Skip to content

BAD CODE: exact-pinned @git-stunts dependencies stop upstream fixes reaching Think #37

Description

@flyingrobots

Observation

package.json pins two @git-stunts packages to exact versions while the rest of the ecosystem uses caret ranges:

Package Think declares Sibling packages declare npm latest
@git-stunts/plumbing 3.0.3 (exact) git-warp/git-cas: ^3.1.0 3.2.0
@git-stunts/git-cas 6.0.0 (exact) git-warp: ^6.2.0 —
@git-stunts/git-warp ^18.2.1 — 19.0.2

Why this is bad

An exact pin means an upstream fix can never reach Think by semver — it requires a hand edit that nothing prompts.

This is live right now. git-stunts/plumbing#13 fixes a defect where git could not read the operator's ~/.gitconfig, causing every mind commit to be attributed to a fabricated user@hostname address that no forge can verify. git-warp and git-cas will pick that fix up automatically once published, because ^3.1.0 already admits it. Think will not, and the copy Think pins is the one that matters: Think calls ShellRunnerFactory.create() from its own @git-stunts/plumbing and hands that runner to git-warp, so git-warp's nested copy is not the deciding one.

Verified by patching node_modules/@git-stunts/plumbing in place: captures then commit as the configured identity. Restored, they revert to the fabricated address.

The pins also disagree with the ecosystem in a way that will collide. Think wants git-warp ^18.2.1 while npm latest is 19.0.2 and PR #29 is mid-cutover to v19; Think pins git-cas 6.0.0 while git-warp itself wants ^6.2.0. The v19 cutover and the identity-fix propagation both need to edit these same pins, so running them concurrently risks conflicting changes across #29 and #34.

Suggested direction

  • Decide deliberately whether exact pins are policy. If they are, the reason should be documented next to them, and a cadence should exist for reviewing them — docs/method/backlog/bad-code/CORE_audit-no-dependency-freshness-cadence.md already notes the missing cadence.
  • If they are incidental, move to caret ranges consistent with the sibling packages and rely on the lockfile for reproducibility.
  • Either way, sequence the v19 cutover and the identity propagation rather than interleaving them.

References

Activity

  1. coderabbitai commented on Aug 4, 2026

    @coderabbitai
    🔗 Related PRs

    #24 - Add Think feature proposal docs [merged]
    #28 - Stop Think from managing git-warp cache [merged]
    #30 - Agent-first README, MCP install tooling, and capture/test isolation fixes [open]
    #31 - Capture followthrough policy and test-harness isolation [merged]
    #34 - Stop Think writing its identity into the host repository [open]


    📝 Issue Planner

    Check the box below or use the @coderabbitai plan command to generate an implementation plan and prompts that you can use with your favorite coding assistant.

    • Create Plan

    🧪 Issue enrichment is currently in open beta.

    You can configure auto-planning by selecting labels in the issue_enrichment configuration.

    To disable automatic issue enrichment, add the following to your .coderabbit.yaml:

    issue_enrichment:
      auto_enrich:
        enabled: false

    💬 Have feedback or questions? Drop into our discord!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions