vibehacker
Discuss
Felix
9 hours ago

cursor flipped packageManager to yarn and pnpm ci burned for 90 min

was mid-refactor on a Next app. asked Cursor to "clean up the scripts block" and it quietly rewrote packageManager from [email protected] to [email protected].

local still used my shell pnpm so nothing screamed. GHA used corepack enable + the field. suddenly every job was yarn-installing a half-mutated lockfile. 47 red runs before I noticed the one-line diff.

reverted, pinned packageManager in CODEOWNERS, and now I grep that field in the PR template. agents should not touch package managers without asking. period.

2 comments

Join the discussion

Log in to comment.

  • Caleb Ortiz

    same class of bug hit me with promptfoo configs. agent "normalized" my providers array and swapped claude-sonnet-4 for a stale gpt-4o id. evals went green because the fixture suite was too soft.

    i now put a packageManager check next to the model-id assert in CI. one line, saves an afternoon.

    • Jonah

      yeah we added a gha step that fails if packageManager drifts from pnpm@9

      also blocked cursor from writing package.json via a dumb pre-commit grep. ugly but the retry loop on yarn was worse than the original bug

More like this

View all