Skip to main content
Version: 0.15 (glpkg CLI)

glpkg install

Install packages. Each package's source is given with --group / --external, or read from glpkg.lock.json.

glpkg install|add|i [options] [packages...]

Options​

OptionDescription
[packages...]Packages to install. Omit to install the whole project (npm).
-D, --save-devSave as devDependencies (npm)
-g, --globalInstall globally (npm) or with pip --user (PyPI). Never reads or writes the lock.
--group <name>Install the named packages from this GitLab group (path or numeric ID). Recorded in glpkg.lock.json.
--externalInstall the named packages from the ecosystem's own registry. Recorded in glpkg.lock.json.
--source <source>Optional, see Registry proxy. With --group: gitlab (default) or proxy
--pypiPyPI package
--goGo module
--nugetNuGet package
--genericGitLab generic package
-o, --output <dir>Output directory (generic only; required)
--keep-npmrcKeep the temporary npm config file and print its path (default: delete it)

install has no --token option. It uses the saved token or GITLAB_TOKEN; see Authentication.

Examples​

# npm, from a GitLab group
glpkg install @your-org/utils --group your-org
glpkg install @your-org/utils@^2.0.0 --group your-org
glpkg install @your-org/test-kit -D --group your-org

# npm, from npmjs
glpkg install typescript @types/node -D --external

# whole project: sources come from glpkg.lock.json only
glpkg install

# global (always needs a flag)
glpkg install -g @your-org/cli --group your-org
glpkg install -g @glpkg/cli --group microwiseai

# other ecosystems
glpkg install mylib --pypi --group your-org
glpkg install requests --pypi --external
glpkg install gitlab.com/your-org/[email protected] --go --group your-org
glpkg install [email protected] --nuget --group your-org
glpkg install @your-org/[email protected] --generic --group your-org -o ./vendor

Behavior​

  • Named packages. Each package needs a source from the flags or the lock. Otherwise the command fails and lists every package without a source (nothing is installed).
  • Whole project (glpkg install with no names, npm only). Reads dependencies and devDependencies from package.json, takes every source from glpkg.lock.json, and runs npm install. --group, --external and --source are rejected here.
  • Recording. After a successful non-global install, the sources are recorded in glpkg.lock.json. After a project npm install, glpkg also adds version and registry details from package-lock.json (best effort; never fails the install).
  • Hosting check. For a GitLab source (npm), glpkg verifies that the group hosts the package and refuses look-alikes. See Package sources.
  • Anonymous installs. Without a token, glpkg tries an anonymous install, which works for public projects only.
  • Failures. If any package fails, the command exits with a non-zero status.

Ecosystem details: Registries and ecosystems and Python, Go, NuGet and generic packages.

Errors​

MessageFix
No install source recorded for: <names>Add --group <group> or --external, or record with glpkg lock set
<pkg> is not in GitLab group '<group>' (…)Wrong group, or the package is not published there
--external and --group are mutually exclusive …Use one of them per command
--source requires --group <group>Add --group
A whole-project \glpkg install` takes no --group/--external/--source.`Name the packages, or use glpkg lock set
Generic packages live only in GitLab: use --group <group> (no --external)Use --group

More in Troubleshooting. Proxy errors: Registry proxy.