I have pretty big monorepo, managed solely by Yarn Workspaces (no Lerna). One of the packages ("workspaces") contains a set of 3rd party NodeJS packages that we use as a shared layer for our Lambda functions, collected as dependencies in package.json of this package. Build script for this package is supposed to collect all dependencies in a zip file that will be later published by Terraform. Unfortunately, Yarn cannot build single workspace from the monorepo, so we have to use NPM directly.
Currently we do roughly the following -
- copy
package.jsonto abuildfolder - run
npm install --productionin this folder - zip the resulting
node_modulestree
My main problem with this approach (besides mixing the build tools) is that the build is not repeatable - each time we run npm install we may get newer compatible version of any dependent package, since the version is "locked" by Yarn in the top-level yarn.lock file and NPM (obviously) is not aware about it.
I'm pretty sure we are not alone in this boat. Are there any better approaches available?