After a lot of research, it looks like Classic Yarn does not support installing private registry packages.
I have an PAT (Personal Access Token) set for my auth token and listed the private registry as a scoped registry. Currently the only way to install my private registry package is through npm with a command like this npm i @scope/package --legacy-peer-deps. Now my issue is that I have a yarn.lock file and a package-lock.json file. Which for me that works and I can run my code fine. However, it updates the package.json file with all packages.
Now if I provide the codebase to a co-worker and they run yarn install it will through the famous "404 not found" error because of the private registry packages. The only way to fix this, is to remove from package.json the private registry files and then install everything then go an install the private registry dependencies with npm.
I know easy answer would be switch to full NPM, but I am certain there has to be a way around this somewhere out there while keeping full Classic Yarn as the package manager.
Thoughts on what I could do:
- split install the yarn and npm packages with something like
install-subsetnpm package -> Issue is that I need every dev to install this globally and I still have 2 lock files in my repo. - Write a script to add to post install that merges the two lock files -> I am certain this will break something
- Try changing to Yarn 2.x -> issue I am using latest Angular with latest ng-cli and right now it does not support Yarn 2.x.
UPDATE:
After some more research I found this comment on a thread under Yarn's issues from a while ago. The only issue is that this works only if the package number never changes, but also only works if we need a single package. Making it hard to maintain, because we need to update multiple lines of _authToken for each package. Does anyone know a way to have this work with maybe a * instead of package number so that we can install multiple packages from the given private registry?