Use this API to interact with the npm package manager client.
This API is used by the npm package manager client and is not meant for manual consumption.
These endpoints do not adhere to the standard API authentication methods. See the npm package registry documentation for details on which headers and token types are supported. Undocumented authentication methods might be removed in the future.
NPM registry bulk advisory endpoint
POST /api/v4/groups/{id}/-/packages/npm/-/npm/v1/security/advisories/bulk
This feature was introduced in GitLab 15.6
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry quick audit endpoint
POST /api/v4/groups/{id}/-/packages/npm/-/npm/v1/security/audits/quick
This feature was introduced in GitLab 15.6
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Get all tags for a given NPM package
GET /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Create or Update the given tag for the given NPM package and version
PUT /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Deletes the given tag
DELETE /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry metadata endpoint
GET /api/v4/groups/{id}/-/packages/npm/{package_name}
This feature was introduced in GitLab 11.8
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name Example: mypackage |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | APIEntities |
302 | Found (redirect) | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry bulk advisory endpoint
POST /api/v4/packages/npm/-/npm/v1/security/advisories/bulk
This feature was introduced in GitLab 15.6
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry quick audit endpoint
POST /api/v4/packages/npm/-/npm/v1/security/audits/quick
This feature was introduced in GitLab 15.6
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Get all tags for a given NPM package
GET /api/v4/packages/npm/-/package/{package_name}/dist-tags
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
package_Path, | String | Package name |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Create or Update the given tag for the given NPM package and version
PUT /api/v4/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Deletes the given tag
DELETE /api/v4/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry metadata endpoint
GET /api/v4/packages/npm/{package_name}
This feature was introduced in GitLab 11.8
Parameters
| Name | Type | Description |
|---|---|---|
package_Path, | String | Package name Example: mypackage |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | APIEntities |
302 | Found (redirect) | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry bulk advisory endpoint
POST /api/v4/projects/{id}/packages/npm/-/npm/v1/security/advisories/bulk
This feature was introduced in GitLab 15.6
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry quick audit endpoint
POST /api/v4/projects/{id}/packages/npm/-/npm/v1/security/audits/quick
This feature was introduced in GitLab 15.6
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | — |
307 | Temporary Redirect | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Get all tags for a given NPM package
GET /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Create or Update the given tag for the given NPM package and version
PUT /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Deletes the given tag
DELETE /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags/{tag}
This feature was introduced in GitLab 12.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
tagPath, | String | Package dist- |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
NPM registry metadata endpoint
GET /api/v4/projects/{id}/packages/npm/{package_name}
This feature was introduced in GitLab 11.8
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name Example: mypackage |
Responses
| Code | Description | Schema |
|---|---|---|
200 | Ok | APIEntities |
302 | Found (redirect) | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Create or deprecate an NPM package
PUT /api/v4/projects/{id}/packages/npm/{package_name}
Creates or deprecates an NPM package for a specified project. Deprecate support was added in GitLab 16.0.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
Request body (multipart/form-data)
| Property | Type | Description |
|---|---|---|
fileRequired | String (binary) | The package file to be published (generated by Multipart middleware) |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
401 | Unauthorized | — |
403 | Forbidden | — |
404 | Not Found | — |
Download the NPM tarball
GET /api/v4/projects/{id}/packages/npm/{package_name}/-/{file_name}
This feature was introduced in GitLab 11.8
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
package_Path, | String | Package name |
file_Path, | String | Package file name |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
403 | Forbidden | — |
404 | Not Found | — |
Schemas
Objects returned by the operations above and objects nested in their request bodies.
APIEntitiesNpmPackage
| Property | Type | Description |
|---|---|---|
dist- | Object | Example:{"latest": |
name | String | Example:my_ |
versions | Object | Example:{"1. |
APIEntitiesNpmPackageTag
| Property | Type | Description |
|---|---|---|
dist_ | Object | Example:{"latest": |