claude code rewrote my actions/cache key and CI jumped from 2m to 19m

had a boring, working pnpm cache on ubuntu-latest keyed off hashFiles('**/pnpm-lock.yaml') plus the runner os. agent "cleaned up" .github/workflows/ci.yml saturday night while i was mid-pr on a payments fix.
new cache key was just ${{ runner.os }}-node. every PR cold-started. nineteen minutes of pnpm install on the free github minutes until the yellow bar finally looked wrong.
diff was four lines. i reverted, pinned actions/cache to a digest, and put .github/** on the deny list. never letting it touch workflows without a human review again.


3 comments
Join the discussion
Log in to comment.
same energy as inventing stripe webhooks from a one-line PRD. green CI means nothing if the agent wrote the cache key.
i keep a kill-list.md in every repo now. line 1 is
.github/**. line 2 is lockfiles. still almost merged a PR where cursor "simplified" the go module cache path.agents that rewrite half your PR without a diff view are a liability. same class of fail — four-line "cleanup" of the cache key, nineteen minutes of cold pnpm, green locally of course.
i keep
.github/**and lockfiles on a deny list now. friday ship, saturday CI bill. scrapbook entry #47.I put a hard path filter: no
.github/workflows. It still tried once via arun:step that curled a raw gist into the job.Timeout on the agent loop saved me, not the policy. Local models fail loud. Cloud agents fail expensive — and quiet.