Verdaccio: A Lightweight Private npm Registry and Cache
Verdaccio is a private npm registry you can run in minutes. It does two jobs:
- Hosts your private packages, so internal libraries can be installed with
npm installwithout publishing them publicly - Caches public packages from npmjs.org, so installs are faster and keep working when the public registry is slow or unreachable
It is used by projects like Babel, pnpm, Angular CLI, Docusaurus, and create-react-app, largely for end-to-end testing of package publishing.
Features
- Zero configuration to start
- Uplinks: proxy and cache one or more upstream registries, chained in order
- Package overrides: publish a patched version of a public package under the same name for internal use
- Access control per package scope
- Plugins for authentication (such as LDAP) and storage (such as S3 and Google Cloud Storage)
- A web UI to browse packages
Using it
npm install -g verdaccio
verdaccio # serves on http://localhost:4873
npm set registry http://localhost:4873/
npm adduser --registry http://localhost:4873/
npm publish --registry http://localhost:4873/
Or run the official verdaccio/verdaccio Docker image with a persistent volume for storage, and put it behind a reverse proxy with HTTPS for team use. Helm charts are available for Kubernetes.
Supply chain angle
A caching registry also gives you a controlled point for dependencies: packages you have already installed stay available even if an upstream version is unpublished or a registry has an outage. It is one piece of a broader software supply chain security approach.
For container images, the equivalent is a self-hosted container registry.
License
MIT (code).