Conformance Check Failure
Check ID: USE-001
Severity: LOW
Category: Usability
Problem Description
USE-001 (Error Code Standardization) requires safe-output handlers that throw errors or call core.setFailed to use the standardized error code catalog (E001–E010) documented in Section 9.5 of the specification. actions/setup/js/azure_devops_work_items.cjs throws numerous plain new Error("...") instances (assignee/tag/field validation, URL validation, HTTP failures, ID/target validation) but none of them carry an E0NN code, ERROR_ prefix, or ERR_ prefix. Every other checked handler in actions/setup/js/*.cjs that throws errors already follows this convention (e.g. add_comment.cjs, add_labels.cjs, add_reaction.cjs).
Affected Components
- Files:
actions/setup/js/azure_devops_work_items.cjs
🔍 Current vs Expected Behavior
Current Behavior
Errors are thrown as plain Error objects with human-readable messages only, e.g.:
throw new Error("assignee must not be empty");
throw new Error(`AZURE_DEVOPS_ORG_URL must be a valid HTTPS URL`);
throw new Error(`Azure DevOps ${method} request failed with HTTP ${response.status} ${response.statusText}`);
There is no machine-readable code attached, so callers/log processors cannot programmatically distinguish error categories the way they can for other handlers.
Expected Behavior
Per spec Section 9.5, thrown errors should map to the closest applicable code from the catalog (e.g. E001 INVALID_SCHEMA for input validation failures such as empty assignee/invalid tags/invalid URL shape, E007 API_ERROR for failed/non-JSON Azure DevOps HTTP responses, E005 MISSING_PARENT for unresolved temporary work-item IDs). Since this handler talks to Azure DevOps rather than GitHub, exact code reuse may need light adaptation, but the message format should at minimum carry a recognizable E0NN/ERROR_/ERR_ marker consistent with the rest of the codebase.
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
- Review the standardized error code table in
docs/src/content/docs/specs/safe-outputs-specification.md Section 9.5 and the error-formatting convention already used in actions/setup/js/add_comment.cjs / actions/setup/js/add_labels.cjs.
- Update
actions/setup/js/azure_devops_work_items.cjs so each throw new Error(...) call includes a matching error code prefix (e.g. throw new Error("E001 INVALID_SCHEMA: assignee must not be empty") or the object/wrapper form used elsewhere in the codebase — match whichever convention the sibling handlers use).
- Update or add unit tests in
actions/setup/js/azure_devops_work_items.test.cjs to assert the error codes are present on the relevant thrown errors.
Verification
After remediation, verify the fix by running:
bash scripts/check-safe-outputs-conformance.sh
The check USE-001 should pass without errors.
References
- Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
- Conformance Checker: scripts/check-safe-outputs-conformance.sh
- Run ID: 36099803519
- Date: 2026-09-25
Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 94 AIC · ⌖ 8.19 AIC · ⊞ 7.7K · ◷
Conformance Check Failure
Check ID: USE-001
Severity: LOW
Category: Usability
Problem Description
USE-001 (Error Code Standardization) requires safe-output handlers that throw errors or call
core.setFailedto use the standardized error code catalog (E001–E010) documented in Section 9.5 of the specification.actions/setup/js/azure_devops_work_items.cjsthrows numerous plainnew Error("...")instances (assignee/tag/field validation, URL validation, HTTP failures, ID/target validation) but none of them carry anE0NNcode,ERROR_prefix, orERR_prefix. Every other checked handler inactions/setup/js/*.cjsthat throws errors already follows this convention (e.g.add_comment.cjs,add_labels.cjs,add_reaction.cjs).Affected Components
actions/setup/js/azure_devops_work_items.cjs🔍 Current vs Expected Behavior
Current Behavior
Errors are thrown as plain
Errorobjects with human-readable messages only, e.g.:There is no machine-readable code attached, so callers/log processors cannot programmatically distinguish error categories the way they can for other handlers.
Expected Behavior
Per spec Section 9.5, thrown errors should map to the closest applicable code from the catalog (e.g.
E001 INVALID_SCHEMAfor input validation failures such as empty assignee/invalid tags/invalid URL shape,E007 API_ERRORfor failed/non-JSON Azure DevOps HTTP responses,E005 MISSING_PARENTfor unresolved temporary work-item IDs). Since this handler talks to Azure DevOps rather than GitHub, exact code reuse may need light adaptation, but the message format should at minimum carry a recognizableE0NN/ERROR_/ERR_marker consistent with the rest of the codebase.Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
docs/src/content/docs/specs/safe-outputs-specification.mdSection 9.5 and the error-formatting convention already used inactions/setup/js/add_comment.cjs/actions/setup/js/add_labels.cjs.actions/setup/js/azure_devops_work_items.cjsso eachthrow new Error(...)call includes a matching error code prefix (e.g.throw new Error("E001 INVALID_SCHEMA: assignee must not be empty")or the object/wrapper form used elsewhere in the codebase — match whichever convention the sibling handlers use).actions/setup/js/azure_devops_work_items.test.cjsto assert the error codes are present on the relevant thrown errors.Verification
After remediation, verify the fix by running:
The check USE-001 should pass without errors.
References