You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure DevOps Pipeline中CodeQL分析任务卡在UnsupportedExternalAPIs.ql步骤

Azure DevOps CodeQL Analyze任务卡在UnsupportedExternalAPIs.ql步骤超时失败

我正在为仓库配置CodeQL检查,让Azure DevOps Pipeline在代码推送到分支时自动运行。但AdvancedSecurity-Codeql-Analyze@1任务始终无法完成,卡在Starting evaluation of codeql/csharp-queries/Telemetry/UnsupportedExternalAPIs.ql.步骤直至超时失败。仓库包含多个基于.NET的项目和解决方案,当前Pipeline的YAML配置如下:

# Advanced Security Dependency Scanning v1 for Whole project

# Scan for open source dependency vulnerabilities in your source code.

trigger:
  branches:
    include:
      - main

pool:
  vmImage: ubuntu-latest

#variables:
  #advancedsecurity.codeql.querysuite: security-extended
  #advancedsecurity.submittoadvancedsecurity: true
  #timeoutInMinutes: 360

steps:
  - task: AdvancedSecurity-Codeql-Init@1
    inputs:
      languages: 'csharp'

  - task: AdvancedSecurity-Codeql-Autobuild@1
    displayName: 'Advanced Security AutoBuild'
  
  - task: AdvancedSecurity-Dependency-Scanning@1
    displayName: 'Advanced Security Dependency scanning'
  
  - task: AdvancedSecurity-Codeql-Analyze@1
    displayName: 'Advanced Security Code Analyze'
    timeoutInMinutes: 360
  
  - task: AdvancedSecurity-Publish@1

已在CodeQL官方仓库提交工单,但尚未收到回复。

可行的解决思路

  • 排除卡顿的特定查询:既然明确卡在UnsupportedExternalAPIs.ql,可以在CodeQL初始化任务中排除该查询。修改AdvancedSecurity-Codeql-Init@1任务参数:

    - task: AdvancedSecurity-Codeql-Init@1
      inputs:
        languages: 'csharp'
        queries: |
          security-extended
          -codeql/csharp-queries/Telemetry/UnsupportedExternalAPIs.ql
    

    如果使用默认查询套件,也可以先指定默认套件再排除目标查询。

  • 切换轻量查询套件:当前注释了security-extended套件,默认可能使用security-default。若该查询属于默认套件,尝试切换到更精简的查询集合,或仅运行核心安全查询:

    variables:
      advancedsecurity.codeql.querysuite: security-default
    

    也可以完全自定义查询列表,只保留必要的安全规则。

  • 优化构建范围:多.NET项目可能导致分析数据量过大,尝试在AutoBuild阶段指定具体要分析的解决方案,避免扫描所有项目:

    - task: AdvancedSecurity-Codeql-Autobuild@1
      displayName: 'Advanced Security AutoBuild'
      inputs:
        solution: '**/YourTargetSolution.sln' # 替换为实际解决方案路径
    

    或者拆分分析任务,分项目单独分析后合并结果。

  • 升级任务或调整资源:检查AdvancedSecurity-Codeql-Analyze@1是否有更新版本;或更换为资源更充足的虚拟机镜像,比如ubuntu-22.04-large,提升分析处理能力:

    pool:
      vmImage: ubuntu-22.04-large
    

内容的提问来源于stack exchange,提问作者Ibrahim Amer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 06:17:24