Would like to use GCP Artifact Registry to be the source of truth for NPM packages to make sure developers are bringing in packages they have gone through licensing, vulnerability, and even potentially overriding them with a patched version
Google gives a few scenarios and use cases; but no real examples on how they suggesting doing this
Store dependencies in a private registry
Artifact Registry provides the convenience of installation from a public repository as well as control over your dependencies.
https://cloud.google.com/artifact-registry/docs/dependencies#approaches
Explicitly mirror the third-party dependencies you need into your private repository, either manually or with a pull-through proxy
https://cloud.google.com/artifact-registry/docs/dependencies#public-dependencies
The guide shows how to upload your package, but doesn't really give a good way to bulk import a bunch of dependencies that aren't yours; it would be even cool to see if a pull-through proxy is possible.