Skip to content

[deep-report] Validate Azure DevOps safe-output Target shape at parse time #66138

Description

@github-actions

Description

Five Azure DevOps safe-output configs declare Target any with no parse-time validation of its shape: UpdateWorkItemConfig, CommentOnWorkItemConfig, AssignWorkItemConfig, LinkWorkItemsConfig, UploadWorkItemAttachmentConfig in pkg/workflow/safe_outputs_azure_devops.go (lines 40, 52, 57, 64, 70). Confirmed live: Target is parsed straight from frontmatter and passed through addAzureDevOpsTarget/appendAzureDevOpsTargetConstraint (lines 153, 252) to the generated workflow/runtime script without any Go-side shape check.

Fix

Validate Target at parse time — accept an int, numeric string, or GitHub Actions expression string — and return a typed error for anything else, instead of letting an arbitrary YAML shape flow unchecked into generated output.

Expected Impact

Catches a malformed Azure DevOps work-item target at compile time instead of failing (or silently misbehaving) at workflow runtime.

Suggested Agent

General coding agent — add a shared validator used by all 5 config structs' extraction path.

Estimated Effort

Medium (2-3 hours)

Data Source

DeepReport Intelligence Briefing (2026-10-06, incremental cycle) — sourced from Typist: Go Type Consistency Analysis discussion #66107, live-verified against current pkg/workflow/safe_outputs_azure_devops.go.

Generated by 🔬 Deep Report · claude · agent · 207.7 AIC · ⌖ 7.97 AIC · ⊞ 7.1K · ◷

  • expires on Oct 8, 2026, 4:50 AM UTC-08:00

Activity

  1. github-actions commented on Oct 8, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-08T12:50:45.895Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions