github / github/codeql

[C#] General issue: CodeQL scanner encounters issues without reporting them

Offen
#20,353 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the issue**

I set up CodeQL scanning using default configurations in a private repository. When scanning the C# code, it reports that it had a low quality scan due to issues, and recommends resolving those issues. However, when I check the status page there are no other issues reported.

Image

Looking at the actions logs reveals the same situation:

```
CodeQL scanned 630 out of 630 C# files in this invocation. Check the status page for overall coverage information: https://github.com/**********/********/security/code-scanning/tools/CodeQL/status/
Analysis produced the following diagnostic information:
##[group]C# analysis with build-mode 'none' completed (1 result)
* C# analysis with build-mode 'none' completed.
##[endgroup]
##[group]Low C# analysis quality (1 result)
* Scanning C# code completed successfully, but the scan encountered issues. This may be caused by problems identifying dependencies or use of generated source code, among other reasons -- see other CodeQL diagnostics reported on the CodeQL status page for more details of possible causes. Addressing these warnings is advisable to avoid false-positive or missing results. If they cannot be addressed, consider scanning C# using either the `autobuild` or `manual` [build modes](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#comparison-of-the-build-modes).
##[endgroup]
##[group]C# was extracted with build-mode set to 'none' (1 result)
* C# was extracted with build-mode set to 'none'. This means that all C# source in the working directory will be scanned, with build tools, such as NuGet and dotnet CLIs, only contributing information about external dependencies.
##[endgroup]

##[group]Uploading code scanning results
```

There doesn't seem to be any information in the output showing what the issues it encountered were or how to fix them.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reproducing the default CodeQL scan for C# with build-mode 'none' and compare the Actions logs with the code-scanning status page. Investigate why the low-quality-scan diagnostic does not expose the underlying issues or remediation details. Done means the encountered issues are reported with actionable information, or the behavior is documented as expected.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
csharp
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
30/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.