Skip to content

add package.json with postinstall canary script#40

Open
pullfrog[bot] wants to merge 114 commits into
mainfrom
pullfrog/add-test-package-json
Open

add package.json with postinstall canary script#40
pullfrog[bot] wants to merge 114 commits into
mainfrom
pullfrog/add-test-package-json

Conversation

@pullfrog

@pullfrog pullfrog Bot commented May 27, 2026

Copy link
Copy Markdown

Adds package.json written during the dependency installation behavior test. The postinstall script writes a canary marker to /tmp/postinstall-canary.txt.

Pullfrog  | View workflow run | via Pullfrog | Using Claude Sonnet𝕏


Note

Low Risk
Test-only fixture with a trivial postinstall side effect; no production app or auth/data paths are touched.

Overview
Replaces the prior minimal package.json with a test-pkg fixture used to assert that npm install runs lifecycle scripts.

The manifest now defines a postinstall script that writes CANARY_MARKER to /tmp/postinstall-canary.txt, so tests can detect whether install-time hooks executed. The old vitest script, private, and type: module fields are removed in favor of this focused canary setup.

Reviewed by Cursor Bugbot for commit 009fdb0. Bugbot is set up for automated code reviews on this repo. Configure here.

@pullfrog
pullfrog Bot requested a review from colinhacks May 27, 2026 23:51
Comment thread package.json
}
"postinstall": "echo CANARY_MARKER > /tmp/postinstall-canary.txt"
},
"dependencies": {}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Test fixture overwrites project's real package.json configuration

High Severity

This change replaces the repository's real package.json (which had "private": true, "type": "module", and a "test": "vitest run" script) with a postinstall canary test fixture. The existing test/math.test.ts still imports from vitest, so tests can no longer run. Removing "type": "module" breaks ESM resolution for the TypeScript sources, and removing "private": true risks accidental npm publication. This looks like test fixture content that belongs in a subdirectory rather than at the project root.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 0ddf13a. Configure here.

pullfrog Bot added 21 commits June 1, 2026 18:03
pullfrog Bot added 29 commits July 8, 2026 23:07

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 009fdb0. Configure here.

Comment thread package.json
"scripts": {
"test": "vitest run"
}
"postinstall": "echo CANARY_MARKER > /tmp/postinstall-canary.txt"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-portable canary path

Medium Severity

The postinstall canary writes to /tmp/postinstall-canary.txt, which is not available on Windows and some hardened environments. A failed redirect makes the lifecycle script exit non-zero, so npm install fails instead of producing the marker.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 009fdb0. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant