Package sources
Every package glpkg installs has an explicit source. glpkg never guesses where a package comes from.
| Source | Meaning | How to choose it |
|---|---|---|
gitlab | The package registry of a GitLab group | --group <group> |
external | The ecosystem's own registry: registry.npmjs.org, pypi.org, proxy.golang.org, nuget.org | --external |
How glpkg decides
For each package you name, glpkg uses the first of:
- Flags:
--group <group>or--external. The flags apply to all packages named in the command. glpkg.lock.jsonin the current directory: the recorded source for that ecosystem and full package name.- Otherwise an error that lists every package without a source and the commands to record one. Nothing is installed (all or nothing).
There is no mapping from an npm scope to a group, and no default registry. A source you give
with a flag is recorded in glpkg.lock.json, so the next install needs no flag.
Flag rules:
--groupand--externalcannot be combined.- A whole-project
glpkg install(no package names) takes no source flags; it reads the lock only.
Global installs
glpkg install -g never reads glpkg.lock.json and never writes it. A global install
always needs --group or --external:
glpkg install -g @your-org/cli --group your-org
glpkg install -g typescript --external
No look-alike packages
GitLab's package forwarding answers a request for a package the group does not have with a redirect to npmjs. glpkg checks the group registry without following redirects. If the group does not host the package (redirect, 404, or tarballs on another host), the install fails:
@your-org/utils is not in GitLab group 'your-org' (GitLab answered 404). Not installing a same-named package from elsewhere.
Dependencies of GitLab packages
When an npm package from a GitLab group depends on other packages that the same group hosts, glpkg routes those dependency scopes to the group registry automatically:
✓ Routed dependency scope @your-org-internal → group registry (hosted by the group)
If a dependency sits in a scope routed to GitLab but the group does not host it, the install stops, because npm would otherwise follow package forwarding to another registry. Publish the dependency to the group, or install it from where it really lives and record that.
Versions
For npm, glpkg passes your version spec (@your-org/utils@^1.2.0, @your-org/utils@beta) to
npm unchanged. npm resolves it against the chosen registry, including dist-tags.
Related
glpkg lock: record sources without installing.- Files: what
glpkg.lock.jsoncontains. - Registry proxy (optional)