Skip to main content
Version: 0.15 (glpkg CLI)

Package sources

Every package glpkg installs has an explicit source. glpkg never guesses where a package comes from.

SourceMeaningHow to choose it
gitlabThe package registry of a GitLab group--group <group>
externalThe ecosystem's own registry: registry.npmjs.org, pypi.org, proxy.golang.org, nuget.org--external

How glpkg decides​

For each package you name, glpkg uses the first of:

  1. Flags: --group <group> or --external. The flags apply to all packages named in the command.
  2. glpkg.lock.json in the current directory: the recorded source for that ecosystem and full package name.
  3. Otherwise an error that lists every package without a source and the commands to record one. Nothing is installed (all or nothing).

There is no mapping from an npm scope to a group, and no default registry. A source you give with a flag is recorded in glpkg.lock.json, so the next install needs no flag.

Flag rules:

  • --group and --external cannot be combined.
  • A whole-project glpkg install (no package names) takes no source flags; it reads the lock only.

Global installs​

glpkg install -g never reads glpkg.lock.json and never writes it. A global install always needs --group or --external:

glpkg install -g @your-org/cli --group your-org
glpkg install -g typescript --external

No look-alike packages​

GitLab's package forwarding answers a request for a package the group does not have with a redirect to npmjs. glpkg checks the group registry without following redirects. If the group does not host the package (redirect, 404, or tarballs on another host), the install fails:

@your-org/utils is not in GitLab group 'your-org' (GitLab answered 404). Not installing a same-named package from elsewhere.

Dependencies of GitLab packages​

When an npm package from a GitLab group depends on other packages that the same group hosts, glpkg routes those dependency scopes to the group registry automatically:

✓ Routed dependency scope @your-org-internal → group registry (hosted by the group)

If a dependency sits in a scope routed to GitLab but the group does not host it, the install stops, because npm would otherwise follow package forwarding to another registry. Publish the dependency to the group, or install it from where it really lives and record that.

Versions​

For npm, glpkg passes your version spec (@your-org/utils@^1.2.0, @your-org/utils@beta) to npm unchanged. npm resolves it against the chosen registry, including dist-tags.