Repository navigation
PACKAGE_MANAGEMENT
Robert Trenaman edited this page Apr 28, 2026
·
1 revision
This guide covers how to upload packages to various registries using GitHub Commander.
GitHub Commander supports uploading packages to:
- npm (JavaScript/Node.js)
- PyPI (Python)
- Cargo (Rust)
- And other package registries
The Packages Panel includes:
- Package Type Selection - Choose the registry (npm, pip, cargo)
- Folder Selection - Browse to package folder
- Registry URL - Configure registry endpoint
- Upload Button - Initiate package upload
- Status Display - Show upload progress and results
Before uploading to npm:
- Have an npm account
- Be logged in to npm locally or have authentication token
- Package must have valid
package.json - Package name must be unique (or you must own it)
- Select a repository
- Go to the Packages Panel
- Select "npm" as the package type
- Click "Browse..." to select the package folder
- Enter the npm registry URL (default: https://registry.npmjs.org)
- Click "Upload Package"
- The package will be published to npm
Valid npm packages must have:
-
package.jsonwith:-
name- Unique package name -
version- Semantic version -
description- Package description -
main- Entry point file -
keywords- Search terms (optional) -
author- Author information (optional) -
license- License information (optional)
-
npm authentication requires:
- Local npm login:
npm login - Or authentication token in
.npmrc - Token must have publish permissions
To use a private npm registry:
- Enter custom registry URL
- Configure authentication for that registry
- Ensure you have publish permissions
Before uploading to PyPI:
- Have a PyPI account
- Enable 2FA on PyPI (required)
- Generate API token for uploads
- Package must have valid structure
- Select a repository
- Go to the Packages Panel
- Select "pip" as the package type
- Click "Browse..." to select the package folder
- Enter the PyPI repository URL (default: https://pypi.org/simple)
- Click "Upload Package"
- The package will be published to PyPI
Valid Python packages must have:
-
setup.pyorpyproject.toml -
README.mdorREADME.rst -
LICENSEfile - Proper package structure:
package-name/ ├── setup.py ├── README.md ├── LICENSE └── package_name/ ├── __init__.py └── module.py
PyPI authentication requires:
- API token from PyPI account settings
- Token stored in
~/.pypircor environment variable - Or username/password (deprecated, use token instead)
To test uploads before production:
- Use Test PyPI URL: https://test.pypi.org/simple
- Separate account for Test PyPI
- Verify package works before publishing to PyPI
Before uploading to crates.io:
- Have a crates.io account
- Generate API token
- Package must have valid
Cargo.toml
- Select a repository
- Go to the Packages Panel
- Select "cargo" as the package type
- Click "Browse..." to select the package folder
- Click "Upload Package"
- The package will be published to crates.io
Valid Rust packages must have:
-
Cargo.tomlwith:-
name- Unique package name -
version- Semantic version -
authors- Author list -
description- Package description -
license- License information -
repository- Repository URL (optional)
-
-
src/directory withmain.rsorlib.rs
Cargo authentication requires:
- API token from crates.io
- Token stored in
~/.cargo/credentials - Login with
cargo login
- npm: https://registry.npmjs.org
- PyPI: https://pypi.org/simple
- Test PyPI: https://test.pypi.org/simple
- crates.io: https://crates.io
To use a custom registry:
- Select the package type
- Enter custom registry URL
- Configure authentication for that registry
- Ensure you have publish permissions
For private registries:
- Obtain registry URL from your organization
- Configure authentication credentials
- Set registry URL in the panel
- Upload as normal
Follow semantic versioning (SemVer):
- MAJOR.MINOR.PATCH (e.g., 1.2.3)
- Increment MAJOR for incompatible changes
- Increment MINOR for new features (backwards compatible)
- Increment PATCH for bug fixes (backwards compatible)
Use pre-release identifiers:
1.0.0-alpha1.0.0-beta.11.0.0-rc.1
If package name exists:
- You must own the package
- Or use a different name
- Or use scoped packages (npm):
@username/package-name
Common causes:
- Invalid authentication
- Package name already exists
- Invalid package structure
- Network issues
Solutions:
- Verify authentication credentials
- Check package name availability
- Validate package structure
- Ensure internet connection
Solutions:
- Use a different package name
- Or if you own it, update version
- For npm, use scoped packages
Solutions:
- Verify required files exist
- Check configuration file syntax
- Ensure proper directory structure
- Validate with registry tools locally
Solutions:
- Verify API token is valid
- Check token permissions
- Ensure token is for correct registry
- Regenerate token if necessary
- Test package locally
- Run all tests
- Update documentation
- Verify version number
- Check CHANGELOG
- Write comprehensive documentation
- Include examples
- Add tests
- Use semantic versioning
- Keep dependencies updated
- Respond to issues and PRs
- Don't commit secrets
- Use environment variables
- Keep dependencies secure
- Review third-party code
- Use vulnerability scanners
After managing packages, explore:
- Release Management - Create GitHub releases
- Git Operations - Version control your packages