GitHub Packages

GitHub Packages and Organization Scopes

GitHub Packages 29 runs an npm registry 2,036 at https://npm.pkg.github.com 29 . A package's scope must be the account or organization that owns it, so an organization called booknest publishes @booknest/price-format. The repository field in package.json links the package to a repository, whose access rules it then inherits: whoever can read the repository can install the package.

Project .npmrc for an organization scope on GitHub Packages (not run here)Shell
@booknest:registry=https://npm.pkg.github.com
//npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN}

npm expands ${NODE_AUTH_TOKEN} from the environment, so the file can be committed without the token. Outside GitHub Actions 29 , this registry accepts only a classic personal access token with read:packages (and write:packages to publish), not a fine-grained one. Inside a workflow, the built-in GITHUB_TOKEN publishes for the workflow's own repository, the path GitHub takes. This book's account has no organization and no classic token, so this setup is shown from GitHub 29 's documentation.

Three ways to host private npm packages
Verdaccio GitHub Packages npmjs private packages
Hosting You run it GitHub npm, Inc.
Price Free (MIT) Free for public; quota for private Paid plan per user
Access control Its own users Repository permissions npm teams
Caches public npm locally Yes No No