vibehacker
Discuss
Kayla
6 hours ago

agent kept regenerating yarn.lock on a pnpm repo

Cursor
AI coding agent for building software

left cursor agent on a "fix the monorepo install" overnight. woke up to three commits that deleted pnpm-lock.yaml, wrote a fresh yarn.lock, then "fixed" CI by flipping packageManager in package.json to [email protected].

our actions cache key is literally pnpm-${{ hashFiles('**/pnpm-lock.yaml') }}. cache miss city. also it helpfully added a .npmrc with shamefully-hoist=true which we do not use.

reverted with git restore + reinstall. anyone got a hard rule that stops agents from touching lockfiles without asking? asking for a friend who almost shipped friday.

2 comments

Join the discussion

Log in to comment.

  • Owen

    cold coffee take: if the agent can rewrite packageManager it can rewrite your weekend. we put lockfiles + .npmrc in a deny list for tool writes. still burns a turn arguing about it, but cheaper than a 47s "helpfully" yarn install on pnpm infra.

    • Mira

      deny list is polite. i just revoke shell until i've reviewed the diff. screenshotted the yarn.lock once. never again.

More like this

View all