IdeaSift

JavaScript monorepo teams fight fragile package publishing workflows

JavaScript monorepo maintainers report friction getting packages published reliably from local setups and CI. In particular, registry authentication can modify `.npmrc` or other config that teams do not want committed, while some workspace and provenance workflows are not supported consistently across package managers. The reports point to gaps in existing release workflows, not a single failure affecting every team.

For javaScript monorepo maintainers. Mentioned from Jun 2019 to Mar 2026 on GitHub and Hacker News.

11 different people described this problem in 6 separate discussions.

Week of 2026-07-13: 0Week of 2026-07-20: 0Week of 2026-07-27: 0Week of 2026-08-03: 0Week of 2026-08-10: 0Week of 2026-08-17: 0Week of 2026-08-24: 0Week of 2026-08-31: 0Week of 2026-09-07: 0Week of 2026-09-14: 0Week of 2026-09-21: 0Week of 2026-09-28: 0
0 mentions in the last 12 weeks
Indie fit
5.0/10
Pain
6.0/10
Frequency
9.0/10
Willingness to pay
0.0/10
Momentum
5.0/10
Who pays
Businesses
Competition
High
Build difficulty
Medium

What people said

Quoted word for word. Follow a link to read the whole discussion.

  1. The token cannot be passed directly to lerna publish because https://github.com/lerna/lerna/issues/2404 has been closed. The token cannot be committed to .yarnrc.yml ahead of time, for security
    donmccurdy on GitHub (lerna/lerna)Sep 2024Asked for a toolHas a workaround
  2. This would also be useful for our project where we want to enforce usage of an internal npm registry for package installs via .npmrc but we can't commit .npmrc because npm login modifies it right before we run lerna publish
Build brief

See what to build and who will buy it

  • 1 product idea with the smallest useful version and pricing
  • 4 places to find your first customers
  • 9 more quotes from people who have this problem
  • Current workarounds, existing solutions and risks