npm, pnpm and Yarn
Install packages with npm
npm install and npm ci work the same way they always have.
Once npm points at packages.example.com, install the way you always do.
$ npm install express lodash added 69 packages, and audited 70 packages in 2s found 0 vulnerabilities $ npm ls --depth=0 storefront@1.0.0 /work/storefront +-- express@4.22.3 `-- lodash@4.18.1
Captured by running these commands against a real ForgeRepo™.
Lock files and npm ci
The resolved addresses in package-lock.json point at packages.example.com. npm ci installs exactly what the lock file says, which is what a pipeline should run.
$ grep -m 2 '"resolved"' package-lock.json "resolved": "https://packages.example.com/accepts/-/accepts-1.3.8.tgz", "resolved": "https://packages.example.com/array-flatten/-/array-flatten-1.1.1.tgz", $ npm ci added 69 packages, and audited 70 packages in 848ms found 0 vulnerabilities
Captured by running these commands against a real ForgeRepo™.
Note
A lock file made before you switched may still say registry.npmjs.org. That is fine: npm 7 and later swap that address for the registry you set, so npm ci still installs through packages.example.com.
npm audit
npm audit asks packages.example.com about the packages you installed. The answer comes from the advisories ForgeRepo™ knows about.
$ npm audit found 0 vulnerabilities
Captured by running these commands against a real ForgeRepo™.