Skip to content

[Safe Outputs Conformance] USE-001: azure_devops_work_items.cjs missing standardized error codes #62320

Description

@github-actions

Conformance Check Failure

Check ID: USE-001
Severity: LOW
Category: Usability

Problem Description

The safe-outputs conformance checker flags actions/setup/js/azure_devops_work_items.cjs for not using the project's standardized error-code prefixes. The handler throws many new Error(...) instances for validation, configuration, network/API, and system failures, but none of the messages are prefixed with a code from actions/setup/js/error_codes.cjs (e.g. ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_SYSTEM). Other safe-output handlers such as create_issue.cjs already follow this convention (e.g. throw new Error(`${ERR_VALIDATION}: ...`)), which enables structured log parsing, monitoring dashboards, and alerting rules across handlers.

Affected Components

  • Files: actions/setup/js/azure_devops_work_items.cjs
  • Reference implementation: actions/setup/js/create_issue.cjs (uses ERR_VALIDATION from actions/setup/js/error_codes.cjs)
  • Error code catalog: actions/setup/js/error_codes.cjs
🔍 Current vs Expected Behavior

Current Behavior

All throw new Error(...) calls in azure_devops_work_items.cjs (over 40 sites, e.g. lines 37, 90-109, 137-157, 168-182, 198-240, 282-358, 399-479, 536) use plain, unprefixed messages such as:

throw new Error("AZURE_DEVOPS_ORG_URL is required");

Expected Behavior

Messages should be prefixed with the appropriate standardized code imported from ./error_codes.cjs, matching the pattern used elsewhere in the codebase:

const { ERR_VALIDATION, ERR_CONFIG, ERR_API, ERR_SYSTEM } = require("./error_codes.cjs");
...
throw new Error(`${ERR_CONFIG}: AZURE_DEVOPS_ORG_URL is required`);

Remediation Steps

This task can be assigned to a Copilot coding agent with the following steps:

  1. Add const { ERR_VALIDATION, ERR_PERMISSION, ERR_API, ERR_CONFIG, ERR_NOT_FOUND, ERR_SYSTEM } = require("./error_codes.cjs"); (only the codes actually used) to the top of actions/setup/js/azure_devops_work_items.cjs.
  2. Walk through each throw new Error(...) / core.setFailed(...) call in the file and prefix the message with the code matching its failure category:
    • Input/format/limit validation (e.g. assignee must not be empty, tags must be an array, title must contain 6 to 255 characters) → ERR_VALIDATION
    • Missing/invalid environment configuration (e.g. AZURE_DEVOPS_ORG_URL is required, SYSTEM_TEAMPROJECT is required) → ERR_CONFIG
    • Outbound HTTP/API request or response failures (e.g. Azure DevOps ... request could not be sent, ... failed with HTTP ..., ... response was not valid JSON) → ERR_API
    • Permission/allowlist denials (e.g. is not permitted by, is blocked by) → ERR_PERMISSION
    • File/attachment I/O failures (e.g. staged attachment could not be read, path traversal/symlink checks) → ERR_SYSTEM
  3. Keep the existing error message text after the code prefix (format: `${CODE}: original message`) so behavior and existing tests that match on message substrings continue to pass — update any test assertions that match on exact (unprefixed) message strings.
  4. Run the handler's unit tests and the conformance checker to confirm the fix.

Verification

After remediation, verify the fix by running:

bash scripts/check-safe-outputs-conformance.sh

The check USE-001 should pass without errors (no [LOW] USE-001 lines in the output).

References

  • Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
  • Conformance Checker: scripts/check-safe-outputs-conformance.sh
  • Run ID: §35565652264
  • Date: 2026-09-21

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 55.8 AIC · ⌖ 8.12 AIC · ⊞ 7.7K · ◷

  • expires on Sep 21, 2026, 9:49 PM UTC-08:00

Activity

  1. github-actions commented on Sep 22, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #62566

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

  2. github-actions commented on Sep 22, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #62567

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

  3. github-actions commented on Sep 22, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #62568

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions