Registries and ecosystems
Group and project registries
GitLab has a package registry per project, and a read-only view per group that covers all projects in it.
| Command | Registry used |
|---|---|
glpkg install … --group <group> | The group registry, e.g. https://gitlab.com/api/v4/groups/<id>/-/packages/npm/ |
glpkg publish | The project registry of the current repository, e.g. https://gitlab.com/api/v4/projects/<id>/packages/npm/ |
When you install without a token and glpkg.lock.json knows the package's project ID,
glpkg uses that project's registry instead (anonymous access works for public projects).
Registry proxy
Optional. If your organization runs a registry proxy, npm and generic packages can be installed through it; see Registry proxy.
How each ecosystem is wired
| Ecosystem | Flag | GitLab source | External source | Tool |
|---|---|---|---|---|
| npm | (default) | Temporary npm config: @scope:registry=<group registry> and the auth line, passed to npm with NPM_CONFIG_USERCONFIG, deleted after the run | registry.npmjs.org | npm |
| PyPI | --pypi | Group index …/groups/<id>/-/packages/pypi/simple (token in the index URL). pypi.org is added as an extra index only when none of the requested names also exists on pypi.org | pypi.org | pip |
| Go | --go | GOPROXY=<group Go proxy>,https://proxy.golang.org,direct, with GOPRIVATE and GONOSUMDB set to <host>/* | default GOPROXY | go get |
| NuGet | --nuget | Adds a source gitlab-<group id> to ./nuget.config | nuget.org | dotnet add package |
| Generic | --generic | Downloads from the GitLab generic registry into --output <dir> | — | — |
For a GitLab NuGet source with a token, glpkg writes the token in clear text into
nuget.config in the current directory. Do not commit that file. See
Files.
npm config and your .npmrc
glpkg never writes your project .npmrc or ~/.npmrc. For each npm run it creates a
temporary config file under the system temp directory and points npm at it with
NPM_CONFIG_USERCONFIG, so your user ~/.npmrc is not used for that run. The token is not
written into the file; it is referenced as ${GITLAB_TOKEN} and passed in the environment.
--keep-npmrc keeps that temporary file and prints its path, which helps debugging.
If a project .npmrc exists and an install fails, glpkg prints a hint, since an old
.npmrc (for example from the gitlab-* CLIs) can conflict with the generated settings.