GitHub Packages 29 runs an npm registry 2,036 at https://npm.pkg.github.com 29 . A package's scope must be the account or organization that owns it, so an organization called booknest publishes @booknest/price-format. The repository field in package.json links the package to a repository, whose access rules it then inherits: whoever can read the repository can install the package.
@booknest:registry=https://npm.pkg.github.com
//npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN}npm expands ${NODE_AUTH_TOKEN} from the environment, so the file can be committed without the token. Outside GitHub Actions 29 , this registry accepts only a classic personal access token with read:packages (and write:packages to publish), not a fine-grained one. Inside a workflow, the built-in GITHUB_TOKEN publishes for the workflow's own repository, the path GitHub takes. This book's account has no organization and no classic token, so this setup is shown from GitHub 29 's documentation.
| Verdaccio | GitHub Packages | npmjs private packages | |
|---|---|---|---|
| Hosting | You run it | GitHub | npm, Inc. |
| Price | Free (MIT) | Free for public; quota for private | Paid plan per user |
| Access control | Its own users | Repository permissions | npm teams |
| Caches public npm locally | Yes | No | No |