aboutcode-org / aboutcode-org/nuget-inspector

NullReferenceException when getting remote metadata

オープン
#78 コメント 0 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
C#
スター
5
フォーク
13
PR マージ指標
30日以内にマージされた PR はありません

説明

We are using nuget-inspector (orchestrated by ORT) in version 0.10.0 to analyze a project that declares a private source repository. The tool is invoked as follows:

```
nuget-inspector --with-details --verbose --project-file Project.csproj --json /tmp/nuget-inspector-output.json
```
The invocation is successful, but for some packages no metadata can be retrieved, and warnings like the one below are issued for those packages:

```
WARNING: Failed to get remote metadata for name: 'Newtonsoft.Json' version: '13.0.4'. System.NullReferenceException: Object reference not set to an instance of an object.
at NugetInspector.NugetApi.GetPackageDownload(PackageIdentity identity, Boolean with_details) in ./nuget-inspector/NugetApi.cs:line 542
at NugetInspector.BasePackage.UpdateWithRemoteMetadata(NugetApi nugetApi, Boolean with_details) in ./nuget-inspector/Models.cs:line 349
at NugetInspector.BasePackage.Update(NugetApi nugetApi, Boolean with_details) in ./nuget-inspector/Models.cs:line 321
```
According to my analysis, the problem seems to be that the private repository (hosted on JFrog Artifactory) does not return a value for the optional `CatalogUri` property. The code that raises the exception, method `GetPackageDownload()` in `NugetApi.cs` in line 542, accesses this property without a null check:

```
PackageSearchMetadataRegistration? registration = FindPackageVersion(identity);
if (registration == null)
return download;

var package_catalog_url = registration.CatalogUri.ToString(); // <-- Line 542, NRE here
```

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。