Welcome to mirror list, hosted at ThFree Co, Russian Federation.

supported_functionality.md « package_registry « packages « user « doc - gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
blob: 3e8852da808cf0242a091d36ef182c2a577921c8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
---
stage: Package
group: Package Registry
info: To determine the technical writer assigned to the Stage/Group associated with this page, see https://about.gitlab.com/handbook/product/ux/technical-writing/#assignments
---

# Supported package functionality

The GitLab Package Registry supports different functionalities for each package type. This support includes publishing
and pulling packages, request forwarding, managing duplicates, and authentication.

## Publishing packages **(FREE ALL)**

Packages can be published to your project, group, or instance.

| Package type                                          | Project | Group | Instance |
|-------------------------------------------------------|---------|-------|----------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Y       | N     | N        |
| [Maven (with `gradle`)](../maven_repository/index.md) | Y       | N     | N        |
| [Maven (with `sbt`)](../maven_repository/index.md)    | N       | N     | N        |
| [npm](../npm_registry/index.md)                       | Y       | N     | N        |
| [NuGet](../nuget_repository/index.md)                 | Y       | N     | N        |
| [PyPI](../pypi_repository/index.md)                   | Y       | N     | N        |
| [Generic packages](../generic_packages/index.md)      | Y       | N     | N        |
| [Terraform](../terraform_module_registry/index.md)    | Y       | N     | N        |
| [Composer](../composer_repository/index.md)           | N       | Y     | N        |
| [Conan](../conan_repository/index.md)                 | Y       | N     | Y        |
| [Helm](../helm_repository/index.md)                   | Y       | N     | N        |
| [Debian](../debian_repository/index.md)               | Y       | N     | N        |
| [Go](../go_proxy/index.md)                            | Y       | N     | N        |
| [Ruby gems](../rubygems_registry/index.md)            | Y       | N     | N        |

## Pulling packages **(FREE ALL)**

Packages can be pulled from your project, group, or instance.

| Package type                                          | Project | Group | Instance |
|-------------------------------------------------------|---------|-------|----------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Y       | Y     | Y        |
| [Maven (with `gradle`)](../maven_repository/index.md) | Y       | Y     | Y        |
| [Maven (with `sbt`)](../maven_repository/index.md)    | Y       | Y     | Y        |
| [npm](../npm_registry/index.md)                       | Y       | Y     | Y        |
| [NuGet](../nuget_repository/index.md)                 | Y       | Y     | N        |
| [PyPI](../pypi_repository/index.md)                   | Y       | Y     | N        |
| [Generic packages](../generic_packages/index.md)      | Y       | N     | N        |
| [Terraform](../terraform_module_registry/index.md)    | N       | Y     | N        |
| [Composer](../composer_repository/index.md)           | Y       | Y     | N        |
| [Conan](../conan_repository/index.md)                 | Y       | N     | Y        |
| [Helm](../helm_repository/index.md)                   | Y       | N     | N        |
| [Debian](../debian_repository/index.md)               | Y       | N     | N        |
| [Go](../go_proxy/index.md)                            | Y       | N     | Y        |
| [Ruby gems](../rubygems_registry/index.md)            | Y       | N     | N        |

## Forwarding requests **(PREMIUM ALL)**

Requests for packages not found in your GitLab project are forwarded to the public registry. For example, Maven Central, npmjs, or PyPI.

| Package type                                          | Supports request forwarding |
|-------------------------------------------------------|-----------------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | [Yes (disabled by default)](../../../administration/settings/continuous_integration.md#maven-forwarding) |
| [Maven (with `gradle`)](../maven_repository/index.md) | [Yes (disabled by default)](../../../administration/settings/continuous_integration.md#maven-forwarding) |
| [Maven (with `sbt`)](../maven_repository/index.md)    | [Yes (disabled by default)](../../../administration/settings/continuous_integration.md#maven-forwarding) |
| [npm](../npm_registry/index.md)                       | [Yes](../../../administration/settings/continuous_integration.md#npm-forwarding) |
| [NuGet](../nuget_repository/index.md)                 | N                           |
| [PyPI](../pypi_repository/index.md)                   | [Yes](../../../administration/settings/continuous_integration.md#pypi-forwarding) |
| [Generic packages](../generic_packages/index.md)      | N                           |
| [Terraform](../terraform_module_registry/index.md)    | N                           |
| [Composer](../composer_repository/index.md)           | N                           |
| [Conan](../conan_repository/index.md)                 | N                           |
| [Helm](../helm_repository/index.md)                   | N                           |
| [Debian](../debian_repository/index.md)               | N                           |
| [Go](../go_proxy/index.md)                            | N                           |
| [Ruby gems](../rubygems_registry/index.md)            | N                           |

## Deleting packages

When package requests are forwarded to a public registry, deleting packages can
be a [dependency confusion vulnerability](https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610).

If a system tries to pull a deleted package, the request is forwarded to the public
registry. If a package with the same name and version is found in the public registry, that package
is pulled instead. There is a risk that the package pulled from the registry might not be
what is expected, and could even be malicious.

To reduce the associated security risks, before deleting a package you can:

- Verify the package is not being actively used.
- Disable request forwarding:
  - Instance administrators can disable forwarding in the [**Continuous Integration** section](../../../administration/settings/continuous_integration.md#package-registry-configuration) of the Admin Area.
  - Group owners can disable forwarding in the **Packages and Registries** section of the group settings.

## Importing packages from other repositories

You can use GitLab pipelines to import packages from other repositories, such as Maven Central or Artifactory with the [package importer tool](https://gitlab.com/gitlab-org/ci-cd/package-stage/pkgs_importer).

| Package type                                          | Importer available? |
|-------------------------------------------------------|---------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Y                   |
| [Maven (with `gradle`)](../maven_repository/index.md) | Y                   |
| [Maven (with `sbt`)](../maven_repository/index.md)    | Y                   |
| [npm](../npm_registry/index.md)                       | Y                   |
| [NuGet](../nuget_repository/index.md)                 | Y                   |
| [PyPI](../pypi_repository/index.md)                   | Y                   |
| [Generic packages](../generic_packages/index.md)      | N                   |
| [Terraform](../terraform_module_registry/index.md)    | N                   |
| [Composer](../composer_repository/index.md)           | N                   |
| [Conan](../conan_repository/index.md)                 | N                   |
| [Helm](../helm_repository/index.md)                   | N                   |
| [Debian](../debian_repository/index.md)               | N                   |
| [Go](../go_proxy/index.md)                            | N                   |
| [Ruby gems](../rubygems_registry/index.md)            | N                   |

## Allow or prevent duplicates **(FREE ALL)**

By default, the GitLab package registry either allows or prevents duplicates based on the default of that specific package manager format.

| Package type                                          | Duplicates allowed? |
|-------------------------------------------------------|---------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Y (configurable)    |
| [Maven (with `gradle`)](../maven_repository/index.md) | Y (configurable)    |
| [Maven (with `sbt`)](../maven_repository/index.md)    | Y (configurable)    |
| [npm](../npm_registry/index.md)                       | N                   |
| [NuGet](../nuget_repository/index.md)                 | Y                   |
| [PyPI](../pypi_repository/index.md)                   | N                   |
| [Generic packages](../generic_packages/index.md)      | Y (configurable)    |
| [Terraform](../terraform_module_registry/index.md)    | N                   |
| [Composer](../composer_repository/index.md)           | N                   |
| [Conan](../conan_repository/index.md)                 | N                   |
| [Helm](../helm_repository/index.md)                   | Y                   |
| [Debian](../debian_repository/index.md)               | Y                   |
| [Go](../go_proxy/index.md)                            | N                   |
| [Ruby gems](../rubygems_registry/index.md)            | Y                   |

## Authentication tokens **(FREE ALL)**

GitLab tokens are used to authenticate with the GitLab Package Registry.

The following tokens are supported:

| Package type                                          | Supported tokens                                                       |
|-------------------------------------------------------|------------------------------------------------------------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Personal access, job tokens, deploy (project or group), project access |
| [Maven (with `gradle`)](../maven_repository/index.md) | Personal access, job tokens, deploy (project or group), project access |
| [Maven (with `sbt`)](../maven_repository/index.md)    | Personal access, job tokens, deploy (project or group), project access |
| [npm](../npm_registry/index.md)                       | Personal access, job tokens, deploy (project or group), project access |
| [NuGet](../nuget_repository/index.md)                 | Personal access, job tokens, deploy (project or group), project access |
| [PyPI](../pypi_repository/index.md)                   | Personal access, job tokens, deploy (project or group), project access |
| [Generic packages](../generic_packages/index.md)      | Personal access, job tokens, deploy (project or group), project access |
| [Terraform](../terraform_module_registry/index.md)    | Personal access, job tokens, deploy (project or group), project access |
| [Composer](../composer_repository/index.md)           | Personal access, job tokens, deploy (project or group), project access |
| [Conan](../conan_repository/index.md)                 | Personal access, job tokens, project access                            |
| [Helm](../helm_repository/index.md)                   | Personal access, job tokens, deploy (project or group)                 |
| [Debian](../debian_repository/index.md)               | Personal access, job tokens, deploy (project or group)                 |
| [Go](../go_proxy/index.md)                            | Personal access, job tokens, project access                            |
| [Ruby gems](../rubygems_registry/index.md)            | Personal access, job tokens, deploy (project or group)                 |

## Authentication protocols **(FREE ALL)**

The following authentication protocols are supported:

| Package type                                          | Supported auth protocols                                    |
|-------------------------------------------------------|-------------------------------------------------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | Headers, Basic auth ([pulling](#pulling-packages) only) (1) |
| [Maven (with `gradle`)](../maven_repository/index.md) | Headers, Basic auth ([pulling](#pulling-packages) only) (1) |
| [Maven (with `sbt`)](../maven_repository/index.md)    | Basic auth (1)                                              |
| [npm](../npm_registry/index.md)                       | OAuth                                                       |
| [NuGet](../nuget_repository/index.md)                 | Basic auth                                                  |
| [PyPI](../pypi_repository/index.md)                   | Basic auth                                                  |
| [Generic packages](../generic_packages/index.md)      | Basic auth                                                  |
| [Terraform](../terraform_module_registry/index.md)    | Token                                                       |
| [Composer](../composer_repository/index.md)           | OAuth                                                       |
| [Conan](../conan_repository/index.md)                 | OAuth, Basic auth                                           |
| [Helm](../helm_repository/index.md)                   | Basic auth                                                  |
| [Debian](../debian_repository/index.md)               | Basic auth                                                  |
| [Go](../go_proxy/index.md)                            | Basic auth                                                  |
| [Ruby gems](../rubygems_registry/index.md)            | Token                                                       |

1. Basic authentication for Maven packages [introduced](https://gitlab.com/gitlab-org/gitlab/-/issues/212854) in GitLab 16.0.

## Supported hash types **(FREE ALL)**

Hash values are used to ensure you are using the correct package. You can view these values in the user interface or with the [API](../../../api/packages.md).

The Package Registry supports the following hash types:

| Package type                                          | Supported hashes                 |
|-------------------------------------------------------|----------------------------------|
| [Maven (with `mvn`)](../maven_repository/index.md)    | MD5, SHA1                        |
| [Maven (with `gradle`)](../maven_repository/index.md) | MD5, SHA1                        |
| [Maven (with `sbt`)](../maven_repository/index.md)    | MD5, SHA1                        |
| [npm](../npm_registry/index.md)                       | SHA1                             |
| [NuGet](../nuget_repository/index.md)                 | not applicable                   |
| [PyPI](../pypi_repository/index.md)                   | MD5, SHA256                      |
| [Generic packages](../generic_packages/index.md)      | SHA256                           |
| [Composer](../composer_repository/index.md)           | not applicable                   |
| [Conan](../conan_repository/index.md)                 | MD5, SHA1                        |
| [Helm](../helm_repository/index.md)                   | not applicable                   |
| [Debian](../debian_repository/index.md)               | MD5, SHA1, SHA256                |
| [Go](../go_proxy/index.md)                            | MD5, SHA1, SHA256                |
| [Ruby gems](../rubygems_registry/index.md)            | MD5, SHA1, SHA256 (gemspec only) |