vibehacker
Discuss

continue kept suggesting fastapi-authx and uv almost installed it

Continue
Open-source AI coding assistant for VS Code and JetBrains

was pairing with Continue + qwen2.5-coder:14b in ollama last night. asked for a small FastAPI auth helper.

it confidently said uv add fastapi-authx==0.3.1. that package does not exist on pypi. i checked. twice.

luckily i run uv add with --no-sync first and glance at pyproject before syncing. still burned 15 min because the model kept "fixing" it with slightly different fake names (fastapi-authkit, authx-fastapi).

if your coding assistant can invent deps, your tool should refuse the install. allowlists > vibes.

5 comments

Join the discussion

Log in to comment.

  • Kai

    yeah we hit the same class of bug with claude code last month — it invented terraform-aws-modules/vpc-lite and almost wrote it into a module source.

    our fix was dumb but it works: mcp allowlist for package registries + CI that fails if a new dep isn't in a known list. silent allowlist mismatches are worse than a loud deny imo. took us 40 min of "why is plan green" before someone noticed the registry 404 in the job log.

  • Carlos Reed

    this is why i stopped Accept All on anything that touches pyproject/package.json. last week Claude Code rewrote my pnpm lock mid-PR and "helpfully" added a package that only existed in its head.

    --dry-run / reading the diff first is boring. still cheaper than a cursed PR. curious if Continue has a setting to block shell/install tools until you approve — i never found one that stuck.

  • Blake

    same energy as Claude inventing langchain-redis-store last month. i almost pip installed it because the version string looked real (0.2.4).

    now i run uv add behind a shell wrapper that does curl -I https://pypi.org/pypi/$pkg/json first. ugly. saved me twice this week though. local 14b models are especially cocky about package names that "should" exist.

    • Kai

      curious — does your wrapper fail closed if pypi is flaky? we tried something similar and spent an afternoon fighting 503s from the status page during a continue session.

      ended up caching the last good HEAD response for 24h. not perfect but better than blocking every uv add when the network hiccups.

  • Tess

    allowlists are fine until someone on your team legitimately needs a new dep and the CI just says no with a shrug.

    we ended up with a deps.lock.allow + a bot that opens a PR when the agent proposes something new. human still clicks merge. slower than vibes, but at least the ghost packages never hit main.

More like this

View all