Conformance Check Failure
Check ID: SEC-004
Severity: MEDIUM
Category: Security
Problem Description
The conformance checker flags two safe-output handlers that contain a body field with no detectable sanitization call (sanitize, stripHTML, escapeMarkdown, or cleanContent). Per the Safe Outputs Specification, any handler that writes untrusted or externally-influenced content into a GitHub-facing body field MUST sanitize that content before the API call.
Affected Components
🔍 Current vs Expected Behavior
Current Behavior
exchange_otlp_workload_identity.cjs has no @safe-outputs-exempt SEC-004 annotation, so the checker cannot distinguish its transport-layer body from a GitHub content body.
report_failed_jobs.cjs interpolates job names/URLs and workflow metadata directly into the issue body string via generateFooterWithExpiration without calling a sanitize/escape helper.
Expected Behavior
Per spec (docs/src/content/docs/specs/safe-outputs-specification.md, SEC-004): handlers that construct GitHub-facing body content from any externally-influenced value must either (a) sanitize the content, or (b) carry a documented @safe-outputs-exempt SEC-004 annotation explaining why sanitization does not apply (as done in artifact_client.cjs, allowed_issue_fields.cjs, assign_agent_helpers.cjs, disable_agentic_workflow.cjs).
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
- In
actions/setup/js/exchange_otlp_workload_identity.cjs, add a @safe-outputs-exempt SEC-004 comment near the top of the file (matching the style used in artifact_client.cjs) clarifying that the body: fields are outbound HTTP transport payloads for OAuth/token-exchange calls, not GitHub content.
- In
actions/setup/js/report_failed_jobs.cjs, review whether formatFailedJobsList/template interpolation needs an explicit sanitize/escape call on job names and URLs before they reach issueBody. If job names can only originate from the repository's own trusted workflow definitions (not fork PR content), instead add a @safe-outputs-exempt SEC-004 annotation explaining that trust boundary explicitly.
- Re-run the conformance checker to confirm SEC-004 passes cleanly for both files.
Verification
After remediation, verify the fix by running:
bash scripts/check-safe-outputs-conformance.sh
The check SEC-004 should pass without errors.
References
- Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
- Conformance Checker: scripts/check-safe-outputs-conformance.sh
- Run ID: 30981409805
- Date: 2026-08-05
Generated by ✅ Daily Safe Outputs Conformance Checker · agent · 39.7 AIC · ⌖ 13.7 AIC · ⊞ 6.8K · ◷
Conformance Check Failure
Check ID: SEC-004
Severity: MEDIUM
Category: Security
Problem Description
The conformance checker flags two safe-output handlers that contain a
bodyfield with no detectable sanitization call (sanitize,stripHTML,escapeMarkdown, orcleanContent). Per the Safe Outputs Specification, any handler that writes untrusted or externally-influenced content into a GitHub-facingbodyfield MUST sanitize that content before the API call.Affected Components
actions/setup/js/exchange_otlp_workload_identity.cjs— likely a false positive: its twobody:occurrences (lines 26, 53) are HTTP request payloads (URLSearchParams/JSON.stringify) sent to a workload-identity token exchange endpoint, not GitHub issue/comment/PR content. This is the same shape of false positive already resolved inactions/setup/js/artifact_client.cjsvia a@safe-outputs-exempt SEC-004annotation.actions/setup/js/report_failed_jobs.cjs— genuine case:issueBody(line 181) is built from a template (failed_jobs_issue.md) interpolated withworkflow_name,workflow_source_url,run_url, and a list of failed job names/URLs (formatFailedJobsList). Job names/URLs originate fromgithub.rest.actions.listJobsForWorkflowRun, which for workflows triggered by external/fork PRs could reflect job names defined in a modified workflow file. There is no explicit sanitization call before this content is passed togithub.rest.issues.create.🔍 Current vs Expected Behavior
Current Behavior
exchange_otlp_workload_identity.cjshas no@safe-outputs-exempt SEC-004annotation, so the checker cannot distinguish its transport-layerbodyfrom a GitHub contentbody.report_failed_jobs.cjsinterpolates job names/URLs and workflow metadata directly into the issue body string viagenerateFooterWithExpirationwithout calling a sanitize/escape helper.Expected Behavior
Per spec (docs/src/content/docs/specs/safe-outputs-specification.md, SEC-004): handlers that construct GitHub-facing
bodycontent from any externally-influenced value must either (a) sanitize the content, or (b) carry a documented@safe-outputs-exempt SEC-004annotation explaining why sanitization does not apply (as done inartifact_client.cjs,allowed_issue_fields.cjs,assign_agent_helpers.cjs,disable_agentic_workflow.cjs).Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
actions/setup/js/exchange_otlp_workload_identity.cjs, add a@safe-outputs-exempt SEC-004comment near the top of the file (matching the style used inartifact_client.cjs) clarifying that thebody:fields are outbound HTTP transport payloads for OAuth/token-exchange calls, not GitHub content.actions/setup/js/report_failed_jobs.cjs, review whetherformatFailedJobsList/template interpolation needs an explicit sanitize/escape call on job names and URLs before they reachissueBody. If job names can only originate from the repository's own trusted workflow definitions (not fork PR content), instead add a@safe-outputs-exempt SEC-004annotation explaining that trust boundary explicitly.Verification
After remediation, verify the fix by running:
The check SEC-004 should pass without errors.
References