You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已配置pull-requests:write权限,CI工作流PR评论任务仍失败

问题:CI工作流无法向PR添加评论(403权限错误)

问题详情

我们的CI/CD流水线中,check_workflow_statuses工作流内的「Leave a comment on the PR if workflow failed」任务持续执行失败。该任务预期在工作流失败时,向关联的Pull Request(PR)添加评论通知贡献者,但即使已配置pull-requests: write权限,仍返回403错误:Resource not accessible by integration。

相关工作流配置片段

- name: Leave a comment on the PR if workflow failed
        if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }}
        uses: ./.github/actions/post-comment
        with:
          owner: ${{ github.event.repository.owner.login }}
          repo: ${{ github.event.repository.name }}
          issue_number: ${{ github.event.number }}
          message: >
            🛠️ Hi @${{ github.event.pull_request.user.login }}, it looks like
            the CI checks are failing on your PR. Please look at the logs and
            follow [these instructions](https://github.com/oppia/oppia/wiki/If-CI-checks-fail-on-your-PR#introduction)
            to fix them, or report the error as a flake. Thanks!
      - name: Fail if workflow status is failure
        if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }}
        run: |
          exit 1
        shell: bash
    permissions:
      pull-requests: write

核心错误日志

RequestError [HttpError]: Resource not accessible by integration
    at /home/runner/work/_actions/actions/github-script/v7/dist/index.js:9537:21
Error: Unhandled error: HttpError: Resource not accessible by integration
    at async main (/home/runner/work/_actions/actions/github-script/v7/dist/index.js:35522:20) {
  status: 403,
  response: {
    url: 'https://api.github.com/repos/oppia/oppia/issues/21691/comments',
    status: 403,
    data: {
      message: 'Resource not accessible by integration',
      documentation_url: 'https://docs.github.com/rest/issues/comments#create-an-issue-comment',
      status: '403'
    }
  }
}

post-comment动作代码

name: 'Post an issue/PR comment'
description: 'This action posts a comment to the GitHub issue or PR conversation thread.'
inputs:
  owner:
    description: 'The owner of the repo.'
    required: true
  repo:
    description: 'The name of the repo containing the issue/PR.'
    required: true
  issue_number:
    description: 'The number of the issue/PR.'
    required: true
  message:
    description: 'The message to post.'
    required: true
runs:
  using: composite
  steps:
    - name: Leave a comment on the PR if workflow failed
      uses: actions/github-script@v7
      env:
        OWNER: ${{ inputs.owner }}
        REPO: ${{ inputs.repo }}
        ISSUE_NUMBER: ${{ inputs.issue_number }}
        MESSAGE: ${{ inputs.message }}
      with:
        github-token: ${{ github.token }}
        script: |
          await github.rest.issues.createComment({
            repo: process.env.REPO,
            owner: process.env.OWNER,
            issue_number: process.env.ISSUE_NUMBER,
            body: process.env.MESSAGE
          });

原因分析

  1. 复刻仓库PR的权限限制:如果PR来自复刻仓库,GitHub默认会限制GITHUB_TOKEN的写权限,即使在工作流中配置了pull-requests: write,也无法向基础仓库的PR添加评论,这是GitHub的安全策略,防止恶意PR修改仓库内容。
  2. 权限配置位置问题:若permissions配置放在job的steps之后,可能存在解析优先级问题,导致权限未正确应用到后续步骤。

解决方案

方案1:启用复刻PR的写权限(推荐)

在仓库的设置中开启允许复刻PR的工作流使用写权限:

  • 进入仓库的「Settings」→「Actions」→「General」
  • 找到「Fork pull request workflows」区域
  • 勾选「Send write tokens to workflows from fork pull requests」
  • 保存设置

方案2:调整权限配置位置

确保permissions配置在job的顶级位置(steps之前),避免解析问题:

jobs:
  check_workflow_statuses:
    # 将permissions移到job的开头
    permissions:
      pull-requests: write
    steps:
      # ... 其他步骤
      - name: Leave a comment on the PR if workflow failed
          if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }}
          uses: ./.github/actions/post-comment
          with:
            # ... 现有参数

方案3:使用个人访问令牌(PAT)替代GITHUB_TOKEN

如果无法修改仓库设置,可创建一个具备pull-requests: write权限的PAT:

  1. 在GitHub账号的「Settings」→「Developer settings」→「Personal access tokens」创建新令牌,勾选pull-requests: write权限
  2. 将令牌存储为仓库的Secret(例如命名为PR_COMMENT_TOKEN)
  3. 修改post-comment动作的github-token参数:
with:
  github-token: ${{ secrets.PR_COMMENT_TOKEN }}

内容的提问来源于stack exchange,提问作者Mayank Mohapatra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 17:27:31