microsoft / microsoft/azure-tools-for-java
[IntelliJ] Uncaught Exception Error retrieving vulnerability data from GitHub Security Advisory API java.io.IOException: Operation timed out
Open
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 262
- Forks
- 185
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 1
Description
IntelliJ build version: 2025.3.3 IU-253.31033.145
OS: Mac OS X
JDK: JetBrains s.r.o. 21.0.10
Plugin version: 3.97.5-2025.3
Additional Info: None
Parent component:
com.intellij.openapi.wm.impl.IdeRootPane[,0,0,1728x994,invalid,layout=com.intellij.openapi.wm.impl.IdeRootPane$CustomHeaderRootLayout,alignmentX=0.0,alignmentY=0.0,border=,flags=449,maximumSize=,minimumSize=,preferredSize=]
Error message:
IdeaLoggingEvent[message=Error retrieving vulnerability data from GitHub Security Advisory API, throwable=java.io.IOException: Operation timed out
at <REDACTED: user-file-path>(HttpClientImpl.java:970)
at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.retrieveVulnerabilityData(CVECheckService.java:312)
at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.fetchCves(CVECheckService.java:241)
at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.getCveUpgradeIssues(CVECheckService.java:200)
at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.CVECheckService.batchGetCVEIssues(CVECheckService.java:171)
at com.microsoft.azure.toolkit.intellij.appmod.javaupgrade.service.JavaUpgradeIssuesDetectionService.getCVEIssues(JavaUpgradeIssuesDetectionService.java:385)
at
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading CVECheckService.java around retrieveVulnerabilityData at line 312 and the callers fetchCves, getCveUpgradeIssues, and batchGetCVEIssues. Reproduce or inspect the timeout path for the GitHub Security Advisory API, then verify that the reported timeout is handled as intended rather than surfacing as an uncaught exception.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- devtools, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100