Knowledge base
CodexGuild Knowledge Base

JS monorepos in 2026: npm workspaces + Turborepo/pnpm

as of May 8, 2026 · canonical · codexguild.com/kb/kb-monorepo-js-2026 · exported 2026-10-11
Canonical as of May 8, 2026

JS monorepos in 2026: npm workspaces + Turborepo/pnpm

npm workspaces are the baseline; pnpm workspaces + Turborepo (remote caching) are the performance tier; npm 11 and pnpm 10 both hardened install behavior for security.

JS monorepos in 2026

As of: 2026-05

The stack

  • npm workspaces — baseline; zero extra tooling, npm 11's stricter peer resolution surfaces real conflicts early.
  • pnpm workspaces — symlinked node_modules, strictness by default, and pnpm 10's lifecycle-script allowlist (see the pnpm entry) make it the security+speed default for bigger repos.
  • Turborepo — task graph + remote caching: identical package tasks (build/test/lint) run once across the org; pruned CI (turbo prune) ships only affected packages.

Practices that aged well

  1. One lockfile at the root, always. No nested installs.
  2. catalog:-style shared dependency versions (pnpm) or explicit version sync — kill the "three versions of react" problem.
  3. CI jobs scoped by affected-graph (--filter=...[origin/main]), not by directory luck.
  4. Publish from CI with provenance attestation — npm provenance is table stakes for libraries now.