Files glpkg reads and writes
In your home directory
All user configuration lives in ~/.config/glpkg/.
| File | Written by | Contents |
|---|---|---|
token | glpkg config save | Your GitLab token. File mode 0600. |
defaults.json | glpkg config defaults | host, repo.* and publish.* defaults |
In your project
| File | Commit it? | Written by | Purpose |
|---|---|---|---|
glpkg.lock.json | Yes | glpkg install, glpkg lock set | Where each package comes from |
distkit.manifest.json | Yes, if present | glpkg migrate-lock --write only | Group origins of packages (packageOrigins) |
glpkg.json | Yes | You | Manifest for glpkg publish --generic |
nuget.config | No (when it holds a token) | glpkg install --nuget | NuGet sources, see below |
glpkg does not write .npmrc, neither in your project nor in your home directory.
glpkg.lock.json
glpkg.lock.json records, for each package glpkg installed or you recorded with
glpkg lock set:
- the ecosystem (npm, PyPI, Go, NuGet, generic) and the full package name,
- the source:
gitlaborexternal, - for GitLab sources, the group path and numeric group ID,
- after a project npm install, version and registry details taken from
package-lock.json.
glpkg manages this file; do not edit it by hand. Use glpkg lock set or
glpkg install … --group|--external to change an entry. Global installs (-g) never read or
write it.
A whole-project glpkg install requires every direct dependency in package.json to be
recorded here. See Package sources.
distkit.manifest.json
Holds the authored group of each package in packageOrigins. In glpkg 0.15 only
glpkg migrate-lock --write writes it. glpkg install neither
reads nor writes it.
glpkg.json
The manifest for generic packages, read by glpkg publish --generic (or the file given with
--manifest). It is a flat JSON object with name, version and a files array (glob
patterns), and optionally exclude. See
Generic packages.
nuget.config
When you install a NuGet package from a GitLab group with a token,
glpkg install --nuget adds a source named gitlab-<group id> to nuget.config in the
current directory and stores your GitLab token there in clear text
(ClearTextPassword, user name gitlab-ci-token).
- Do not commit that
nuget.config. Add it to.gitignore, or remove the credentials after installing. - Prefer a token with the smallest scope you need (
read_api). - In CI, make sure the file is not kept as an artifact or cache.
.npmrc
For each npm install and publish, glpkg creates a temporary npm config file in the system
temp directory (glpkg-*) and points npm at it with NPM_CONFIG_USERCONFIG. The file holds
the scope registry lines and an auth line that references ${GITLAB_TOKEN}; the token itself
is passed in the environment. The file is deleted after the command, unless you pass
--keep-npmrc to install.
Because npm reads that file as its user config during the run, your ~/.npmrc is not used
for glpkg's npm runs. A project .npmrc is still read by npm. An old project .npmrc with
GitLab registry or _authToken lines (for example from the gitlab-* CLIs) can conflict; remove
it if installs fail.
Files glpkg no longer uses
| File | Status |
|---|---|
.gitlab-packages.json | Not read by glpkg. Delete it. |
~/.config/gitlab-config/token | Token file of the old gitlab-config CLI. Save your token again with glpkg config save. |
package.json "glpkg": { "groups": … } | Deprecated. Migrate with glpkg migrate-lock. |