You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The safe-outputs conformance checker flags actions/setup/js/azure_devops_work_items.cjs for not using the project's standardized error-code prefixes. The handler throws many new Error(...) instances for validation, configuration, network/API, and system failures, but none of the messages are prefixed with a code from actions/setup/js/error_codes.cjs (e.g. ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_SYSTEM). Other safe-output handlers such as create_issue.cjs already follow this convention (e.g. throw new Error(`${ERR_VALIDATION}: ...`)), which enables structured log parsing, monitoring dashboards, and alerting rules across handlers.
All throw new Error(...) calls in azure_devops_work_items.cjs (over 40 sites, e.g. lines 37, 90-109, 137-157, 168-182, 198-240, 282-358, 399-479, 536) use plain, unprefixed messages such as:
thrownewError("AZURE_DEVOPS_ORG_URL is required");
Expected Behavior
Messages should be prefixed with the appropriate standardized code imported from ./error_codes.cjs, matching the pattern used elsewhere in the codebase:
const{ERR_VALIDATION,ERR_CONFIG,ERR_API,ERR_SYSTEM}=require("./error_codes.cjs");
...
thrownewError(`${ERR_CONFIG}: AZURE_DEVOPS_ORG_URL is required`);
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
Add const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_SYSTEM } = require("./error_codes.cjs"); (only the codes actually used) to the top of actions/setup/js/azure_devops_work_items.cjs.
Walk through each throw new Error(...) / core.setFailed(...) call in the file and prefix the message with the code matching its failure category:
Input/format/limit validation (e.g. assignee must not be empty, tags must be an array, title must contain 6 to 255 characters) → ERR_VALIDATION
Missing/invalid environment configuration (e.g. AZURE_DEVOPS_ORG_URL is required, SYSTEM_TEAMPROJECT is required) → ERR_CONFIG
Outbound HTTP/API request or response failures (e.g. Azure DevOps ... request could not be sent, ... failed with HTTP ..., ... response was not valid JSON) → ERR_API
Permission/allowlist denials (e.g. is not permitted by, is blocked by) → ERR_PERMISSION
File/attachment I/O failures (e.g. staged attachment could not be read, path traversal/symlink checks) → ERR_SYSTEM
Keep the existing error message text after the code prefix (format: `${CODE}: original message`) so behavior and existing tests that match on message substrings continue to pass — update any test assertions that match on exact (unprefixed) message strings.
Run the handler's unit tests and the conformance checker to confirm the fix.
Verification
After remediation, verify the fix by running:
bash scripts/check-safe-outputs-conformance.sh
The check USE-001 should pass without errors (no [LOW] USE-001 lines in the output).
Conformance Check Failure
Check ID: USE-001
Severity: LOW
Category: Usability
Problem Description
The safe-outputs conformance checker flags
actions/setup/js/azure_devops_work_items.cjsfor not using the project's standardized error-code prefixes. The handler throws manynew Error(...)instances for validation, configuration, network/API, and system failures, but none of the messages are prefixed with a code fromactions/setup/js/error_codes.cjs(e.g.ERR_VALIDATION,ERR_CONFIG,ERR_API,ERR_SYSTEM). Other safe-output handlers such ascreate_issue.cjsalready follow this convention (e.g.throw new Error(`${ERR_VALIDATION}: ...`)), which enables structured log parsing, monitoring dashboards, and alerting rules across handlers.Affected Components
actions/setup/js/azure_devops_work_items.cjsactions/setup/js/create_issue.cjs(usesERR_VALIDATIONfromactions/setup/js/error_codes.cjs)actions/setup/js/error_codes.cjs🔍 Current vs Expected Behavior
Current Behavior
All
throw new Error(...)calls inazure_devops_work_items.cjs(over 40 sites, e.g. lines 37, 90-109, 137-157, 168-182, 198-240, 282-358, 399-479, 536) use plain, unprefixed messages such as:Expected Behavior
Messages should be prefixed with the appropriate standardized code imported from
./error_codes.cjs, matching the pattern used elsewhere in the codebase:Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_SYSTEM } = require("./error_codes.cjs");(only the codes actually used) to the top ofactions/setup/js/azure_devops_work_items.cjs.throw new Error(...)/core.setFailed(...)call in the file and prefix the message with the code matching its failure category:assignee must not be empty,tags must be an array,title must contain 6 to 255 characters) →ERR_VALIDATIONAZURE_DEVOPS_ORG_URL is required,SYSTEM_TEAMPROJECT is required) →ERR_CONFIGAzure DevOps ... request could not be sent,... failed with HTTP ...,... response was not valid JSON) →ERR_APIis not permitted by,is blocked by) →ERR_PERMISSIONstaged attachment could not be read, path traversal/symlink checks) →ERR_SYSTEM`${CODE}: original message`) so behavior and existing tests that match on message substrings continue to pass — update any test assertions that match on exact (unprefixed) message strings.Verification
After remediation, verify the fix by running:
The check USE-001 should pass without errors (no
[LOW] USE-001lines in the output).References
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.