github / github/codeql

[C#] General issue: CodeQL scanner encounters issues without reporting them

未关闭
#20,353 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the issue**

I set up CodeQL scanning using default configurations in a private repository. When scanning the C# code, it reports that it had a low quality scan due to issues, and recommends resolving those issues. However, when I check the status page there are no other issues reported.

Image

Looking at the actions logs reveals the same situation:

```
CodeQL scanned 630 out of 630 C# files in this invocation. Check the status page for overall coverage information: https://github.com/**********/********/security/code-scanning/tools/CodeQL/status/
Analysis produced the following diagnostic information:
##[group]C# analysis with build-mode 'none' completed (1 result)
* C# analysis with build-mode 'none' completed.
##[endgroup]
##[group]Low C# analysis quality (1 result)
* Scanning C# code completed successfully, but the scan encountered issues. This may be caused by problems identifying dependencies or use of generated source code, among other reasons -- see other CodeQL diagnostics reported on the CodeQL status page for more details of possible causes. Addressing these warnings is advisable to avoid false-positive or missing results. If they cannot be addressed, consider scanning C# using either the `autobuild` or `manual` [build modes](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#comparison-of-the-build-modes).
##[endgroup]
##[group]C# was extracted with build-mode set to 'none' (1 result)
* C# was extracted with build-mode set to 'none'. This means that all C# source in the working directory will be scanned, with build tools, such as NuGet and dotnet CLIs, only contributing information about external dependencies.
##[endgroup]

##[group]Uploading code scanning results
```

There doesn't seem to be any information in the output showing what the issues it encountered were or how to fix them.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。