Python, Go, NuGet and generic packages
The same source rules apply to every ecosystem: --group <group> or --external, or a
record in glpkg.lock.json. Global installs always need a flag.
Python (PyPI)
Requires pip; publishing also needs build and twine (pip install build twine).
glpkg install mylib --pypi --group your-org
glpkg install "mylib>=1.2" --pypi --group your-org
glpkg install requests --pypi --external
glpkg install mytool --pypi -g --group your-org # pip --user
From a GitLab group, glpkg installs from the group's PyPI index. To protect against dependency confusion, pypi.org is added as an extra index only if none of the requested names also exists on pypi.org; otherwise glpkg installs from the GitLab index alone and prints a warning.
Publish from the directory with pyproject.toml:
glpkg publish --pypi --dry-run
glpkg publish --pypi --bump patch
glpkg bumps the version in pyproject.toml, runs python -m build (skip with
--no-build), uploads dist/* with twine to the project registry, then commits
pyproject.toml, tags and pushes.
Go
Requires go.
glpkg install gitlab.com/your-org/mymod --go --group your-org
glpkg install gitlab.com/your-org/[email protected] --go --group your-org
glpkg install golang.org/x/text --go --external
From a GitLab group, glpkg runs go get with GOPROXY set to the group's Go proxy, then
https://proxy.golang.org,direct, and GOPRIVATE / GONOSUMDB set to your GitLab host.
Publishing a Go module creates and pushes a Git tag; there is no upload:
glpkg publish --go --dry-run
glpkg publish --go --bump minor # latest tag v1.3.2 → v1.4.0
glpkg publish --go # latest tag + patch
glpkg runs go mod tidy, commits go.mod/go.sum (chore: update go.mod), tags the new
version and pushes (unless --push false; --git-tag does not apply to Go). Without any tag,
glpkg publish --go creates v0.1.0, and --bump starts from v0.0.0 (--bump patch →
v0.0.1).
--dry-run skips the commit, tag and push, but still runs go mod tidy, which can change
go.mod and go.sum.
NuGet
Requires the dotnet CLI.
glpkg install Your.Package --nuget --group your-org
glpkg install [email protected] --nuget --group your-org
glpkg install Newtonsoft.Json --nuget --external
With a GitLab source and a token, glpkg adds a source gitlab-<group id> to nuget.config
in the current directory and writes your token into it in clear text. Do not commit
that file; add it to .gitignore. Use a token with the smallest scope you need
(read_api). See Files.
Publish from the directory with the .csproj:
glpkg publish --nuget --bump patch
glpkg bumps the version in the .csproj, runs dotnet pack -c Release (skip with
--no-build), pushes the .nupkg from bin/Release to the project registry (existing
versions are skipped), then commits, tags and pushes.
Generic packages
Generic packages live only in GitLab. They are named @scope/name, with an optional
@version.
glpkg install @your-org/assets --generic --group your-org -o ./vendor
glpkg install @your-org/[email protected] --generic --group your-org -o ./vendor
-o, --output <dir> is required. The source is recorded in glpkg.lock.json when you pass
--group.
Publish with a glpkg.json manifest (or --manifest <file>):
{
"name": "@your-org/assets",
"version": "1.0.0",
"files": ["dist/**"],
"exclude": ["**/*.map"]
}
name, version and the files array are required; exclude is optional. Without a
glpkg.json, glpkg falls back to package.json, which then needs a files field or a
glpkg block.
glpkg publish --generic --dry-run
glpkg publish --generic
glpkg creates a tarball and uploads it to the project's generic registry. The [type]
argument and --bump are not used for generic packages; set version in glpkg.json.