Skip to main content
Version: 0.15 (glpkg CLI)

Python, Go, NuGet and generic packages

The same source rules apply to every ecosystem: --group <group> or --external, or a record in glpkg.lock.json. Global installs always need a flag.

Python (PyPI)​

Requires pip; publishing also needs build and twine (pip install build twine).

glpkg install mylib --pypi --group your-org
glpkg install "mylib>=1.2" --pypi --group your-org
glpkg install requests --pypi --external
glpkg install mytool --pypi -g --group your-org # pip --user

From a GitLab group, glpkg installs from the group's PyPI index. To protect against dependency confusion, pypi.org is added as an extra index only if none of the requested names also exists on pypi.org; otherwise glpkg installs from the GitLab index alone and prints a warning.

Publish from the directory with pyproject.toml:

glpkg publish --pypi --dry-run
glpkg publish --pypi --bump patch

glpkg bumps the version in pyproject.toml, runs python -m build (skip with --no-build), uploads dist/* with twine to the project registry, then commits pyproject.toml, tags and pushes.

Go​

Requires go.

glpkg install gitlab.com/your-org/mymod --go --group your-org
glpkg install gitlab.com/your-org/[email protected] --go --group your-org
glpkg install golang.org/x/text --go --external

From a GitLab group, glpkg runs go get with GOPROXY set to the group's Go proxy, then https://proxy.golang.org,direct, and GOPRIVATE / GONOSUMDB set to your GitLab host.

Publishing a Go module creates and pushes a Git tag; there is no upload:

glpkg publish --go --dry-run
glpkg publish --go --bump minor # latest tag v1.3.2 → v1.4.0
glpkg publish --go # latest tag + patch

glpkg runs go mod tidy, commits go.mod/go.sum (chore: update go.mod), tags the new version and pushes (unless --push false; --git-tag does not apply to Go). Without any tag, glpkg publish --go creates v0.1.0, and --bump starts from v0.0.0 (--bump patch → v0.0.1).

--dry-run skips the commit, tag and push, but still runs go mod tidy, which can change go.mod and go.sum.

NuGet​

Requires the dotnet CLI.

glpkg install Your.Package --nuget --group your-org
glpkg install [email protected] --nuget --group your-org
glpkg install Newtonsoft.Json --nuget --external
Token stored in clear text

With a GitLab source and a token, glpkg adds a source gitlab-<group id> to nuget.config in the current directory and writes your token into it in clear text. Do not commit that file; add it to .gitignore. Use a token with the smallest scope you need (read_api). See Files.

Publish from the directory with the .csproj:

glpkg publish --nuget --bump patch

glpkg bumps the version in the .csproj, runs dotnet pack -c Release (skip with --no-build), pushes the .nupkg from bin/Release to the project registry (existing versions are skipped), then commits, tags and pushes.

Generic packages​

Generic packages live only in GitLab. They are named @scope/name, with an optional @version.

glpkg install @your-org/assets --generic --group your-org -o ./vendor
glpkg install @your-org/[email protected] --generic --group your-org -o ./vendor

-o, --output <dir> is required. The source is recorded in glpkg.lock.json when you pass --group.

Publish with a glpkg.json manifest (or --manifest <file>):

{
"name": "@your-org/assets",
"version": "1.0.0",
"files": ["dist/**"],
"exclude": ["**/*.map"]
}

name, version and the files array are required; exclude is optional. Without a glpkg.json, glpkg falls back to package.json, which then needs a files field or a glpkg block.

glpkg publish --generic --dry-run
glpkg publish --generic

glpkg creates a tarball and uploads it to the project's generic registry. The [type] argument and --bump are not used for generic packages; set version in glpkg.json.

→ Registry proxy (optional)