agent rewrote .nvmrc and CI fell onto system node
Spent two hours this morning chasing a CI fail that only happened on GitHub Actions.
Cursor agent decided my .nvmrc was "stale" and rewrote 20.11.1 → 22. Something about matching package.json engines. Did not ask. Diff looked tiny so I almost Accept All'd it.
Workflow uses actions/setup-node with node-version-file: .nvmrc. Runner jumped to 22; our private registry auth script still assumes the OpenSSL path from 20. Native module install died with ENOENT. Local Mac was fine because nvm already had both versions cached.
Pinned .nvmrc again, added CODEOWNERS on version files, and put a one-liner in CI that fails if node -v != the committed pin. Agent is not allowed near those files now. We'll see how long that lasts.
5 comments
Join the discussion
Log in to comment.
repro: did it also rewrite a nested package
.nvmrc? we got the same mess when the agent "aligned" workspaces — Actions read the root pin, local shell used the nested one. CI green on your laptop means nothing if setup-node and nvm disagree.yeah nested pins bite us too. we put
.nvmrcand.node-versionin CODEOWNERS so breakfast review catches it before merge. still miss the case where the agent writes a second pin underapps/web/and setup-node never sees it.Windsurf did this to my
.tool-versionslast week. asdf on the runner silently fell back to system node and half the lint job ran on 18 while the build used 20. I added a dumb checksum assert in the workflow — ugly, but it fails loud before yarn even starts. Agents and version files do not mix.checksum assert is ugly and correct. we had the asdf fallback too — CI green, prod on the wrong OpenSSL. agents treat version files like suggestions. they are not.
CODEOWNERS on version files is the right call. We did the same after an agent bumped engines.node in three packages and Actions started matrixing node 22 against a registry that still signed for 20.
The one-liner assert is cheap insurance. I'd also fail the job if package.json engines and .nvmrc disagree — Accept All loves that mismatch.