Skip to content

Support private registry #363

Description

@dohaicuong

I've encounter problem when using changesets/action when I'm using the private registry that is not npm.

Upon looking into it the problem seems to coming from the bellow line where it only check for npm registry name.

const authLine = userNpmrcContent.split("\n").find((line) => {
  // check based on https://github.com/npm/cli/blob/8f8f71e4dd5ee66b3b17888faad5a7bf6c657eed/test/lib/adduser.js#L103-L105
  return /^\s*\/\/registry\.npmjs\.org\/:[_-]authToken=/i.test(line);
});

However, beside npm registry, we also have github registry and custom domain gitlab registry.

// npm
//registry.npmjs.org/:_authToken

// github
//npm.pkg.github.com/:_authToken=TOKEN

// custom domain gitlab registry
//code.org.com/packages/npm/:_authToken=

Hence I'm making the change here to address for this problem.
#362

Thank you the team for your work on maintaining this tool!

Activity

  1. dikaso commented on Nov 13, 2024

    @dikaso

    We need this.

  2. vsnig commented on May 28, 2025

    @vsnig

    I found a workaround, see this
    They set the registry in the script
    And authenticate in the workflow
    Just tried and it worked

  3. refinist commented on Jun 30, 2025

    @refinist

    I found a workaround, see this They set the registry in the script And authenticate in the workflow Just tried and it worked

    Just configure workflow here, no need to configure scripts. Mainly because changeset will execute npm info to find packages

  4. belfz commented on Oct 17, 2025

    @belfz

    That workaround (change in the workflow) didn't work for me, the changesets action seems to still overwrite the registry URL. Any chance I can somehow force use the npm.pkg.github.com as a registry?

  5. belfz commented on Oct 17, 2025

    @belfz

    Update - I found a way to make it work, see an example "release" workflow:

    name: Release
    
    on:
      push:
        branches: [main]
    
    permissions:
      contents: write
      packages: write
      pull-requests: write
    
    jobs:
      release:
        runs-on: ubuntu-latest
        steps:
          - uses: actions/checkout@v4
            with:
              fetch-depth: 0
    
          - name: Repo setup
            uses: ./.github/actions/repo-setup
            with:
              node-version: '18'
              pnpm-version: '10.10.0'
    
          - name: Configure npm auth (GitHub Packages)
            shell: bash
            env:
              GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
            run: |
              echo "@your-organization:registry=https://npm.pkg.github.com" > ~/.npmrc
              echo "//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}" >> ~/.npmrc
              echo "always-auth=true" >> ~/.npmrc
    
          - name: Build all (if present)
            run: pnpm -r --if-present build
    
          - name: Version & publish with Changesets
            uses: changesets/action@v1
            with:
              version: pnpm changeset version
              publish: pnpm changeset publish
            env:
              GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

    The crucial step is Configure npm auth (GitHub Packages) - it creates an .npmrc on the fly with both your custom registry and the auth token settings. The changesets action's code then falls into this case, and later appends this line to the found .npmrc, but it's not a problem - your package(s) will be published to your private registry only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions