Description
Five Azure DevOps safe-output configs declare Target any with no parse-time validation of its shape: UpdateWorkItemConfig, CommentOnWorkItemConfig, AssignWorkItemConfig, LinkWorkItemsConfig, UploadWorkItemAttachmentConfig in pkg/workflow/safe_outputs_azure_devops.go (lines 40, 52, 57, 64, 70). Confirmed live: Target is parsed straight from frontmatter and passed through addAzureDevOpsTarget/appendAzureDevOpsTargetConstraint (lines 153, 252) to the generated workflow/runtime script without any Go-side shape check.
Fix
Validate Target at parse time — accept an int, numeric string, or GitHub Actions expression string — and return a typed error for anything else, instead of letting an arbitrary YAML shape flow unchecked into generated output.
Expected Impact
Catches a malformed Azure DevOps work-item target at compile time instead of failing (or silently misbehaving) at workflow runtime.
Suggested Agent
General coding agent — add a shared validator used by all 5 config structs' extraction path.
Estimated Effort
Medium (2-3 hours)
Data Source
DeepReport Intelligence Briefing (2026-10-06, incremental cycle) — sourced from Typist: Go Type Consistency Analysis discussion #66107, live-verified against current pkg/workflow/safe_outputs_azure_devops.go.
Generated by 🔬 Deep Report · claude · agent · 207.7 AIC · ⌖ 7.97 AIC · ⊞ 7.1K · ◷
Description
Five Azure DevOps safe-output configs declare
Target anywith no parse-time validation of its shape:UpdateWorkItemConfig,CommentOnWorkItemConfig,AssignWorkItemConfig,LinkWorkItemsConfig,UploadWorkItemAttachmentConfiginpkg/workflow/safe_outputs_azure_devops.go(lines 40, 52, 57, 64, 70). Confirmed live:Targetis parsed straight from frontmatter and passed throughaddAzureDevOpsTarget/appendAzureDevOpsTargetConstraint(lines 153, 252) to the generated workflow/runtime script without any Go-side shape check.Fix
Validate
Targetat parse time — accept an int, numeric string, or GitHub Actions expression string — and return a typed error for anything else, instead of letting an arbitrary YAML shape flow unchecked into generated output.Expected Impact
Catches a malformed Azure DevOps work-item target at compile time instead of failing (or silently misbehaving) at workflow runtime.
Suggested Agent
General coding agent — add a shared validator used by all 5 config structs' extraction path.
Estimated Effort
Medium (2-3 hours)
Data Source
DeepReport Intelligence Briefing (2026-10-06, incremental cycle) — sourced from Typist: Go Type Consistency Analysis discussion #66107, live-verified against current
pkg/workflow/safe_outputs_azure_devops.go.