Skip to content

[Safe Outputs Conformance] USE-001: azure_devops_work_items.cjs does not use standardized error codes #62136

Description

@github-actions

Conformance Check Failure

Check ID: USE-001
Severity: LOW
Category: Usability

Problem Description

actions/setup/js/azure_devops_work_items.cjs throws ~40 distinct Error objects (validation failures, HTTP/API failures, malformed responses) but none of them carry a standardized error code prefix. Every other handler that interacts with GitHub/external APIs in actions/setup/js/ uses the shared error_codes.cjs module (ERR_VALIDATION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_PARSE, ERR_SYSTEM, ERR_PERMISSION) or the legacy E001-E010 numeric taxonomy, which lets error messages be machine-parsed for logging, monitoring dashboards, and alerting rules. This handler is an outlier.

Affected Components

  • Files: actions/setup/js/azure_devops_work_items.cjs
  • Reference implementation: actions/setup/js/error_codes.cjs (shared error-code constants)
🔍 Current vs Expected Behavior

Current Behavior

Errors are thrown as plain, unprefixed messages, e.g.:

throw new Error("assignee must not be empty");
throw new Error(`Azure DevOps ${method} request failed with HTTP ${response.status} ${response.statusText}`);
throw new Error("work item ID must be a positive safe integer");

Expected Behavior

Errors should be prefixed with a standardized code from error_codes.cjs so they match the pattern other handlers use, e.g.:

const { ERR_VALIDATION, ERR_API, ERR_CONFIG, ERR_PARSE } = require("./error_codes.cjs");

throw new Error(`${ERR_VALIDATION}: assignee must not be empty`);
throw new Error(`${ERR_API}: Azure DevOps ${method} request failed with HTTP ${response.status} ${response.statusText}`);
throw new Error(`${ERR_VALIDATION}: work item ID must be a positive safe integer`);

Remediation Steps

This task can be assigned to a Copilot coding agent with the following steps:

  1. In actions/setup/js/azure_devops_work_items.cjs, require("./error_codes.cjs") and destructure the constants it needs (likely ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_PARSE).
  2. Classify each existing throw new Error(...) call site (~40 total, see lines 37-358+) by category:
    • Input/field validation (assignee, tags, title, description, field references, target checks) → ERR_VALIDATION
    • Environment/config checks (AZURE_DEVOPS_ORG_URL, SYSTEM_TEAMPROJECT, token requirements) → ERR_CONFIG
    • HTTP request/response failures (network errors, non-2xx status, redirect rejection) → ERR_API
    • Response body / JSON parsing failures → ERR_PARSE
  3. Prefix each message with the chosen code, e.g. `${ERR_VALIDATION}: assignee must not be empty`, keeping the rest of the message text unchanged so existing tests that match on message substrings still pass.
  4. Run the existing test suite for this handler (e.g. actions/setup/js/azure_devops_work_items.test.cjs if present, otherwise the relevant Go/JS test harness) and update any assertions that match on exact error message text.

Verification

After remediation, verify the fix by running:

bash scripts/check-safe-outputs-conformance.sh

USE-001 should report [PASS] with no LOW-severity mention of azure_devops_work_items.cjs.

References

  • Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
  • Conformance Checker: scripts/check-safe-outputs-conformance.sh (USE-001 check, ~line 201)
  • Error code reference module: actions/setup/js/error_codes.cjs
  • Run ID: §35492320605
  • Date: 2026-09-20

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 59.8 AIC · ⌖ 8.58 AIC · ⊞ 7.7K · ◷

  • expires on Sep 20, 2026, 9:47 PM UTC-08:00

Activity

  1. github-actions commented on Sep 21, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #62320

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions