On PR #270, the CodeRabbit auto-fix commit (5e49637) regenerated both api/pnpm-lock.yaml and web/pnpm-lock.yaml alongside the two small fixes it was actually asked to make. The regeneration floated every dependency to the newest version its range allows, which pulled zod 4.4.3 into @polar-sh/sdk and broke @polar-sh/sdk/webhooks type resolution. Four API test suites failed to compile and the "Build and test API" and web "e2e" checks went red. The lockfiles were restored in 0ee62ea.
Notably, .coderabbit.yaml already excludes **/pnpm-lock.yaml via reviews.path_filters, but that only keeps lockfiles out of review comments. The auto-fix agent runs installs in its own sandbox and commits whatever its workspace produces, so the exclusion did not stop it.
Guardrails to add:
- A lockfile guard workflow that fails any PR where a pnpm-lock.yaml changes without its sibling package.json. This is the only deterministic stop, and it covers any actor, not just CodeRabbit.
- packageManager pins (pnpm@9.14.2) in api/package.json and web/package.json, with the CI workflows reading the pin instead of a loose version: 9, so every tool resolves dependencies with the same pnpm.
- --frozen-lockfile on the CI installs so an out-of-sync lockfile fails at install time instead of being silently re-resolved.
- An explicit instruction in .coderabbit.yaml telling the fix agent to never run installs or commit lockfile changes.
Reactions are currently unavailable
On PR #270, the CodeRabbit auto-fix commit (5e49637) regenerated both api/pnpm-lock.yaml and web/pnpm-lock.yaml alongside the two small fixes it was actually asked to make. The regeneration floated every dependency to the newest version its range allows, which pulled zod 4.4.3 into @polar-sh/sdk and broke @polar-sh/sdk/webhooks type resolution. Four API test suites failed to compile and the "Build and test API" and web "e2e" checks went red. The lockfiles were restored in 0ee62ea.
Notably, .coderabbit.yaml already excludes **/pnpm-lock.yaml via reviews.path_filters, but that only keeps lockfiles out of review comments. The auto-fix agent runs installs in its own sandbox and commits whatever its workspace produces, so the exclusion did not stop it.
Guardrails to add: