You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Safe Outputs Conformance] USE-001: azure_devops_work_items.cjs does not use standardized error codes #62136
actions/setup/js/azure_devops_work_items.cjs throws ~40 distinct Error objects (validation failures, HTTP/API failures, malformed responses) but none of them carry a standardized error code prefix. Every other handler that interacts with GitHub/external APIs in actions/setup/js/ uses the shared error_codes.cjs module (ERR_VALIDATION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM, ERR_PERMISSION) or the legacy E001-E010 numeric taxonomy, which lets error messages be machine-parsed for logging, monitoring dashboards, and alerting rules. This handler is an outlier.
Errors are thrown as plain, unprefixed messages, e.g.:
thrownewError("assignee must not be empty");thrownewError(`Azure DevOps ${method} request failed with HTTP ${response.status}${response.statusText}`);thrownewError("work item ID must be a positive safe integer");
Expected Behavior
Errors should be prefixed with a standardized code from error_codes.cjs so they match the pattern other handlers use, e.g.:
const{ERR_VALIDATION,ERR_API,ERR_CONFIG,ERR_PARSE}=require("./error_codes.cjs");thrownewError(`${ERR_VALIDATION}: assignee must not be empty`);thrownewError(`${ERR_API}: Azure DevOps ${method} request failed with HTTP ${response.status}${response.statusText}`);thrownewError(`${ERR_VALIDATION}: work item ID must be a positive safe integer`);
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
In actions/setup/js/azure_devops_work_items.cjs, require("./error_codes.cjs") and destructure the constants it needs (likely ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_PARSE).
Classify each existing throw new Error(...) call site (~40 total, see lines 37-358+) by category:
Prefix each message with the chosen code, e.g. `${ERR_VALIDATION}: assignee must not be empty`, keeping the rest of the message text unchanged so existing tests that match on message substrings still pass.
Run the existing test suite for this handler (e.g. actions/setup/js/azure_devops_work_items.test.cjs if present, otherwise the relevant Go/JS test harness) and update any assertions that match on exact error message text.
Verification
After remediation, verify the fix by running:
bash scripts/check-safe-outputs-conformance.sh
USE-001 should report [PASS] with no LOW-severity mention of azure_devops_work_items.cjs.
Conformance Check Failure
Check ID: USE-001
Severity: LOW
Category: Usability
Problem Description
actions/setup/js/azure_devops_work_items.cjsthrows ~40 distinctErrorobjects (validation failures, HTTP/API failures, malformed responses) but none of them carry a standardized error code prefix. Every other handler that interacts with GitHub/external APIs inactions/setup/js/uses the sharederror_codes.cjsmodule (ERR_VALIDATION,ERR_API,ERR_CONFIG,ERR_NOT_FOUND,ERR_PARSE,ERR_SYSTEM,ERR_PERMISSION) or the legacyE001-E010numeric taxonomy, which lets error messages be machine-parsed for logging, monitoring dashboards, and alerting rules. This handler is an outlier.Affected Components
actions/setup/js/azure_devops_work_items.cjsactions/setup/js/error_codes.cjs(shared error-code constants)🔍 Current vs Expected Behavior
Current Behavior
Errors are thrown as plain, unprefixed messages, e.g.:
Expected Behavior
Errors should be prefixed with a standardized code from
error_codes.cjsso they match the pattern other handlers use, e.g.:Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
actions/setup/js/azure_devops_work_items.cjs,require("./error_codes.cjs")and destructure the constants it needs (likelyERR_VALIDATION,ERR_CONFIG,ERR_API,ERR_PARSE).throw new Error(...)call site (~40 total, see lines 37-358+) by category:ERR_VALIDATIONAZURE_DEVOPS_ORG_URL,SYSTEM_TEAMPROJECT, token requirements) →ERR_CONFIGERR_APIERR_PARSE`${ERR_VALIDATION}: assignee must not be empty`, keeping the rest of the message text unchanged so existing tests that match on message substrings still pass.actions/setup/js/azure_devops_work_items.test.cjsif present, otherwise the relevant Go/JS test harness) and update any assertions that match on exact error message text.Verification
After remediation, verify the fix by running:
USE-001 should report
[PASS]with no LOW-severity mention ofazure_devops_work_items.cjs.References
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.