pnpm Workspaces & Private Flag: Should Workspace Root Privacy Implicitly Apply to Nested Packages?
0 reputation · 03 Oct 2020, 09:53 UTC
Problem Context
The private field in a package’s package.json is intended to prevent accidental public publishing. In a pnpm workspace, each package can declare its own privacy setting, but the workspace root’s private flag is not automatically propagated to nested packages. This can lead to confusion when a developer expects a single pnpm publish command to publish only the intended package(s).
Unresolved Decision
pnpm currently treats the private flag as a per‑package attribute. There is no documented enforcement that a workspace root marked "private": true will implicitly mark all child packages as private, unlike npm’s default behavior in some contexts. The community has debated whether such propagation should be added, but no consensus or implementation has been finalized as of the latest release.
Key Questions
- Should pnpm automatically treat all packages within a workspace as private if the workspace root’s
privateflag is set? - If propagation is added, how would that affect existing projects that rely on mixed public/private packages within the same workspace?
- What mechanisms would pnpm use to document and enforce this implicit privacy, and how would it interact with the
--accessflag during publishing?