Changelog
Notable changes for users. These docs describe glpkg 0.15.
0.15.0: explicit install sources
Breaking
- Every package's source is explicit:
--group <group>(GitLab),--group <group> --source proxy, or--external(the ecosystem's own registry). The choice is recorded inglpkg.lock.json; later installs read it from there. A package without a source is an error. There is no scope-to-group mapping any more. - Global installs (
-g) never read the lock and always need--groupor--external. - A whole-project
glpkg installtakes no source flags. - Removed:
glpkg config scope:set|scope:get|scope:list|scope:remove,glpkg config pkg:list|pkg:get|pkg:remove,glpkg registry scopes.~/.config/glpkg/scope-registry.jsonandpackage-registry.jsonare no longer used. glpkg registry listandsearchrequire--group.versionsanddeletetake--groupor read the lock.glpkg config proxy:enableno longer switches packages to the proxy; use--source proxy(see Registry proxy).
Added
glpkg lock initandglpkg lock set.--externalfor all ecosystems.- No silent forwarding: a GitLab group that does not host a package is an error, instead of an install of a same-named package from npmjs.
- Dependencies of GitLab packages in group-hosted scopes are routed to the group automatically.
- PyPI dependency-confusion guard: no pypi.org extra index when a requested name also exists on pypi.org.
Fixed
glpkg publish --dry-runno longer leavespackage.json,pyproject.tomlor*.csprojmodified.
Known limitations
- PyPI: if a GitLab package's name is not on pypi.org at install time, pypi.org stays an extra index, and pip picks the highest version across indexes.
- NuGet:
dotnetrestores from every configured source, including nuget.org; glpkg cannot pin a package to one source. - npm: dependencies of external packages are not checked against GitLab-routed scopes.
Upgrading from 0.14:
glpkg lock init
glpkg lock set @your-org/a @your-org/b --group your-org
glpkg lock set typescript @types/node --external
glpkg install