Uh oh!
There was an error while loading. Please reload this page.
C#: TSP note and compilation info for unreachable feeds. - #22364
Conversation
a7acd5c to
8c6d158CompareThere was a problem hiding this comment.
Pull request overview
Improves C# buildless diagnostics by identifying unreachable explicitly configured NuGet feeds.
Changes:
- Reports unreachable feeds in warnings, tool status diagnostics, and compilation metadata.
- Updates integration queries and expected results to support string-valued metadata.
- Adds a change note.
Show a summary per file
| File | Description |
|---|---|
csharp/ql/lib/change-notes/2026-08-18-tsp-nuget-feed-reachability.md | Documents the diagnostic enhancement. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/diagnostics.expected | Expects the unreachable fallback feed. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/CompilationInfo.expected | Expects unreachable-feed metadata. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error/CompilationInfo.expected | Expects the failed feed URL. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/diagnostics.expected | Expects multiple unreachable feeds. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/CompilationInfo.expected | Expects multiple failed feed URLs. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_clear/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_clear/CompilationInfo.expected | Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_winforms/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_winforms/CompilationInfo.expected | Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_slnx/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_slnx/CompilationInfo.expected | Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_resx/CompilationInfo.ql | Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_resx/CompilationInfo.expected | Updates string-formatted expectations. |
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs | Computes and reports unreachable explicit feeds. |
Review details
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 18/18 changed files
- Comments generated: 1
- Review effort level: Balanced
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Review details
Suppressed comments (1)
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs:549
- Returning the original value when URI parsing fails defeats the redaction this helper is intended to provide.
FeedManageraccepts any source beginning with HTTP(S), so a malformed credential-bearing value such ashttps://user:secret@can failnew Uri, be classified as unreachable, and then be written verbatim to compilation telemetry and the status-page diagnostic. Do not echo an unparsed value on this path.
return feed;
- Files reviewed: 18/18 changed files
- Comments generated: 1
- Review effort level: Balanced
Uh oh!
There was an error while loading. Please reload this page.
ff13ec8 to
fc43f8fCompareThere was a problem hiding this comment.
Review details
Suppressed comments (1)
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs:550
- Malformed explicit feeds still bypass the redaction: feed discovery only checks the
http(s)://prefix, so a value such ashttps://user:token@reaches this branch after both URI construction and the reachability request fail. Returning it verbatim then exposes the credential through the warning,compilation_info, and the telemetry-enabled diagnostic. Use a non-sensitive placeholder (or a separately validated redaction) when parsing fails.
return feed;
- Files reviewed: 18/18 changed files
- Comments generated: 0 new
- Review effort level: Balanced
fc43f8f to
65184b8Compare…able explicit feeds.
…f hardcoded in the nuget.config feed URL).
65184b8 to
9446394Comparemichaelnebel
commented
Aug 26, 2026
DCA looks good. |
Uh oh!
There was an error while loading. Please reload this page.
In this PR, the tool status page note is improved to contain unreachable explicit feeds.