Skip to content

[Safe Outputs Conformance] USE-001: azure_devops_work_items.cjs missing standardized error codes #61965

Description

@github-actions

Conformance Check Failure

Check ID: USE-001
Severity: LOW
Category: Usability

Problem Description

The conformance checker (scripts/check-safe-outputs-conformance.sh, check check_error_codes) flags actions/setup/js/azure_devops_work_items.cjs as the only safe-output handler in the repository that throws errors without using the standardized error-code taxonomy defined in actions/setup/js/error_codes.cjs (ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM). Every other handler that interacts with octokit/safe-output plumbing (e.g. add_comment.cjs) already imports and prefixes its thrown errors with one of these codes. This handler has 55 throw new Error(...) call sites with plain, unprefixed messages, so operators cannot reliably filter/alert on its failures by error class the way they can for other handlers.

Affected Components

  • Files: actions/setup/js/azure_devops_work_items.cjs
  • Handlers: Azure DevOps work item safe-output handler (ado_create_work_item, ado_update_work_item, attachment/link helpers, URL/org validation, etc.)
🔍 Current vs Expected Behavior

Current Behavior

All 55 throw new Error(...) sites in actions/setup/js/azure_devops_work_items.cjs use plain, unprefixed messages, e.g.:

throw new Error("assignee must not be empty");
throw new Error("AZURE_DEVOPS_ORG_URL is required");
throw new Error(`work item #${id} is not permitted by the target configuration`);

Expected Behavior

Per the Safe Outputs Specification (Section 9.5, Error Code Catalog) and the pattern already followed by other handlers (e.g. actions/setup/js/add_comment.cjs:26,472), errors should be prefixed with a standardized code imported from actions/setup/js/error_codes.cjs:

const { ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_NOT_FOUND, ERR_SYSTEM } = require("./error_codes.cjs");

throw new Error(`${ERR_VALIDATION}: assignee must not be empty`);
throw new Error(`${ERR_CONFIG}: AZURE_DEVOPS_ORG_URL is required`);
throw new Error(`${ERR_VALIDATION}: work item #${id} is not permitted by the target configuration`);

Remediation Steps

This task can be assigned to a Copilot coding agent with the following steps:

  1. Add const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM } = require("./error_codes.cjs"); (only import the codes actually used) near the top of actions/setup/js/azure_devops_work_items.cjs.
  2. Walk through each of the 55 throw new Error(...) call sites and prefix the message with the appropriate error code based on its category:
    • Input/format/limit validation (empty fields, invalid tags, bad URL format, length limits, disallowed values) → ERR_VALIDATION
    • Missing/invalid env vars or configuration (AZURE_DEVOPS_ORG_URL, SYSTEM_TEAMPROJECT, tokens) → ERR_CONFIG
    • Permission/allowlist rejections (assignee not permitted, tag/link-type not permitted) → ERR_PERMISSION
    • Azure DevOps HTTP/API failures (request could not be sent, non-OK status, bad JSON body) → ERR_API
    • Work item / attachment / resource lookup failures (temporary ID not resolved, work item not found) → ERR_NOT_FOUND
    • File/staging I/O errors (attachment read failures, symlink/path escape checks) → ERR_SYSTEM
  3. Keep existing message text after the code prefix (format: `${ERR_CODE}: original message`) so messages stay human-readable.
  4. Re-run the conformance checker to confirm USE-001 passes.

Verification

After remediation, verify the fix by running:

bash scripts/check-safe-outputs-conformance.sh

The check USE-001 should pass without errors.

References

  • Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
  • Conformance Checker: scripts/check-safe-outputs-conformance.sh
  • Error code catalog: actions/setup/js/error_codes.cjs
  • Reference implementation: actions/setup/js/add_comment.cjs
  • Run ID: 35424632696
  • Date: 2026-09-19

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 65.6 AIC · ⌖ 8.34 AIC · ⊞ 7.7K · ◷

  • expires on Sep 19, 2026, 9:47 PM UTC-08:00

Activity

  1. github-actions commented on Sep 20, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #62136

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions