已配置pull-requests:write权限,CI工作流PR评论任务仍失败
问题:CI工作流无法向PR添加评论(403权限错误)
问题详情
我们的CI/CD流水线中,check_workflow_statuses工作流内的「Leave a comment on the PR if workflow failed」任务持续执行失败。该任务预期在工作流失败时,向关联的Pull Request(PR)添加评论通知贡献者,但即使已配置pull-requests: write权限,仍返回403错误:Resource not accessible by integration。
相关工作流配置片段
- name: Leave a comment on the PR if workflow failed if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }} uses: ./.github/actions/post-comment with: owner: ${{ github.event.repository.owner.login }} repo: ${{ github.event.repository.name }} issue_number: ${{ github.event.number }} message: > 🛠️ Hi @${{ github.event.pull_request.user.login }}, it looks like the CI checks are failing on your PR. Please look at the logs and follow [these instructions](https://github.com/oppia/oppia/wiki/If-CI-checks-fail-on-your-PR#introduction) to fix them, or report the error as a flake. Thanks! - name: Fail if workflow status is failure if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }} run: | exit 1 shell: bash permissions: pull-requests: write
核心错误日志
RequestError [HttpError]: Resource not accessible by integration at /home/runner/work/_actions/actions/github-script/v7/dist/index.js:9537:21 Error: Unhandled error: HttpError: Resource not accessible by integration at async main (/home/runner/work/_actions/actions/github-script/v7/dist/index.js:35522:20) { status: 403, response: { url: 'https://api.github.com/repos/oppia/oppia/issues/21691/comments', status: 403, data: { message: 'Resource not accessible by integration', documentation_url: 'https://docs.github.com/rest/issues/comments#create-an-issue-comment', status: '403' } } }
post-comment动作代码
name: 'Post an issue/PR comment' description: 'This action posts a comment to the GitHub issue or PR conversation thread.' inputs: owner: description: 'The owner of the repo.' required: true repo: description: 'The name of the repo containing the issue/PR.' required: true issue_number: description: 'The number of the issue/PR.' required: true message: description: 'The message to post.' required: true runs: using: composite steps: - name: Leave a comment on the PR if workflow failed uses: actions/github-script@v7 env: OWNER: ${{ inputs.owner }} REPO: ${{ inputs.repo }} ISSUE_NUMBER: ${{ inputs.issue_number }} MESSAGE: ${{ inputs.message }} with: github-token: ${{ github.token }} script: | await github.rest.issues.createComment({ repo: process.env.REPO, owner: process.env.OWNER, issue_number: process.env.ISSUE_NUMBER, body: process.env.MESSAGE });
原因分析
- 复刻仓库PR的权限限制:如果PR来自复刻仓库,GitHub默认会限制
GITHUB_TOKEN的写权限,即使在工作流中配置了pull-requests: write,也无法向基础仓库的PR添加评论,这是GitHub的安全策略,防止恶意PR修改仓库内容。 - 权限配置位置问题:若
permissions配置放在job的steps之后,可能存在解析优先级问题,导致权限未正确应用到后续步骤。
解决方案
方案1:启用复刻PR的写权限(推荐)
在仓库的设置中开启允许复刻PR的工作流使用写权限:
- 进入仓库的「Settings」→「Actions」→「General」
- 找到「Fork pull request workflows」区域
- 勾选「Send write tokens to workflows from fork pull requests」
- 保存设置
方案2:调整权限配置位置
确保permissions配置在job的顶级位置(steps之前),避免解析问题:
jobs: check_workflow_statuses: # 将permissions移到job的开头 permissions: pull-requests: write steps: # ... 其他步骤 - name: Leave a comment on the PR if workflow failed if: ${{ steps.check_workflow_status.outputs.WORKFLOW_STATUS == 'failure' }} uses: ./.github/actions/post-comment with: # ... 现有参数
方案3:使用个人访问令牌(PAT)替代GITHUB_TOKEN
如果无法修改仓库设置,可创建一个具备pull-requests: write权限的PAT:
- 在GitHub账号的「Settings」→「Developer settings」→「Personal access tokens」创建新令牌,勾选
pull-requests: write权限 - 将令牌存储为仓库的Secret(例如命名为
PR_COMMENT_TOKEN) - 修改post-comment动作的
github-token参数:
with: github-token: ${{ secrets.PR_COMMENT_TOKEN }}
内容的提问来源于stack exchange,提问作者Mayank Mohapatra
相关产品推荐
相关产品推荐

