cursor agent swapped pnpm@9 for [email protected] and GHA burned 38 min
asked Cursor (composer, claude-4.5-sonnet) to "resolve the lockfile conflict" on a monorepo PR. it rewrote packageManager in package.json from [email protected] to [email protected], deleted pnpm-lock.yaml, and left a half-written yarn.lock.
ci on ubuntu-latest did a cold yarn install. 38 minutes. Activity Monitor on my M2 still showed the local pnpm store humming along, so of course it "worked on my machine." cancelled the run after the Actions bill jumped ~$2.40.
now I have package.json and pnpm-lock.yaml on a CODEOWNERS deny for agents. has anyone else seen composer treat packageManager like a suggestion instead of a contract?

4 comments
Join the discussion
Log in to comment.
yeah. we started treating
packageManagerlike a schema file after the third time an agent "helpfully" swapped it.our rule now: agent can touch source and tests. lockfiles + packageManager + engines stay human-only, and CI fails loud if the field drifts from the committed value. the 38 min cold install is the expensive lesson; the silent yarn.lock stub is the scary one.
same failure mode hit us on a Prisma schema last month. agent "fixed" a migrate conflict by rewriting
schema.prismaand regenerating client — local Next build passed, staging GraphQL gateway started returning null on three fields.we added a CI check that diffs
packageManager, lockfiles, andprisma/schema.prismaagainst main and fails if an agent PR touches them without a[human]label. still nervous every rainy pair session though.ha the
[human]label trick is good. we tried a soft warn first and people just ignored it on friday merges.now the check fails hard if
packageManagerorpnpm-lock.yamldrifts without that label. cost me one merge delay last week. cheaper than a 38 min yarn spiral on ubuntu-latest thoughwe caught the same thing when composer "fixed" a lockfile merge on a turborepo.
ci said pnpm store miss for 22 min before i noticed
packageManagerhad flipped to yarn. now it's in the same CODEOWNERS bucket as.github/**— agent PRs that touch it need a human label or the check fails.does cursor even surface the packageManager diff in the apply preview? mine buried it under a 400-line lockfile chunk.