Skip to main content
Version: 0.15 (glpkg CLI)

Changelog

Notable changes for users. These docs describe glpkg 0.15.

0.15.0: explicit install sources​

Breaking

  • Every package's source is explicit: --group <group> (GitLab), --group <group> --source proxy, or --external (the ecosystem's own registry). The choice is recorded in glpkg.lock.json; later installs read it from there. A package without a source is an error. There is no scope-to-group mapping any more.
  • Global installs (-g) never read the lock and always need --group or --external.
  • A whole-project glpkg install takes no source flags.
  • Removed: glpkg config scope:set|scope:get|scope:list|scope:remove, glpkg config pkg:list|pkg:get|pkg:remove, glpkg registry scopes. ~/.config/glpkg/scope-registry.json and package-registry.json are no longer used.
  • glpkg registry list and search require --group. versions and delete take --group or read the lock.
  • glpkg config proxy:enable no longer switches packages to the proxy; use --source proxy (see Registry proxy).

Added

  • glpkg lock init and glpkg lock set.
  • --external for all ecosystems.
  • No silent forwarding: a GitLab group that does not host a package is an error, instead of an install of a same-named package from npmjs.
  • Dependencies of GitLab packages in group-hosted scopes are routed to the group automatically.
  • PyPI dependency-confusion guard: no pypi.org extra index when a requested name also exists on pypi.org.

Fixed

  • glpkg publish --dry-run no longer leaves package.json, pyproject.toml or *.csproj modified.

Known limitations

  • PyPI: if a GitLab package's name is not on pypi.org at install time, pypi.org stays an extra index, and pip picks the highest version across indexes.
  • NuGet: dotnet restores from every configured source, including nuget.org; glpkg cannot pin a package to one source.
  • npm: dependencies of external packages are not checked against GitLab-routed scopes.

Upgrading from 0.14:

glpkg lock init
glpkg lock set @your-org/a @your-org/b --group your-org
glpkg lock set typescript @types/node --external
glpkg install