFeeds(InheritedFeeds) logs the same warning (run 37530537674):

[build-stdout] [001] Found 1 nuget.config files in /home/runner/work/Interfaces/Interfaces: ...
[build-stdout] [001] Checking NuGet feed reachability on feeds: https://api.nuget.org/v3/index.json
[build-stdout] [001] Checking NuGet feed reachability on feeds: 
[build-stdout] [001] Warning: No NuGet feeds are reachable.

The only workaround is to turn the reachability check off for repositories whose only feed is nuget.org:

- uses: github/codeql-action/analyze@v4
  env:
    CODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK: 'false'

linksplatform/Interfaces does this in PR #151.

Suggested fix

Do not check or warn when there is nothing to check, for example at the start of GetReachableNuGetFeeds:

if (feedsToCheck.Count == 0)
{
    logger.LogInfo($"No {fallbackStr}NuGet feeds to check for reachability.");
    return [];
}
主要語言
CodeQL
星號
10.2k
分支
2.1k
平均合併
2 天 14 小時
30 天內合併 PR
142

環境準備

在 Codespaces 中開啟

在瀏覽器裡用你自己的 GitHub 帳號啟動這個專案的開發容器。

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 Backend & API Design Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。