glpkg lock
Record where each package comes from in glpkg.lock.json, without installing anything.
glpkg lock init [--json]
glpkg lock set <packages...> (--group <group> | --external) [--pypi|--go|--nuget|--generic]
lock init
Lists the direct dependencies in package.json that have no recorded source, and the
commands to record them. It writes nothing and guesses nothing.
glpkg lock init
glpkg lock init --json # { "recorded": [...], "missing": [...] }
lock set
Records the source of one or more packages.
| Option | Description |
|---|---|
--group <group> | GitLab group the packages come from (path or numeric ID) |
--source <source> | Optional, see Registry proxy. With --group: gitlab (default) or proxy |
--external | The ecosystem's own registry |
--pypi, --go, --nuget | Record for another ecosystem (default: npm) |
--generic | Generic packages, named @scope/name |
For npm packages with a GitLab source, lock set checks that the group hosts each package,
just like install. Generic packages cannot be --external.
Recording sources for an existing project
glpkg lock init
glpkg lock set @your-org/a @your-org/b --group your-org
glpkg lock set react react-dom --external
glpkg lock set typescript vitest --external
glpkg lock init # "Every direct dependency has a recorded source"
glpkg install
git add glpkg.lock.json && git commit -m "Record package sources"
To change a package's source, run lock set (or install with a flag) again; the entry is
replaced.