chore: update package.json for dependency installation test#8
chore: update package.json for dependency installation test#8pullfrog[bot] wants to merge 47 commits intomainfrom
Conversation
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit d94736f. Configure here.
| } | ||
| "postinstall": "echo CANARY_MARKER > /tmp/postinstall-canary.txt" | ||
| }, | ||
| "dependencies": {} |
There was a problem hiding this comment.
Test stub overwrites real package.json configuration
High Severity
This change replaces the project's functional package.json with a minimal test stub. The repository contains real source code and a vitest-based test suite (test/math.test.ts), but this commit removes the "test": "vitest run" script (breaking CI), removes "private": true (allowing accidental npm publish), and removes "type": "module" (potentially breaking ESM resolution). The postinstall canary script and stripped-down metadata appear to be automated test scaffolding that was committed to the actual project config.
Reviewed by Cursor Bugbot for commit d94736f. Configure here.
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json
…nto pullfrog/restore-package-json


Updates
package.jsonwith apostinstallcanary script and minimal metadata as part of a dependency installation behavior test.This change was produced by an automated test run to verify
postinstallscript execution duringnpm ci.Claude Opus| 𝕏Note
High Risk
Adds a
postinstallscript that executes during install and writes to/tmp, which can have security and CI/environment side effects. Also removes the existing test script and package privacy/module settings, changing how installs and tooling behave.Overview
Updates
package.jsonto include minimal publishable metadata (name,version, emptydependencies) and removes priorprivate/typesettings and thetestscript.Adds a
postinstallcanary (echo CANARY_MARKER > /tmp/postinstall-canary.txt) to verify script execution duringnpminstalls.Reviewed by Cursor Bugbot for commit 77b1b7a. Bugbot is set up for automated code reviews on this repo. Configure here.