Publishing
Publish an npm package
Publish company packages under the names your admin reserved.
You can publish when both of these are true:
- Your role is publisher, approver or admin.
- The name is reserved for your company, like everything under
@acme/. Reserving a name stops anyone from pulling a public package with the same name, which is how dependency confusion attacks work.
Add publishConfig so the package can never go to the public registry by mistake:
$ cat package.json { "name": "@acme/widgets", "version": "1.1.0", "description": "Shared UI widgets", "main": "index.js", "license": "MIT", "publishConfig": { "registry": "https://packages.example.com/" } } $ npm publish ... npm notice 21B index.js npm notice 205B package.json npm notice Tarball Details npm notice name: @acme/widgets npm notice version: 1.1.0 npm notice filename: acme-widgets-1.1.0.tgz npm notice package size: 286 B npm notice unpacked size: 226 B npm notice shasum: 5ea64ab60dfee1406a44ea1f33d304538ced8fe1 npm notice integrity: sha512-Dg4xaZ8I5VGhO[...]qlB3og57SxGhw== npm notice total files: 2 npm notice npm notice Publishing to https://packages.example.com/ with tag latest and default access + @acme/widgets@1.1.0
Captured by running these commands against a real ForgeRepo™.
Note
In whitelist mode your own packages still need an allow rule before anyone can install them. Ask an approver to add one for your scope, like @acme/*.
If your role cannot publish
$ npm publish npm error code E403 npm error 403 403 Forbidden - PUT https://packages.example.com/@acme%2fwidgets - your-user-name cannot publish here, it needs the publisher, approver or admin role npm error 403 In most cases, you or one of your dependencies are requesting npm error 403 a package version that is forbidden by your security policy, or npm error 403 on a server you do not have access to. npm error A complete log of this run can be found in: /root/.npm/_logs/2026-09-17T15_03_25_298Z-debug-0.log
Captured by running these commands against a real ForgeRepo™.
| Error says | What to do |
|---|---|
| cannot publish here, it needs the publisher, approver or admin role | Ask an admin to change your role, or publish from a pipeline token owned by a publisher account. |
| is not a reserved name | Ask an admin to reserve the name or scope. |
| is already published, and a published version never changes | Bump the version in package.json and publish again. |