logoalt Hacker News

DanielHBtoday at 12:36 PM1 replyview on HN

I made changes to my dependency lists in the same code where Claude ran npm update. The lockfile diff was a few hundred lines after I undid what Claude did.

And yes, eventually I did check the lockfile changes and spotted the problem. I just usually don't check the lockfile that throughly.


Replies

kouteiheikatoday at 2:14 PM

> I made changes to my dependency lists in the same code where Claude ran npm update.

...but was it in the same commit? Two "update lockfile" commits, one yours and one Claude's should have made this obvious, no?

Here's another useful rule of thumb: never mix your changes with the agent's changes. Agent always starts with a clean repository (no pending, uncommited human changes). You always start with with a clean repository (no pending, uncommited agent changes).

Personally I have this in my `AGENTS.md`:

    ## Commit early, commit often
    You are allowed and encouraged to produce small, self-contained commits.
    Never `git push`; I will always review and rebase the full history and do the push myself.
    Commit messages should be *short* and on-point. They're there for *me* to review your work, and *not* a public historical artifact.
So my workflow is usually this: start agent with a clean repository, tell it to do a thing, it works in the background, then once it's finished I come back, review, rewrite and clean up half of what it wrote, then maybe iterate some more with it, and finally do an interactive git rebase to get a clean commit history.
show 1 reply