You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The conformance checker (scripts/check-safe-outputs-conformance.sh, check check_error_codes) flags actions/setup/js/azure_devops_work_items.cjs as the only safe-output handler in the repository that throws errors without using the standardized error-code taxonomy defined in actions/setup/js/error_codes.cjs (ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM). Every other handler that interacts with octokit/safe-output plumbing (e.g. add_comment.cjs) already imports and prefixes its thrown errors with one of these codes. This handler has 55 throw new Error(...) call sites with plain, unprefixed messages, so operators cannot reliably filter/alert on its failures by error class the way they can for other handlers.
All 55 throw new Error(...) sites in actions/setup/js/azure_devops_work_items.cjs use plain, unprefixed messages, e.g.:
thrownewError("assignee must not be empty");thrownewError("AZURE_DEVOPS_ORG_URL is required");thrownewError(`work item #${id} is not permitted by the target configuration`);
Expected Behavior
Per the Safe Outputs Specification (Section 9.5, Error Code Catalog) and the pattern already followed by other handlers (e.g. actions/setup/js/add_comment.cjs:26,472), errors should be prefixed with a standardized code imported from actions/setup/js/error_codes.cjs:
const{ERR_VALIDATION,ERR_CONFIG,ERR_API,ERR_NOT_FOUND,ERR_SYSTEM}=require("./error_codes.cjs");thrownewError(`${ERR_VALIDATION}: assignee must not be empty`);thrownewError(`${ERR_CONFIG}: AZURE_DEVOPS_ORG_URL is required`);thrownewError(`${ERR_VALIDATION}: work item #${id} is not permitted by the target configuration`);
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
Add const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM } = require("./error_codes.cjs"); (only import the codes actually used) near the top of actions/setup/js/azure_devops_work_items.cjs.
Walk through each of the 55 throw new Error(...) call sites and prefix the message with the appropriate error code based on its category:
Input/format/limit validation (empty fields, invalid tags, bad URL format, length limits, disallowed values) → ERR_VALIDATION
Missing/invalid env vars or configuration (AZURE_DEVOPS_ORG_URL, SYSTEM_TEAMPROJECT, tokens) → ERR_CONFIG
Permission/allowlist rejections (assignee not permitted, tag/link-type not permitted) → ERR_PERMISSION
Azure DevOps HTTP/API failures (request could not be sent, non-OK status, bad JSON body) → ERR_API
Work item / attachment / resource lookup failures (temporary ID not resolved, work item not found) → ERR_NOT_FOUND
Conformance Check Failure
Check ID: USE-001
Severity: LOW
Category: Usability
Problem Description
The conformance checker (
scripts/check-safe-outputs-conformance.sh, checkcheck_error_codes) flagsactions/setup/js/azure_devops_work_items.cjsas the only safe-output handler in the repository that throws errors without using the standardized error-code taxonomy defined inactions/setup/js/error_codes.cjs(ERR_VALIDATION,ERR_PERMISSION,ERR_API,ERR_CONFIG,ERR_NOT_FOUND,ERR_PARSE,ERR_SYSTEM). Every other handler that interacts with octokit/safe-output plumbing (e.g.add_comment.cjs) already imports and prefixes its thrown errors with one of these codes. This handler has 55throw new Error(...)call sites with plain, unprefixed messages, so operators cannot reliably filter/alert on its failures by error class the way they can for other handlers.Affected Components
actions/setup/js/azure_devops_work_items.cjsado_create_work_item,ado_update_work_item, attachment/link helpers, URL/org validation, etc.)🔍 Current vs Expected Behavior
Current Behavior
All 55
throw new Error(...)sites inactions/setup/js/azure_devops_work_items.cjsuse plain, unprefixed messages, e.g.:Expected Behavior
Per the Safe Outputs Specification (Section 9.5, Error Code Catalog) and the pattern already followed by other handlers (e.g.
actions/setup/js/add_comment.cjs:26,472), errors should be prefixed with a standardized code imported fromactions/setup/js/error_codes.cjs:Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM } = require("./error_codes.cjs");(only import the codes actually used) near the top ofactions/setup/js/azure_devops_work_items.cjs.throw new Error(...)call sites and prefix the message with the appropriate error code based on its category:ERR_VALIDATIONAZURE_DEVOPS_ORG_URL,SYSTEM_TEAMPROJECT, tokens) →ERR_CONFIGERR_PERMISSIONERR_APIERR_NOT_FOUNDERR_SYSTEM`${ERR_CODE}: original message`) so messages stay human-readable.Verification
After remediation, verify the fix by running:
The check USE-001 should pass without errors.
References
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.