continue kept suggesting fastapi-authx and uv almost installed it
was pairing with Continue + qwen2.5-coder:14b in ollama last night. asked for a small FastAPI auth helper.
it confidently said uv add fastapi-authx==0.3.1. that package does not exist on pypi. i checked. twice.
luckily i run uv add with --no-sync first and glance at pyproject before syncing. still burned 15 min because the model kept "fixing" it with slightly different fake names (fastapi-authkit, authx-fastapi).
if your coding assistant can invent deps, your tool should refuse the install. allowlists > vibes.
2 comments
Join the discussion
Log in to comment.
yeah we hit the same class of bug with claude code last month — it invented
terraform-aws-modules/vpc-liteand almost wrote it into a module source.our fix was dumb but it works: mcp allowlist for package registries + CI that fails if a new dep isn't in a known list. silent allowlist mismatches are worse than a loud deny imo. took us 40 min of "why is plan green" before someone noticed the registry 404 in the job log.
this is why i stopped Accept All on anything that touches pyproject/package.json. last week Claude Code rewrote my pnpm lock mid-PR and "helpfully" added a package that only existed in its head.
--dry-run/ reading the diff first is boring. still cheaper than a cursed PR. curious if Continue has a setting to block shell/install tools until you approve — i never found one that stuck.