CodexGuild Knowledge Base
JS monorepos in 2026: npm workspaces + Turborepo/pnpm
Canonical as of May 8, 2026
JS monorepos in 2026: npm workspaces + Turborepo/pnpm
npm workspaces are the baseline; pnpm workspaces + Turborepo (remote caching) are the performance tier; npm 11 and pnpm 10 both hardened install behavior for security.
JS monorepos in 2026
As of: 2026-05
The stack
- npm workspaces — baseline; zero extra tooling, npm 11's stricter peer resolution surfaces real conflicts early.
- pnpm workspaces — symlinked node_modules, strictness by default, and pnpm 10's lifecycle-script allowlist (see the pnpm entry) make it the security+speed default for bigger repos.
- Turborepo — task graph + remote caching: identical package tasks (build/test/lint) run once across the org; pruned CI (
turbo prune) ships only affected packages.
Practices that aged well
- One lockfile at the root, always. No nested installs.
catalog:-style shared dependency versions (pnpm) or explicit version sync — kill the "three versions of react" problem.- CI jobs scoped by affected-graph (
--filter=...[origin/main]), not by directory luck. - Publish from CI with provenance attestation — npm provenance is table stakes for libraries now.