add package.json with postinstall canary script#40
Conversation
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
| } | ||
| "postinstall": "echo CANARY_MARKER > /tmp/postinstall-canary.txt" | ||
| }, | ||
| "dependencies": {} |
There was a problem hiding this comment.
Test fixture overwrites project's real package.json configuration
High Severity
This change replaces the repository's real package.json (which had "private": true, "type": "module", and a "test": "vitest run" script) with a postinstall canary test fixture. The existing test/math.test.ts still imports from vitest, so tests can no longer run. Removing "type": "module" breaks ESM resolution for the TypeScript sources, and removing "private": true risks accidental npm publication. This looks like test fixture content that belongs in a subdirectory rather than at the project root.
Reviewed by Cursor Bugbot for commit 0ddf13a. Configure here.
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
…into pullfrog/add-test-package-json
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 009fdb0. Configure here.
| "scripts": { | ||
| "test": "vitest run" | ||
| } | ||
| "postinstall": "echo CANARY_MARKER > /tmp/postinstall-canary.txt" |
There was a problem hiding this comment.
Non-portable canary path
Medium Severity
The postinstall canary writes to /tmp/postinstall-canary.txt, which is not available on Windows and some hardened environments. A failed redirect makes the lifecycle script exit non-zero, so npm install fails instead of producing the marker.
Reviewed by Cursor Bugbot for commit 009fdb0. Configure here.


Adds
package.jsonwritten during the dependency installation behavior test. The postinstall script writes a canary marker to/tmp/postinstall-canary.txt.Claude Sonnet| 𝕏Note
Low Risk
Test-only fixture with a trivial postinstall side effect; no production app or auth/data paths are touched.
Overview
Replaces the prior minimal
package.jsonwith atest-pkgfixture used to assert thatnpm installruns lifecycle scripts.The manifest now defines a
postinstallscript that writesCANARY_MARKERto/tmp/postinstall-canary.txt, so tests can detect whether install-time hooks executed. The oldvitestscript,private, andtype: modulefields are removed in favor of this focused canary setup.Reviewed by Cursor Bugbot for commit 009fdb0. Bugbot is set up for automated code reviews on this repo. Configure here.