Skip to content

fix(di): DI004 — expression-bodied/field-init provider capture, trans… #370

fix(di): DI004 — expression-bodied/field-init provider capture, trans…

fix(di): DI004 — expression-bodied/field-init provider capture, trans… #370

Triggered via push June 21, 2026 09:24
Status Success
Total duration 1m 23s
Artifacts –

ci.yml

on: push
lint (ruff + mypy --strict)
15s
lint (ruff + mypy --strict)
extended codegen fuzz
35s
extended codegen fuzz
golden C# compiles & runs (.NET)
21s
golden C# compiles & runs (.NET)
C# leak extractor (Roslyn) -> OwnIR -> core
35s
C# leak extractor (Roslyn) -> OwnIR -> core
own-check repo scan (github + msbuild) + composite action
42s
own-check repo scan (github + msbuild) + composite action
own-check SARIF -> GitHub code scanning (dog-food)
31s
own-check SARIF -> GitHub code scanning (dog-food)
corpus benchmark (real C# recall + specificity)
1m 19s
corpus benchmark (real C# recall + specificity)
Matrix: tests
Fit to window
Zoom out
Zoom in

Annotations

20 errors and 41 warnings
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L89
IDisposable local 'forLeak' is never disposed (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L77
IDisposable local 'foreachLeak' is never disposed (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L66
IDisposable local 'whileLeak' is never disposed (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L26
IDisposable local 'leak' may not be disposed on every path (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/FlowLocalsSample.cs#L17
IDisposable local 'uad' is used after it is disposed
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L160
singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L157
singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L149
singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext)
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L89
[OWN001] IDisposable local 'forLeak' is never disposed (leak) [resource: disposable]
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L77
[OWN001] IDisposable local 'foreachLeak' is never disposed (leak) [resource: disposable]
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L66
[OWN001] IDisposable local 'whileLeak' is never disposed (leak) [resource: disposable]
OWN003: frontend/roslyn/samples/FlowLocalsSample.cs#L36
[OWN003] IDisposable local 'dbl' is disposed more than once [resource: disposable]
OWN001: frontend/roslyn/samples/FlowLocalsSample.cs#L26
[OWN001] IDisposable local 'leak' may not be disposed on every path (leak) [resource: disposable]
OWN002: frontend/roslyn/samples/FlowLocalsSample.cs#L17
[OWN002] IDisposable local 'uad' is used after it is disposed [resource: disposable]
OWN001: frontend/roslyn/samples/DisposableFieldViewModel.cs#L10
[OWN001] IDisposable field '_cts' (type 'CancellationTokenSource') is never disposed — its owner 'ReportViewModel' leaks it (leak) [resource: disposable field]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L160
[DI001] singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext) [resource: DI lifetime]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L157
[DI001] singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo) [resource: DI lifetime]
DI001: frontend/roslyn/samples/DiCaptiveSample.cs#L149
[DI001] singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext) [resource: DI lifetime]
tests (py3.13)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
tests (py3.11)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
tests (py3.12)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
lint (ruff + mypy --strict)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
golden C# compiles & runs (.NET)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check SARIF -> GitHub code scanning (dog-food)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check SARIF -> GitHub code scanning (dog-food): frontend/roslyn/OwnSharp.Extractor/Program.cs#L1259
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
C# leak extractor (Roslyn) -> OwnIR -> core
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
C# leak extractor (Roslyn) -> OwnIR -> core: frontend/roslyn/OwnSharp.Extractor/Program.cs#L1259
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
extended codegen fuzz
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L201
singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L192
singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L182
singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L179
singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L173
singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L160
singleton 'PrimaryCtorService' captures scoped service 'AppDbContext' (captive dependency: PrimaryCtorService -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L157
singleton 'CacheService' captures scoped service 'IRepo' (captive dependency: CacheService -> IRepo)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L149
singleton 'EmailSender' captures scoped service 'AppDbContext' (captive dependency: EmailSender -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/LambdaHandlerViewModel.cs#L21
event 'bus.CustomerChanged' is subscribed (handler '(s, e) => _count++') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'LambdaHandlerViewModel' alive (possible leak — and being an inline lambda it has no '-=' handle, so it could never be detached)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/ExternalRefSubscription.cs#L20
event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L205
singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L201
singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L192
singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L182
singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L179
singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/DiCaptiveSample.cs#L173
singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/CustomerViewModel.cs#L15
event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak)
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak)
OWN001: frontend/roslyn/samples/ExternalRefSubscription.cs#L20
[OWN001] event '_bus.Changed' is subscribed (handler 'OnChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'ExternalRefSubscription' alive (possible leak) [resource: subscription token]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L205
[DI004] singleton 'WrapperResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (WrapperResolver -> MidConnection -> PooledConnection) [resource: DI lifetime]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L201
[DI004] singleton 'ExprBodiedResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ExprBodiedResolver -> PooledConnection) [resource: DI lifetime]
DI004: frontend/roslyn/samples/DiCaptiveSample.cs#L192
[DI004] singleton 'ConnectionResolver' resolves transient IDisposable 'PooledConnection' by hand from its injected root IServiceProvider (GetService/GetRequiredService — the service-locator anti-pattern): the root provider tracks every IDisposable it resolves and frees them only at application shutdown, so each call leaks a transient that should be scope-lived — resolve it from an IServiceScope instead (ConnectionResolver -> PooledConnection) [resource: DI lifetime]
DI002: frontend/roslyn/samples/DiCaptiveSample.cs#L182
[DI002] singleton 'WeakCacheOpt' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCacheOpt -> AppDbContext) [resource: DI lifetime]
DI002: frontend/roslyn/samples/DiCaptiveSample.cs#L179
[DI002] singleton 'WeakCache' weakly captures scoped service 'AppDbContext' (WeakReference): 'AppDbContext' is still resolved from the root provider and promoted to application lifetime — the weak reference avoids pinning it for the GC but does not fix the captive-dependency lifetime violation (WeakCache -> AppDbContext) [resource: DI lifetime]
DI003: frontend/roslyn/samples/DiCaptiveSample.cs#L173
[DI003] singleton 'ConnectionWarmer' captures transient IDisposable 'PooledConnection': it is promoted to application lifetime and disposed only when the root provider is disposed (ConnectionWarmer -> PooledConnection) [resource: DI lifetime]
OWN001: frontend/roslyn/samples/CustomerViewModel.cs#L15
[OWN001] event 'bus.CustomerChanged' is subscribed (handler 'OnCustomerChanged') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'CustomerViewModel' alive (possible leak) [resource: subscription token]
OWN001: frontend/roslyn/samples/AliasedSourceViewModel.cs#L23
[OWN001] event 'src.CustomerChanged' is subscribed (handler 'OnAliased') but never unsubscribed; its source is an injected dependency whose lifetime is unknown, so it may outlive and keep 'AliasedSourceViewModel' alive (possible leak) [resource: subscription token]
own-check repo scan (github + msbuild) + composite action: frontend/roslyn/OwnSharp.Extractor/Program.cs#L1259
Argument of type 'IEnumerable<string?>' cannot be used for parameter 'collection' of type 'IEnumerable<string>' in 'HashSet<string>.HashSet(IEnumerable<string> collection, IEqualityComparer<string>? comparer)' due to differences in the nullability of reference types.
corpus benchmark (real C# recall + specificity)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-dotnet@v4, actions/setup-python@v5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/