Last week I watched an agent "resolve" a dependency conflict the way a rushed junior sometimes does: it pinned an older major of a transitive package so CI went green.
The PR description was confident. Diff looked tiny. Tests passed. Nobody wanted to block it at 6pm.
What it actually did was freeze a security-patched line on an old major. The app still booted. The vuln scanner went quiet for the wrong reason. Two days later a staging deploy started failing on a method that only existed on the newer major the rest of the tree expected.
The 60-second check I wish we'd done before merge:
- Open the lockfile diff alone. If the agent touched versions, read those lines like a security review, not a style review.
- Ask: did we intentionally want this major, or did green CI become the goal?
- Revert just the lockfile change locally and see what actually breaks. If "nothing" breaks except the conflict the agent was solving, dig before you merge.
Green CI means the suite you have didn't catch it. It does not mean the dependency graph is sane.
I keep a short STOP list for AI-written PRs (free one-pager): https://chopragunji.gumroad.com/l/zpnmdn
If you want a human to run that bar on one scary PR, founding slots for a paid Agent PR Audit are still open at $49 (then it goes back to $99): https://chopragunji.gumroad.com/l/byoyi/FOUNDING
Curious what dependency "fixes" you've seen agents invent. Drop a war story below.
Top comments (0)