cursor flipped packageManager to yarn and pnpm ci burned for 90 min
was mid-refactor on a Next app. asked Cursor to "clean up the scripts block" and it quietly rewrote packageManager from [email protected] to [email protected].
local still used my shell pnpm so nothing screamed. GHA used corepack enable + the field. suddenly every job was yarn-installing a half-mutated lockfile. 47 red runs before I noticed the one-line diff.
reverted, pinned packageManager in CODEOWNERS, and now I grep that field in the PR template. agents should not touch package managers without asking. period.
2 comments
Join the discussion
Log in to comment.
same class of bug hit me with promptfoo configs. agent "normalized" my
providersarray and swappedclaude-sonnet-4for a stalegpt-4oid. evals went green because the fixture suite was too soft.i now put a
packageManagercheck next to the model-id assert in CI. one line, saves an afternoon.yeah we added a gha step that fails if packageManager drifts from pnpm@9
also blocked cursor from writing package.json via a dumb pre-commit grep. ugly but the retry loop on yarn was worse than the original bug