C#: TSP note and compilation info for unreachable feeds. - #22364
Draft
michaelnebel wants to merge 4 commits into
Draft
C#: TSP note and compilation info for unreachable feeds.#22364michaelnebel wants to merge 4 commits into
michaelnebel wants to merge 4 commits into
Conversation
michaelnebel
force-pushed
the
csharp/tspreportbadfeeds
branch
6 times, most recently
from
August 21, 2026 09:19
a7acd5c to
8c6d158
Compare
Contributor
There was a problem hiding this comment.
Pull request overview
Improves C# buildless diagnostics by identifying unreachable explicitly configured NuGet feeds.
Changes:
- Reports unreachable feeds in warnings, tool status diagnostics, and compilation metadata.
- Updates integration queries and expected results to support string-valued metadata.
- Adds a change note.
Show a summary per file
| File | Description |
|---|---|
csharp/ql/lib/change-notes/2026-08-18-tsp-nuget-feed-reachability.md |
Documents the diagnostic enhancement. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/diagnostics.expected |
Expects the unreachable fallback feed. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_fallback/CompilationInfo.expected |
Expects unreachable-feed metadata. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error/CompilationInfo.expected |
Expects the failed feed URL. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/diagnostics.expected |
Expects multiple unreachable feeds. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_config_error_timeout/CompilationInfo.expected |
Expects multiple failed feed URLs. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_clear/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/posix/standalone_dependencies_nuget_clear/CompilationInfo.expected |
Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_winforms/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_winforms/CompilationInfo.expected |
Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_slnx/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_slnx/CompilationInfo.expected |
Updates string-formatted expectations. |
csharp/ql/integration-tests/all-platforms/standalone_resx/CompilationInfo.ql |
Reads string metadata values. |
csharp/ql/integration-tests/all-platforms/standalone_resx/CompilationInfo.expected |
Updates string-formatted expectations. |
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs |
Computes and reports unreachable explicit feeds. |
Review details
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 18/18 changed files
- Comments generated: 1
- Review effort level: Balanced
Contributor
There was a problem hiding this comment.
Review details
Suppressed comments (1)
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs:549
- Returning the original value when URI parsing fails defeats the redaction this helper is intended to provide.
FeedManageraccepts any source beginning with HTTP(S), so a malformed credential-bearing value such ashttps://user:secret@can failnew Uri, be classified as unreachable, and then be written verbatim to compilation telemetry and the status-page diagnostic. Do not echo an unparsed value on this path.
return feed;
- Files reviewed: 18/18 changed files
- Comments generated: 1
- Review effort level: Balanced
michaelnebel
force-pushed
the
csharp/tspreportbadfeeds
branch
from
August 24, 2026 14:14
ff13ec8 to
fc43f8f
Compare
Contributor
There was a problem hiding this comment.
Review details
Suppressed comments (1)
csharp/extractor/Semmle.Extraction.CSharp.DependencyFetching/NugetPackageRestorer.cs:550
- Malformed explicit feeds still bypass the redaction: feed discovery only checks the
http(s)://prefix, so a value such ashttps://user:token@reaches this branch after both URI construction and the reachability request fail. Returning it verbatim then exposes the credential through the warning,compilation_info, and the telemetry-enabled diagnostic. Use a non-sensitive placeholder (or a separately validated redaction) when parsing fails.
return feed;
- Files reviewed: 18/18 changed files
- Comments generated: 0 new
- Review effort level: Balanced
…able explicit feeds.
…f hardcoded in the nuget.config feed URL).
michaelnebel
force-pushed
the
csharp/tspreportbadfeeds
branch
from
August 25, 2026 07:15
fc43f8f to
65184b8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In this PR, the tool status page note is improved to contain unreachable explicit feeds.