microsoft / microsoft/azure-tools-for-java

[IntelliJ] Uncaught Exception Error retrieving vulnerability data from GitHub Security Advisory API java.net.ConnectException

Open
#11,982 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
262
Forks
185
Avg merge
2d 21h
Merged PRs (30d)
1

Description

IntelliJ build version: 2026.1 IU-261.22158.277
OS: Mac OS X
JDK: JetBrains s.r.o. 25.0.2
Plugin version: 3.97.4-2026.1
Additional Info: None
Parent component:

com.intellij.openapi.wm.impl.IdeRootPane[,0,0,1920x1080,layout=com.intellij.openapi.wm.impl.IdeRootPane$CustomHeaderRootLayout,alignmentX=0.0,alignmentY=0.0,border=,flags=449,maximumSize=,minimumSize=,preferredSize=]

Error message:

IdeaLoggingEvent[message=Error retrieving vulnerability data from GitHub Security Advisory API, throwable=java.net.ConnectException
	at <REDACTED: user-file-path>(HttpClientImpl.java:923)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.retrieveVulnerabilityData(CVECheckService.java:312)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.fetchCves(CVECheckService.java:241)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.getCveUpgradeIssues(CVECheckService.java:200)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.batchGetCVEIssues(CVECheckService.java:171)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.JavaUpgradeIssuesDetectionService.getCVEIssues(JavaUpgradeIssuesDetectionService.java:385)
	at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with CVECheckService.java around retrieveVulnerabilityData (line 312) and its callers fetchCves and getCveUpgradeIssues; then review JavaUpgradeIssuesDetectionService.java around getCVEIssues. Reproduce the GitHub Security Advisory API connection failure with the reported IntelliJ and plugin versions. Done means the failure has a verified, non-uncaught outcome in the CVE flow.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, java
Domain
devtools, networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.