In order for FOSSA to reach private scoped packages on NPM, you must configure auth using the data found in
.npmrc after running
To configure authentication, your FOSSA admin must edit
config.env with one of two authentication methods. Check your
.npmrc to see which of the two formats below you use.
For newer registries or NPM Enterprise, FOSSA supports tokens for authentication. If you are using this method, you can find a line in your
.npmrc formatted as
AUTH_TOKEN and add the following config:
Many systems still use legacy authentication, especially if you are using a private registry like Artifactory. Look for
username in your
fetchers__npm__auth__email fetchers__npm__auth__token # _auth parameter in .npmrc fetchers__npm__auth__username
After configuring, your FOSSA admin must run
If you are using a private registry like Artifactory for you NPM code, your FOSSA admin can specify a private registry URL:
Often private registries require authentication, which is covered above under Private Packages.
See here for FOSSA's NPM Enterprise integration.