Repository navigation
Conversation
With a repox-url other than https://repox.jfrog.io, config-npm also sets replace-registry-host=repox.jfrog.io. Lockfiles generated against SaaS Repox then download their tarballs from repox-url instead of hitting SaaS without a token for that host.
Code Review ✅ Approved 2 closed / 2 findings🔴 High risk · Risk could not be assessed, so high risk was applied as a precaution. Rewrites SaaS-pinned npm lockfile URLs to the Edge host instead of setting ✅ 2 closed✅ Bug: Bare-host replace-registry-host doubles the /artifactory/api/npm/npm path
✅ Edge Case: Setting a hostname turns off the default registry.npmjs.org rewrite
Review coverage🧪 Functional validation 0 of 4 objectives covered 📋 Rules No rules evaluated Cross-repo coverage 2 repositories selected 🤖 Auto-approval Not enabled · Set up Implementation Status ◻️ 0 of 4 objectives covered◻️ BUILD-12160 - 0 of 4 objectives coveredThis PR adds NuGet configuration to resolve packages through Repox, which is unrelated to the pilot objectives for sonar-dummy or SaaS-only deploys. Other objectives on this issue, possibly covered elsewhere:
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
…istry-host npm 10 builds a host-only replace-registry-host URL from the full registry URL plus the original path, which doubles /artifactory/api/npm/npm. A hostname also turns off the default registry.npmjs.org rewrite. With an Edge repox-url, config-npm now rewrites the SaaS Repox URLs of the workspace lockfiles outside node_modules to repox-url, and leaves replace-registry-host at its default.
|
|
Closing: the lockfile is fixed at the source instead. SonarJS now records its tarballs on |



Part of BUILD-12160
Summary
npm lockfiles record absolute
resolvedURLs onhttps://repox.jfrog.io. With an Edgerepox-url,config-npmonly authenticates the Edge host, sonpm cistill downloads every tarball from SaaS without a token and gets a 401.repox-urlother thanhttps://repox.jfrog.io,config-npmrewrites everyhttps://repox.jfrog.io/artifactory/api/npm/URL in the workspacepackage-lock.jsonandnpm-shrinkwrap.jsonfiles (outsidenode_modules) torepox-url. The rewrite is not committed. The SaaS default is unchanged.replace-registry-hoststays at npm's default, so lockfile URLs onregistry.npmjs.orgstill go through the configured registry. Setting it torepox.jfrog.ioinstead would double/artifactory/api/npm/npmon npm 10, whose Arborist builds${registry}${resolved.pathname}, and would turn off the npmjs rewrite.config-npmsection.Test plan
spec/config-npm_spec.sh: 16 examples, 0 failures. The newrewrite_lockfiles()cases cover root, nested andnpm-shrinkwrap.jsonlockfiles, skipnode_modules, keepregistry.npmjs.orgURLs, and leave SaaS untouched.https://repox.jfrog.io/artifactory/api/npm/npm/is-number/-/is-number-7.0.0.tgzentry and onehttps://registry.npmjs.org/is-odd/-/is-odd-3.0.1.tgzentry, rewritten byrewrite_lockfileswithARTIFACTORY_URL=http://127.0.0.1:9/artifactory, registryhttp://127.0.0.1:9/artifactory/api/npm/npm/:npm cirequestshttp://127.0.0.1:9/artifactory/api/npm/npm/is-number/-/is-number-7.0.0.tgzandhttp://127.0.0.1:9/artifactory/api/npm/npm/is-odd/-/is-odd-3.0.1.tgz.populate_npm_cacheonconfig-npmfrom this branch with the Edgerepox-url.