Edit icon Edit This Page

Managing npm Packages

This page shows what you can do with a package after you have published it: move dist-tags, deprecate a version, unpublish it, search a registry, audit an installation and log out. The commands are npm’s. The last section says which of them the other package managers have.

The examples assume that npm is configured for your registry as described in Authenticating with npm, with @foo routed to it. <registry-url> stands for https://<your-repsy-host>/<repo-name>/. Every command that changes a registry needs a credential with write access: a user account or a Read/Write deploy token. A Read Only token is refused with E401.

Dist-tags

A dist-tag is a name for a version. npm install @foo/<package-name> installs the version that latest points to, and npm install @foo/<package-name>@beta the version that beta points to.

npm dist-tag ls @foo/<package-name>
npm dist-tag add @foo/<package-name>@1.1.0 next
npm dist-tag rm @foo/<package-name> next

npm publish --tag beta publishes a version and sets the tag beta to it instead of latest. How Repsy sets the tags:

  • The first version of a package always gets latest, also when you publish it with --tag beta. Both beta and latest then point to it.
  • A later publish without --tag moves latest to the new version and leaves the other tags where they are.
  • latest cannot be removed: Repsy answers 400 Bad Request to npm dist-tag rm @foo/<package-name> latest. Move it to another version with dist-tag add instead.
  • Repsy refuses a tag for a version that does not exist (400 Bad Request).
  • npm itself refuses a tag name that is a valid version range, such as x.

The web UI shows the tags of a package on the page of its versions.

Deprecating a Version

A deprecated version stays installable, but package managers warn about it. Give a message, and a version or a version range:

npm deprecate @foo/<package-name>@1.0.0 "use 1.1.0 instead"

Deprecate again with an empty message to clear the deprecation:

npm deprecate @foo/<package-name>@1.0.0 ""

Repsy keeps the message on the version and serves it to every client. What a client does with it differs:

  • npm prints a warning with the message when it installs the version.
  • Yarn classic prints a warning with the message.
  • pnpm prints deprecated <package-name>@<version> without the message. pnpm 12 also chooses the newest version that is not deprecated when it resolves a version range. An exact version is still installed.
  • Yarn Berry and Bun print nothing when they install a deprecated version. yarn npm info <package-name>@<version> -f deprecated and bun info <package-name>@<version> deprecated show the message.

Unpublishing a Version

npm unpublish @foo/<package-name>@1.1.0

Repsy deletes the version and its tarball. If it was the version latest pointed to, latest moves to a remaining version. To delete a whole package with all its versions, or its only version, npm asks for --force:

npm unpublish @foo/<package-name> --force

When the last version of a package goes, the package is gone from the registry. npm warns that a version cannot be published again for 24 hours after that. That is a rule of npmjs.org, and Repsy does not enforce it.

Unpublishing needs write access to the registry, like publishing. You can also delete a package or a version in the web UI, as an administrator.

Searching a Registry

npm search --registry https://<your-repsy-host>/<repo-name>/ <text>

The search looks only at the packages of that registry, never at other repositories or npmjs.org, and it works on the latest version of each package. On a private registry it needs a credential. You can use these qualifiers in the text:

QualifierFinds
scope:fooPackages of the scope @foo
keywords:pad,stringPackages that have the keywords
author:<name> and maintainer:<name>Packages by author or maintainer
is:deprecated, is:unstable and is:insecurePackages whose latest version is deprecated, is below 1.0.0, or has vulnerabilities found by a scan (see the next section). not: turns each filter around, for example not:deprecated.
boost-exact:falseTakes the bonus for an exact name match off the ranking

A search text that consists of qualifiers Repsy cannot filter on finds no package.

Auditing an Installation

npm audit, pnpm audit, yarn npm audit (Yarn Berry) and bun audit ask the registry for the vulnerabilities of the versions in your dependency tree:

npm audit --registry https://<your-repsy-host>/<repo-name>/

Repsy answers from the scans of vulnerability scanning, so this works only when scanning is enabled on your instance and for the repository, see Vulnerability Scanning in the Configuration Reference. Repsy reports:

  • only the versions the audit asks about and that a scan of this repository found a vulnerability in. It uses the latest completed scan of each version.
  • nothing, with the exit code 0, when scanning is off (the scanner is disabled, or scanning is turned off for the repository, even if an earlier scan found something), and for a version that has not been scanned yet. found 0 vulnerabilities therefore does not mean that a package is free of vulnerabilities.

An audit request may hold up to 20,000 packages and 8 MiB (after decompression). Yarn classic (yarn audit) always asks registry.yarnpkg.com and never reaches Repsy.

Logging Out

npm logout --registry https://<your-repsy-host>/<repo-name>/ revokes the login token that npm login saved and removes it from .npmrc, see Authenticating with npm. It does not work for a deploy token.

What the Other Package Managers Have

npmYarn classicYarn BerrypnpmBun
Publishnpm publishyarn publishyarn npm publishpnpm publishbun publish
Dist-tagsnpm dist-tagyarn tagyarn npm tagpnpm dist-tagPublish --tag, no command
Deprecatenpm deprecateNo commandNo commandpnpm deprecate and pnpm undeprecateNo command
Unpublishnpm unpublishNo commandNo commandpnpm unpublishNo command
whoaminpm whoamiNo commandyarn npm whoamipnpm whoamibun pm whoami
Searchnpm searchNo commandNo commandpnpm searchNo command
Auditnpm auditNever reaches Repsyyarn npm auditpnpm auditbun audit
Log outnpm logoutyarn logout, not testedyarn npm logout, not testedpnpm logoutNo command

Where a package manager has no command, use npm for the task with the same .npmrc.

Was this page helpful?