Azure DevOps Pipeline中CodeQL分析任务卡在UnsupportedExternalAPIs.ql步骤
我正在为仓库配置CodeQL检查,让Azure DevOps Pipeline在代码推送到分支时自动运行。但AdvancedSecurity-Codeql-Analyze@1任务始终无法完成,卡在Starting evaluation of codeql/csharp-queries/Telemetry/UnsupportedExternalAPIs.ql.步骤直至超时失败。仓库包含多个基于.NET的项目和解决方案,当前Pipeline的YAML配置如下:
# Advanced Security Dependency Scanning v1 for Whole project # Scan for open source dependency vulnerabilities in your source code. trigger: branches: include: - main pool: vmImage: ubuntu-latest #variables: #advancedsecurity.codeql.querysuite: security-extended #advancedsecurity.submittoadvancedsecurity: true #timeoutInMinutes: 360 steps: - task: AdvancedSecurity-Codeql-Init@1 inputs: languages: 'csharp' - task: AdvancedSecurity-Codeql-Autobuild@1 displayName: 'Advanced Security AutoBuild' - task: AdvancedSecurity-Dependency-Scanning@1 displayName: 'Advanced Security Dependency scanning' - task: AdvancedSecurity-Codeql-Analyze@1 displayName: 'Advanced Security Code Analyze' timeoutInMinutes: 360 - task: AdvancedSecurity-Publish@1
已在CodeQL官方仓库提交工单,但尚未收到回复。
可行的解决思路
排除卡顿的特定查询:既然明确卡在
UnsupportedExternalAPIs.ql,可以在CodeQL初始化任务中排除该查询。修改AdvancedSecurity-Codeql-Init@1任务参数:- task: AdvancedSecurity-Codeql-Init@1 inputs: languages: 'csharp' queries: | security-extended -codeql/csharp-queries/Telemetry/UnsupportedExternalAPIs.ql如果使用默认查询套件,也可以先指定默认套件再排除目标查询。
切换轻量查询套件:当前注释了
security-extended套件,默认可能使用security-default。若该查询属于默认套件,尝试切换到更精简的查询集合,或仅运行核心安全查询:variables: advancedsecurity.codeql.querysuite: security-default也可以完全自定义查询列表,只保留必要的安全规则。
优化构建范围:多.NET项目可能导致分析数据量过大,尝试在AutoBuild阶段指定具体要分析的解决方案,避免扫描所有项目:
- task: AdvancedSecurity-Codeql-Autobuild@1 displayName: 'Advanced Security AutoBuild' inputs: solution: '**/YourTargetSolution.sln' # 替换为实际解决方案路径或者拆分分析任务,分项目单独分析后合并结果。
升级任务或调整资源:检查
AdvancedSecurity-Codeql-Analyze@1是否有更新版本;或更换为资源更充足的虚拟机镜像,比如ubuntu-22.04-large,提升分析处理能力:pool: vmImage: ubuntu-22.04-large
内容的提问来源于stack exchange,提问作者Ibrahim Amer

