Skip to main content
Version: 0.15 (glpkg CLI)

Registries and ecosystems

Group and project registries​

GitLab has a package registry per project, and a read-only view per group that covers all projects in it.

CommandRegistry used
glpkg install … --group <group>The group registry, e.g. https://gitlab.com/api/v4/groups/<id>/-/packages/npm/
glpkg publishThe project registry of the current repository, e.g. https://gitlab.com/api/v4/projects/<id>/packages/npm/

When you install without a token and glpkg.lock.json knows the package's project ID, glpkg uses that project's registry instead (anonymous access works for public projects).

Registry proxy​

Optional. If your organization runs a registry proxy, npm and generic packages can be installed through it; see Registry proxy.

How each ecosystem is wired​

EcosystemFlagGitLab sourceExternal sourceTool
npm(default)Temporary npm config: @scope:registry=<group registry> and the auth line, passed to npm with NPM_CONFIG_USERCONFIG, deleted after the runregistry.npmjs.orgnpm
PyPI--pypiGroup index …/groups/<id>/-/packages/pypi/simple (token in the index URL). pypi.org is added as an extra index only when none of the requested names also exists on pypi.orgpypi.orgpip
Go--goGOPROXY=<group Go proxy>,https://proxy.golang.org,direct, with GOPRIVATE and GONOSUMDB set to <host>/*default GOPROXYgo get
NuGet--nugetAdds a source gitlab-<group id> to ./nuget.confignuget.orgdotnet add package
Generic--genericDownloads from the GitLab generic registry into --output <dir>——
NuGet credentials

For a GitLab NuGet source with a token, glpkg writes the token in clear text into nuget.config in the current directory. Do not commit that file. See Files.

npm config and your .npmrc​

glpkg never writes your project .npmrc or ~/.npmrc. For each npm run it creates a temporary config file under the system temp directory and points npm at it with NPM_CONFIG_USERCONFIG, so your user ~/.npmrc is not used for that run. The token is not written into the file; it is referenced as ${GITLAB_TOKEN} and passed in the environment.

--keep-npmrc keeps that temporary file and prints its path, which helps debugging.

If a project .npmrc exists and an install fails, glpkg prints a hint, since an old .npmrc (for example from the gitlab-* CLIs) can conflict with the generated settings.