Skip to content

chore(security): InspectCode noise-floor .DotSettings — structural FPs only (#361) - #383

Merged
Chris-Wolfgang merged 2 commits into
vNextfrom
fix/inspectcode-dotsettings-noisefloor
Aug 14, 2026
Merged

Chris-Wolfgang merged 2 commits into
vNextfrom
fix/inspectcode-dotsettings-noisefloor

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Stacked PR 8 (final) on the Code Scanning cleanup. Base: fix/inspectcode-longtail-cref (PR #380). Closes #361.

What

A ReSharper InspectCode noise-floor .DotSettings limited to structurally-always-FP inspections (12 entries): the RS0016/36/37 PublicAPI trio (InspectCode runs the analyzer without the PublicAPI.*.txt baseline), the 7 nullable-…AccordingToAPIContract rules (defensive base-lib null-checks), UnusedAutoPropertyAccessor.Global (library has external consumers), and MA0158 (Lock is net9+).

Relationship to #378

This supersedes the .DotSettings from the parallel #361 draft (#378). #378's version blanket-suppressed ~45 rules including many that are fixable (RCS1102, S2930, S1939, xUnit1030, Redundant*, unused-variable/dead-field, S4456, S125) and even S2068 (hard-coded credentials — a security rule). Those should not be silenced — they're fixed in code by this vNext stack (#370–#380) or dismissed per instance with a reason (so future genuine occurrences still surface). #378's code changes fully duplicate this stack (same StaticMemberInGenericType holder, S2699, S4487, cref fixes — verified full-matrix here). See the reconciliation comment on #378.

Notes

  • *.sln.DotSettings is not a protected file — no admin-bypass needed.
  • jb inspectcode auto-loads this solution-adjacent file, so the suppressions apply in CI (the pr.yaml InspectCode job) exactly as documented in that workflow's "tune the noise floor via .DotSettings" comment.

🤖 Generated with Claude Code

Chris-Wolfgang and others added 2 commits August 13, 2026 20:41
Re-audit of the dismissed long-tail found this was a real dead-code finding, not
a won't-fix: CapturingExtractor stored intervalMs in _intervalMs but never read
it (ReportingInterval is set from the ctor param directly). Removed the field.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…s only (#361)

Adds a ReSharper InspectCode noise-floor limited to inspections that are
STRUCTURALLY always false-positive for this repo (12 entries):
- RS0016/RS0036/RS0037 — InspectCode runs PublicApiAnalyzers without the
  PublicAPI.*.txt AdditionalFiles; the in-build analyzer emits zero.
- 7 nullable "…AccordingToAPIContract" rules — R# flags the base library's
  deliberate defensive null-checks; intentional for a lib called from
  nullable-oblivious / older-TFM code.
- UnusedAutoPropertyAccessor.Global — R# can't see a library's external consumers.
- MA0158 — System.Threading.Lock is net9.0+; multi-TFM floor requires object locks.

Deliberately EXCLUDES the broader suppression set from the parallel #361 draft
(#378): fixable style/correctness rules (RCS1102, S2930, S1939, xUnit1030,
Redundant*, unused-variable/dead-field, S4456, S125, …) are FIXED in code on the
vNext cleanup stack, location-specific intentional patterns are dismissed per
instance with a reason, and S2068 (hard-coded credentials, a security rule) is
NOT blanket-silenced. See the #378 reconciliation comment.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 14, 2026 13:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Chris-Wolfgang
Chris-Wolfgang changed the base branch from fix/inspectcode-longtail-cref to vNext August 14, 2026 20:27
@Chris-Wolfgang
Chris-Wolfgang merged commit e33d85b into vNext Aug 14, 2026
2 checks passed
@Chris-Wolfgang
Chris-Wolfgang deleted the fix/inspectcode-dotsettings-noisefloor branch August 14, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants