Swift packages
Set up SwiftPM
Point SwiftPM at the ForgeRepo™ package registry and log in with your token.
Tell SwiftPM to use ForgeRepo™ as its package registry, then log in with your user name and your token as the password:
$ swift package-registry set --global https://packages.example.com/swift/ $ swift package-registry login https://packages.example.com/swift/ --username your-user-name --password "$REPO_TOKEN" --no-confirm Login successful. Credentials have been saved to netrc file. Registry configuration updated.
Captured by running these commands against a real ForgeRepo™.
--globalsets it for every package on your machine. Leave it out to set it for one package only.- The login is saved in
~/.netrcon Linux and in the keychain on a Mac. It needs https. - A package is named by its identity,
scope.name.apple.swift-logis github.com/apple/swift-log. - SwiftPM warns that a source archive is not signed. ForgeRepo™ does not sign archives. SwiftPM checks each one against the checksum packages.example.com gives it.
Name dependencies by identity in Package.swift, and in a product use the identity as the package name:
$ cat Package.swift // swift-tools-version:5.9 import PackageDescription let package = Package( name: "Shop", dependencies: [ .package(id: "apple.swift-log", from: "1.6.0") ], targets: [ .executableTarget(name: "Shop", dependencies: [ .product(name: "Logging", package: "apple.swift-log") ]) ] ) $ swift package resolve Computing version for apple.swift-log Computed apple.swift-log at 1.6.4 (1.41s) Fetching apple.swift-log warning: 'apple.swift-log': apple.swift-log version 1.6.4 source archive from https://packages.example.com/swift/ is not signed Fetched apple.swift-log from cache (0.06s) $ swift build 2>&1 | tail -2 [15/16] Linking Shop Build complete! (4.92s)
Captured by running these commands against a real ForgeRepo™.
Note
A dependency written as a GitHub url still goes to GitHub. Add --replace-scm-with-registry to swift package resolve or swift build, and SwiftPM asks packages.example.com for it instead.