Skip to content

Private npm package registries

Enable npm in a Ravenstash repository to publish scoped or unscoped packages and install private JavaScript, TypeScript, Node.js, and WebAssembly packages through an authenticated npm-compatible registry.

Ravenstash serves npm-compatible package metadata, version metadata, and tarballs. It supports authenticated publication and registry configuration for npm-compatible clients. The rvs npm wrapper provides the shortest supported workflow without persisting a registry token in .npmrc.

When one Ravenstash repository supports several formats, npm packages, URLs, usage, and mirror settings remain separate from its PyPI and Maven content.

When the repository connects a npmjs.org mirror or another private repository, its own packages come first and the first upstream that has a name supplies all of its versions. See How upstream package resolution works.

To keep names you own, such as @acme/*, away from public registries, or to combine versions from several sources, add package resolution rules on the repository’s Rules tab.