Skip to main content
Version: 0.15 (glpkg CLI)

glpkg lock

Record where each package comes from in glpkg.lock.json, without installing anything.

glpkg lock init [--json]
glpkg lock set <packages...> (--group <group> | --external) [--pypi|--go|--nuget|--generic]

lock init​

Lists the direct dependencies in package.json that have no recorded source, and the commands to record them. It writes nothing and guesses nothing.

glpkg lock init
glpkg lock init --json # { "recorded": [...], "missing": [...] }

lock set​

Records the source of one or more packages.

OptionDescription
--group <group>GitLab group the packages come from (path or numeric ID)
--source <source>Optional, see Registry proxy. With --group: gitlab (default) or proxy
--externalThe ecosystem's own registry
--pypi, --go, --nugetRecord for another ecosystem (default: npm)
--genericGeneric packages, named @scope/name

For npm packages with a GitLab source, lock set checks that the group hosts each package, just like install. Generic packages cannot be --external.

Recording sources for an existing project​

glpkg lock init
glpkg lock set @your-org/a @your-org/b --group your-org
glpkg lock set react react-dom --external
glpkg lock set typescript vitest --external
glpkg lock init # "Every direct dependency has a recorded source"
glpkg install
git add glpkg.lock.json && git commit -m "Record package sources"

To change a package's source, run lock set (or install with a flag) again; the entry is replaced.