Skip to main content
Version: 0.15 (glpkg CLI)

Files glpkg reads and writes

In your home directory​

All user configuration lives in ~/.config/glpkg/.

FileWritten byContents
tokenglpkg config saveYour GitLab token. File mode 0600.
defaults.jsonglpkg config defaultshost, repo.* and publish.* defaults

In your project​

FileCommit it?Written byPurpose
glpkg.lock.jsonYesglpkg install, glpkg lock setWhere each package comes from
distkit.manifest.jsonYes, if presentglpkg migrate-lock --write onlyGroup origins of packages (packageOrigins)
glpkg.jsonYesYouManifest for glpkg publish --generic
nuget.configNo (when it holds a token)glpkg install --nugetNuGet sources, see below

glpkg does not write .npmrc, neither in your project nor in your home directory.

glpkg.lock.json​

glpkg.lock.json records, for each package glpkg installed or you recorded with glpkg lock set:

  • the ecosystem (npm, PyPI, Go, NuGet, generic) and the full package name,
  • the source: gitlab or external,
  • for GitLab sources, the group path and numeric group ID,
  • after a project npm install, version and registry details taken from package-lock.json.

glpkg manages this file; do not edit it by hand. Use glpkg lock set or glpkg install … --group|--external to change an entry. Global installs (-g) never read or write it.

A whole-project glpkg install requires every direct dependency in package.json to be recorded here. See Package sources.

distkit.manifest.json​

Holds the authored group of each package in packageOrigins. In glpkg 0.15 only glpkg migrate-lock --write writes it. glpkg install neither reads nor writes it.

glpkg.json​

The manifest for generic packages, read by glpkg publish --generic (or the file given with --manifest). It is a flat JSON object with name, version and a files array (glob patterns), and optionally exclude. See Generic packages.

nuget.config​

Token stored in clear text

When you install a NuGet package from a GitLab group with a token, glpkg install --nuget adds a source named gitlab-<group id> to nuget.config in the current directory and stores your GitLab token there in clear text (ClearTextPassword, user name gitlab-ci-token).

  • Do not commit that nuget.config. Add it to .gitignore, or remove the credentials after installing.
  • Prefer a token with the smallest scope you need (read_api).
  • In CI, make sure the file is not kept as an artifact or cache.

.npmrc​

For each npm install and publish, glpkg creates a temporary npm config file in the system temp directory (glpkg-*) and points npm at it with NPM_CONFIG_USERCONFIG. The file holds the scope registry lines and an auth line that references ${GITLAB_TOKEN}; the token itself is passed in the environment. The file is deleted after the command, unless you pass --keep-npmrc to install.

Because npm reads that file as its user config during the run, your ~/.npmrc is not used for glpkg's npm runs. A project .npmrc is still read by npm. An old project .npmrc with GitLab registry or _authToken lines (for example from the gitlab-* CLIs) can conflict; remove it if installs fail.

Files glpkg no longer uses​

FileStatus
.gitlab-packages.jsonNot read by glpkg. Delete it.
~/.config/gitlab-config/tokenToken file of the old gitlab-config CLI. Save your token again with glpkg config save.
package.json "glpkg": { "groups": … }Deprecated. Migrate with glpkg migrate-lock.

→ Registry proxy (optional)