Skip to content

[BUG] corepack not use COREPACK_NPM_REGISTRY install of tarball #792

Description

@kuolemax

When the COREPACK_NPM_REGISTRY environment variable is set, the tarball mirror URL is always used instead of the one set in COREPACK_NPM_REGISTRY.

This is likely because the URL in line 243 of installVersion is overwritten with the tarball address, but the replace function in line 249 still replaces it with DEFAULT_NPM_REGISTRY_URL.

Activity

  1. Yash121l commented on Sep 15, 2026

    @Yash121l

    I looked at this. The replace on line 249 is harmless, the arguments run the other way. The real gap is that it only rewrites tarball URLs that start with https://registry.npmjs.org, so when the registry in COREPACK_NPM_REGISTRY advertises dist.tarball on another host (the upstream it mirrors, a CDN), the download goes there instead, and without the token since httpUtils.fetch only attaches it for the configured origin. I'll open a PR that resolves the tarball path against the configured registry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions