Repository settings live in DESCRIPTION, and the lockfile records where each selected package comes from. Every project has one base repository and can include additional repositories and Git sources.
Repository changes update rpx.lock. Run rpx sync afterward to apply them to the installed environment.
Base repository
rpx starts with the CRAN mirror at https://rrepo.dev/upstream/cran as its primary package source. You can replace it for a project, for example to use CRAN directly:
rpx repo base set https://cloud.r-project.org
This stores the selected URL in Config/rpx/base-repository in DESCRIPTION.
Restore the built-in repository with:
rpx repo base reset
Additional repositories
Add another collection of packages alongside the base, such as your team's private repository:
rpx repo additional add https://rrepo.dev/my-team/packages
Additional repositories are stored in Additional_repositories in DESCRIPTION. Remove one with:
rpx repo additional remove https://rrepo.dev/my-team/packages
Git packages
Git repositories can supply packages outside a package registry. Git must be installed and available on PATH.
rpx repo remote add github::owner/repository@main
Remotes are stored in the Remotes field in DESCRIPTION. rpx supports GitHub, GitLab, Bitbucket, and generic Git URLs. You can select a branch or tag after @, and a package subdirectory after the repository name. For example, github::owner/repository/subdir@v1 selects a package in subdir at tag v1.
When resolving dependencies, rpx records the selected Git commit in rpx.lock, so later installations use that commit even if the branch moves.
Remove a remote with:
rpx repo remote remove github::owner/repository@main
HTTPS authentication uses your configured Git credential helpers. SSH authentication uses the SSH agent.
Private repositories
Use the repository URL and API key supplied by your provider. When authentication is required, interactive rpx prompts for the key and stores it in the operating system keyring. Non-interactive runs need a usable key stored beforehand.
Credentials are scoped to the repository origin: scheme, host, and port. Repositories at different paths on the same origin share the stored credential.
To remove the stored credential along with a repository, pass --remove-credential:
rpx repo additional remove https://rrepo.dev/my-team/packages --remove-credential
The flag is also available on rpx repo base reset. Because credentials are shared by origin, removing one also affects other repositories using that credential.
Inspect repositories and selection
List the project's configured sources:
rpx repo list
rpx prefers an existing locked version when it remains compatible and available. Otherwise, it selects the highest compatible version across the configured repositories. When the same version appears in multiple sources, the order is base repository, Git remotes, then additional repositories.
Adding a repository makes its packages available for resolution. Downloads use each package's locked source; another repository is not an artifact fallback for that package.