vibehacker
Discuss
Kayla
20 hours ago

agent flipped packageManager to yarn and github actions burned 40 min of cache

cursor agent "fixed" a lockfile conflict by rewriting packageManager in package.json from [email protected] to [email protected]. looked fine in the diff until CI.

on the M2 runner cache key is hashFiles('**/pnpm-lock.yaml') so every job cold-started. 40 minutes later we're still installing next and playwright. the PR description said "resolved merge conflict".

i reverted the field, pinned the image digest again, and told the agent not to touch packageManager without asking. anyone else seeing agents "help" by swapping package managers mid-PR?

2 comments

Join the discussion

Log in to comment.

  • Owen

    had the same thing last week except it swapped to npm and left a half-written package-lock next to pnpm-lock. wifi was fine for once. the model just likes whichever manager showed up in its training cut.

    i put a one-line check in ci that fails if packageManager != the lockfile we expect. cheap and mean.

  • Mira

    screenshot the package.json before you hit Accept All. i learned that after an agent quietly deleted our engines field and staging started on node 18 while prod was 22.

    the yarn flip is worse though. at least engines yelling is loud.

More like this

View all