JavaScript monorepo teams fight fragile package publishing workflows
JavaScript monorepo maintainers report friction getting packages published reliably from local setups and CI. In particular, registry authentication can modify `.npmrc` or other config that teams do not want committed, while some workspace and provenance workflows are not supported consistently across package managers. The reports point to gaps in existing release workflows, not a single failure affecting every team.
For javaScript monorepo maintainers. Mentioned from Jun 2019 to Mar 2026 on GitHub and Hacker News.
11 different people described this problem in 6 separate discussions.
- Indie fit
- 5.0/10
- Pain
- 6.0/10
- Frequency
- 9.0/10
- Willingness to pay
- 0.0/10
- Momentum
- 5.0/10
- Who pays
- Businesses
- Competition
- High
- Build difficulty
- Medium
What people said
Quoted word for word. Follow a link to read the whole discussion.
The token cannot be passed directly to lerna publish because https://github.com/lerna/lerna/issues/2404 has been closed. The token cannot be committed to .yarnrc.yml ahead of time, for security
This would also be useful for our project where we want to enforce usage of an internal npm registry for package installs via .npmrc but we can't commit .npmrc because npm login modifies it right before we run lerna publish
Build brief
See what to build and who will buy it
- 1 product idea with the smallest useful version and pricing
- 4 places to find your first customers
- 9 more quotes from people who have this problem
- Current workarounds, existing solutions and risks