glpkg install
Install packages. Each package's source is given with --group / --external, or read from
glpkg.lock.json.
glpkg install|add|i [options] [packages...]
Options
| Option | Description |
|---|---|
[packages...] | Packages to install. Omit to install the whole project (npm). |
-D, --save-dev | Save as devDependencies (npm) |
-g, --global | Install globally (npm) or with pip --user (PyPI). Never reads or writes the lock. |
--group <name> | Install the named packages from this GitLab group (path or numeric ID). Recorded in glpkg.lock.json. |
--external | Install the named packages from the ecosystem's own registry. Recorded in glpkg.lock.json. |
--source <source> | Optional, see Registry proxy. With --group: gitlab (default) or proxy |
--pypi | PyPI package |
--go | Go module |
--nuget | NuGet package |
--generic | GitLab generic package |
-o, --output <dir> | Output directory (generic only; required) |
--keep-npmrc | Keep the temporary npm config file and print its path (default: delete it) |
install has no --token option. It uses the saved token or GITLAB_TOKEN; see
Authentication.
Examples
# npm, from a GitLab group
glpkg install @your-org/utils --group your-org
glpkg install @your-org/utils@^2.0.0 --group your-org
glpkg install @your-org/test-kit -D --group your-org
# npm, from npmjs
glpkg install typescript @types/node -D --external
# whole project: sources come from glpkg.lock.json only
glpkg install
# global (always needs a flag)
glpkg install -g @your-org/cli --group your-org
glpkg install -g @glpkg/cli --group microwiseai
# other ecosystems
glpkg install mylib --pypi --group your-org
glpkg install requests --pypi --external
glpkg install gitlab.com/your-org/[email protected] --go --group your-org
glpkg install [email protected] --nuget --group your-org
glpkg install @your-org/[email protected] --generic --group your-org -o ./vendor
Behavior
- Named packages. Each package needs a source from the flags or the lock. Otherwise the command fails and lists every package without a source (nothing is installed).
- Whole project (
glpkg installwith no names, npm only). ReadsdependenciesanddevDependenciesfrompackage.json, takes every source fromglpkg.lock.json, and runsnpm install.--group,--externaland--sourceare rejected here. - Recording. After a successful non-global install, the sources are recorded in
glpkg.lock.json. After a project npm install, glpkg also adds version and registry details frompackage-lock.json(best effort; never fails the install). - Hosting check. For a GitLab source (npm), glpkg verifies that the group hosts the package and refuses look-alikes. See Package sources.
- Anonymous installs. Without a token, glpkg tries an anonymous install, which works for public projects only.
- Failures. If any package fails, the command exits with a non-zero status.
Ecosystem details: Registries and ecosystems and Python, Go, NuGet and generic packages.
Errors
| Message | Fix |
|---|---|
No install source recorded for: <names> | Add --group <group> or --external, or record with glpkg lock set |
<pkg> is not in GitLab group '<group>' (…) | Wrong group, or the package is not published there |
--external and --group are mutually exclusive … | Use one of them per command |
--source requires --group <group> | Add --group |
A whole-project \glpkg install` takes no --group/--external/--source.` | Name the packages, or use glpkg lock set |
Generic packages live only in GitLab: use --group <group> (no --external) | Use --group |
More in Troubleshooting. Proxy errors: Registry proxy.