npm, pnpm and Yarn
Set up npm
Point npm at packages.example.com for one project or for your whole machine.
npm reads its settings from a file called .npmrc. Put one in the root of your project so everyone who clones it uses packages.example.com.
.npmrc
registry=https://packages.example.com/
//packages.example.com/:_authToken=${NPM_TOKEN}
The first line sends every install to packages.example.com. The second line gives npm your token, read from the NPM_TOKEN environment variable, so the file is safe to commit.
Careful
A line starting with // is not a comment. In .npmrc, // starts a web address with the https: left off, and it says which registry the setting belongs to. So //packages.example.com/:_authToken=... is the token for packages.example.com, and //google.com/:_authToken=... would be a token for google.com. Delete a // line and your installs stop working.
Comments in .npmrc start with # or ;:
.npmrc
# this is a comment, and so is the next line
; both of these are ignored
# the line below is a setting for one registry host, not a comment
//packages.example.com/:_authToken=${NPM_TOKEN}
$ cat .npmrc registry=https://packages.example.com/ //packages.example.com/:_authToken=${NPM_TOKEN} $ npm config get registry https://packages.example.com/ $ npm whoami your-user-name $ npm ping npm notice PING https://packages.example.com/ npm notice PONG 33ms
Captured by running these commands against a real ForgeRepo™.
npm whoami printing your user name means the token works. npm ping answering PONG means npm can reach packages.example.com.
For every project on your machine
npm config set registry https://packages.example.com/
npm config set //packages.example.com/:_authToken "$NPM_TOKEN"
This writes to ~/.npmrc in your home folder. A project .npmrc still wins when both exist.
Tip
Using a scope only for your company packages? You can send just the scope to packages.example.com with @acme:registry=https://packages.example.com/. Sending everything is safer, because then every public package is checked too.