Your first install
This page installs an npm package from a GitLab group into a project. Other ecosystems work the same way; see Python, Go, NuGet and generic packages.
1. Install with a source
Tell glpkg which GitLab group hosts the package:
cd my-project
glpkg install @your-org/utils --group your-org
--group takes the group path (your-org, your-org/subgroup) or its numeric ID.
glpkg then:
- Resolves the group and checks that the group's npm registry really hosts
@your-org/utils. If it does not, the install stops (no fallback to npmjs). - Writes a temporary npm config pointing the
@your-orgscope at the group registry, with your token, and runsnpm install. - Deletes the temporary config.
- Records the source in
glpkg.lock.json.
Packages from npmjs are installed with --external:
glpkg install typescript vitest -D --external
2. Commit glpkg.lock.json
git add package.json package-lock.json glpkg.lock.json
git commit -m "Add @your-org/utils"
glpkg.lock.json records where each direct dependency comes from. Commit it, like
package-lock.json.
3. Install the whole project
On a fresh clone, or in CI:
glpkg install
With no package names, glpkg reads dependencies and devDependencies from
package.json, takes each package's source from glpkg.lock.json, and runs npm install.
Every direct dependency must have a recorded source; otherwise glpkg lists the missing ones
and stops:
✗ Install failed: No install source recorded for: lodash
→ glpkg does not guess. Say where each package comes from (recorded in glpkg.lock.json;
later installs need no flag):
glpkg install lodash --group <group> # GitLab …
glpkg install lodash --external # the npm registry (registry.npmjs.org)
or record without installing: glpkg lock set <pkgs...> --group <group> | --external
Existing project with many dependencies
Record all sources once, without installing:
glpkg lock init # lists direct deps with no source
glpkg lock set @your-org/a @your-org/b --group your-org
glpkg lock set react react-dom typescript --external
glpkg install
See glpkg lock.
Next
- Publish a package
- Package sources explains the rules in detail.