Skip to content

MSBuild parser skipping tool messages hides important warnings #1512

Description

@KalleOlaviNiemitalo

Jenkins and plugins versions report

Environment
Jenkins: 2.555.1
OS: Windows Server 2025 - 10.0
Java: 25.0.3 - Microsoft (OpenJDK 64-Bit Server VM)
---
Office-365-Connector:5.3.0
analysis-model-api:14.5.0-972.v41833a_663046
ansicolor:536.v13fa_b_860c267
antisamy-markup-formatter:173.v680e3a_b_69ff3
apache-httpcomponents-client-4-api:4.5.14-269.vfa_2321039a_83
apache-httpcomponents-client-5-api:5.6.1-195.v65ffe15189a_d
asm-api:9.9.1-189.vb_5ef2964da_91
atlassian-bitbucket-server-integration:4.2.0
authentication-tokens:1.144.v5ff4a_5ec5c33
authorize-project:2.0.0
azure-ad:667.v4c5827a_e74a_0
azure-sdk:259.vf079c96088a_f
bitbucket-server-checks:1.0-SNAPSHOT (private-7c02c34a-kalle)
bootstrap5-api:5.3.8-1038.vee76a_fe825ff
bouncycastle-api:2.30.1.84-291.v9f17b_21896e2
branch-api:2.1280.v0d4e5b_b_460ef
buildtriggerbadge:343.vb_693d3ceda_44
caffeine-api:3.2.3-194.v31a_b_f7a_b_5a_81
checks-api:402.vca_263b_f200e3
cloudbees-bitbucket-branch-source:937.3.1
cloudbees-disk-usage-simple:256.v20ec4eb_884f1
cloudbees-folder:6.1100.ve9eed61d16c4
command-launcher:134.v025a_5fcf9dea_
commons-collections4-api:4.5.0-8.va_d5448ef9011
commons-compress-api:1.28.0-3
commons-lang3-api:3.20.0-109.ve43756e2d2b_4
commons-text-api:1.15.0-218.va_61573470393
compress-artifacts:112.v52b_808b_85a_e8
configuration-as-code:2077.v41f1011a_5110
copyartifact:795.ve8e151429b_27
coverage:3.3220.v9f7ea_a_7f63b_4
credentials:1502.v5c95e620ddfe
credentials-binding:720.v3f6decef43ea_
csp:2.58.v31cd65258cb_2
customizable-header:295.v2544b_ca_19b_97
dark-theme:652.vea_da_dfea_e769
data-tables-api:2.3.8-1570.v1cb_1cd2a_0fb_c
display-url-api:2.217.va_6b_de84cc74b_
dtkit-api:3.0.3
durable-task:664.v2b_e7a_dfff66c
echarts-api:6.0.0-1287.vfd24c22a_3d00
eddsa-api:0.3.0.1-29.v67e9a_1c969b_b_
extended-read-permission:68.vd270568a_7520
flatpickr-api:4.6.13-32.v60a_51029c136
font-awesome-api:7.2.0-990.vf220b_2a_496f9
forensics-api:4.1891.v5e60f3377506
git:5.10.1
git-client:6.6.0
git-forensics:4.2367.vb_399b_30a_e8fb_
gson-api:2.14.0-201.v8eefe5515533
handy-uri-templates-2-api:2.1.8-38.vcea_5d521d5f3
hudson-wsclean-plugin:1.0.8
instance-identity:203.v15e81a_1b_7a_38
ionicons-api:94.vcc3065403257
jackson-annotations2-api:2.21-7.v4777a_f3a_a_d47
jackson2-api:2.21.2-436.v29efdb_7418ff
jackson3-api:3.1.3-76.vd9b_7cd2e80b_8
jakarta-activation-api:2.1.4-1
jakarta-mail-api:2.1.5-1
jakarta-xml-bind-api:4.0.6-12.vb_1833c1231d3
javax-activation-api:1.2.0-8
javax-mail-api:1.6.2-11
jaxb:2.3.9-143.v5979df3304e6
jdk-tool:83.v417146707a_3d
jersey2-api:2.48-180.ve47b_264f849b_
jira:3.21
job-restrictions:242.v6edda_c9e4ca_f
joda-time-api:2.14.2-193.v422b_efce56e0
jquery3-api:3.7.1-687.v68d468e40b_30
json-api:20251224-185.v0cc18490c62c
json-path-api:3.0.0-218.vcd4dd1355de2
jsoup:1.22.2-95.vc5d00f1eb_42d
junit:1403.vd9d1413fd205
lockable-resources:1515.v380548282a_59
mailer:534.v1b_36f5864073
manage-permission:20.v5e6fa_97fa_0fe
matrix-auth:3.2.10
matrix-project:870.v9db_fcfc2f45b_
metrics:4.2.37-494.v06f9a_939d33a_
mina-sshd-api-common:2.16.0-167.va_269f38cc024
mina-sshd-api-core:2.16.0-167.va_269f38cc024
netty-api:4.2.12.Final-25.v1b_911a_364383
okhttp-api:5.3.2-200.vedb_720a_cf1f8
pipeline-build-step:584.vdb_a_2cc3a_d07a_
pipeline-graph-analysis:254.v0f63a_a_447dca_
pipeline-graph-view:873.v8cb_25b_5e95f4
pipeline-groovy-lib:797.v90ea_a_9b_e45a_0
pipeline-input-step:551.vdff487c5998c
pipeline-milestone-step:152.v6e22b_8cfc66c
pipeline-model-api:2.2277.v00573e73ddf1
pipeline-model-definition:2.2277.v00573e73ddf1
pipeline-model-extensions:2.2277.v00573e73ddf1
pipeline-rest-api:2.41
pipeline-stage-step:345.va_96187909426
pipeline-stage-tags-metadata:2.2277.v00573e73ddf1
pipeline-stage-view:2.41
pipeline-utility-steps:2.20.0
plain-credentials:199.v9f8e1f741799
plugin-util-api:7.1341.v039f146993d9
prism-api:1.30.0-727.vc475481f034d
resource-disposer:0.25
scm-api:728.vc30dcf7a_0df5
script-security:1402.v94c9ce464861
sidebar-link:2.5.0
simple-queue:1.4.13
snakeyaml-api:2.5-149.v72471e9c6371
snakeyaml-engine-api:3.0.1-5.vd98ea_ff3b_92e
ssh-credentials:372.va_250881b_08cd
sshd:3.384.vc89b_5e138cf9
structs:362.va_b_695ef4fdf9
theme-manager:346.v06cca_64c6a_37
timestamper:1.30
token-macro:477.vd4f0dc3cb_cf1
trilead-api:2.284.v1974ea_324382
variant:70.va_d9f17f859e0
warnings-ng:13.10091.vd687e63e8591
woodstox-core-api:7.1.1-1.v4d297985f397
workflow-aggregator:608.v67378e9d3db_1
workflow-api:1413.v2ff1a_5e720fa_
workflow-basic-steps:1098.v808b_fd7f8cf4
workflow-cps:4315.va_e456c4e7f4f
workflow-durable-task-step:1475.ved562f6ec8b_3
workflow-job:1571.1580.v18e46842c125
workflow-multibranch:821.vc3b_4ea_780798
workflow-scm-step:466.va_d69e602552b_
workflow-step-api:724.v538c2362b_dfb_
workflow-support:1015.v785e5a_b_b_8b_22
ws-cleanup:0.49
xunit:3.1.6

What Operating System are you using (both controller, and any agents involved in the problem)?

Windows

Reproduction steps

Build an MSBuild project that uses the Exec task to run NuGet.exe restore on a project that references vulnerable NuGet packages. Use MSBuild command-line options to output the NuGet warnings to a log file in MSBuild format. The log file contains:

EXEC : warning : NU1902: Package 'Microsoft.IdentityModel.JsonWebTokens' 6.11.1 has a known moderate severity vulnerability, https://github.com/advisories/GHSA-59j7-ghrg-fj52 [C:\jenkins\workspace\project\ci.msbuildproj]
EXEC : warning : NU1903: Package 'Microsoft.Owin' 4.2.0 has a known high severity vulnerability, https://github.com/advisories/GHSA-3rq8-h3gj-r5c6 [C:\jenkins\workspace\project\ci.msbuildproj]
EXEC : warning : NU1902: Package 'System.IdentityModel.Tokens.Jwt' 6.11.1 has a known moderate severity vulnerability, https://github.com/advisories/GHSA-59j7-ghrg-fj52 [C:\jenkins\workspace\project\ci.msbuildproj]

In Jenkinsfile, use the recordIssues step to parse the file.

recordIssues(
    tools: [
        msBuild(id: 'msbuild', name: 'MSBuild', pattern: 'MSBuild.log', reportEncoding: 'UTF-8')]);

Expected Results

The NU1902 and NU1903 warnings should show up in the Warnings plugin of Jenkins, so that developers see the vulnerable dependency and can address it.

Actual Results

Jenkins does not show the warnings.

Anything else?

This is caused by #744, which was intended to fix JENKINS-56613 aka #1330. The Java code recognizes the EXEC keyword and discards the warnings, so as not to attempt to read a source file named EXEC.

/**
* Pattern to identify bare tool names that should be ignored (without path separators).
* Only matches tool names when they appear alone, not as part of a path.
*/
private static final Pattern TOOL_NAME_PATTERN = Pattern.compile(
"^(?:EXEC|NMAKE|LINK|MSBUILD|CSC|MSBuild|link|nmake|msbuild|cl|rs)$|"
+ "^[^/\\\\]*\\.exe$|"
+ "^<[^>]+>$",
Pattern.CASE_INSENSITIVE);

/**
* Checks if the given fileName is a known tool name that should be ignored.
* Tool names include executables (e.g., ConsoleTranslator.exe) and bare tool names (e.g., NMAKE, rs).
* This method is conservative and only filters known tool names to avoid false positives.
*
* @param fileName
* the filename to check
*
* @return true if this is a tool name that should be ignored, false otherwise
*/
private boolean isToolName(final String fileName) {
if (StringUtils.isBlank(fileName) || "-".equals(fileName) || "unknown.file".equals(fileName)) {
return true;
}
var baseFileName = FilenameUtils.getName(fileName).trim();
baseFileName = baseFileName.replaceAll("^\\d{1,2}:\\d{2}:\\d{2}\\s+", "");
return TOOL_NAME_PATTERN.matcher(baseFileName).matches();
}

var fileName = determineFileName(matcher);
if (isLinkerParameter(fileName)) {
fileName = "-";
}
// Skip if this is a tool name (executable or tool without proper source extension)
else if (isToolName(fileName)) {
return Optional.empty();
}

I'd like to get these warnings displayed in Jenkins, despite them not carrying a file name. The parser could use "-" as the file name in the Issue object, like it does in the isLinkerParameter(fileName) case. It would be better to prepend the tool name to the message than discard the tool name altogether.

In the sample log above, the [C:\jenkins\workspace\project\ci.msbuildproj] suffix on each warning is not output by NuGet itself; rather, MSBuild appends that to show which MSBuild project used the Exec task to run NuGet. AFAICT, the parser uses that in determineFileName to figure out the base directory for resolving relative paths. In my opinion, the parser should not be changed to use ci.msbuildproj as the file name in the Issue object.

Are you interested in contributing a fix?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    No fields configured for Bug.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions