使用GitHub Actions创建PR时遭遇GraphQL权限错误的求助
GitHub Actions创建PR时遭遇GraphQL权限错误的求助
问题还原
我在运行GitHub Actions工作流自动创建PR时,一直碰到这个权限报错:
pull request create failed: GraphQL: Resource not accessible by integration (createPullRequest)
我已经尝试给GITHUB_TOKEN开了所有可见权限,但问题还是没解决。我的工作流代码如下,原本想着能自动修改配置文件后创建PR,结果卡在权限这一步了:
name: Pull Request Action on: push: workflow_dispatch: env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} jobs: build: runs-on: ubuntu-latest steps: - name: Check out repository uses: actions/checkout@v3 - name: Set up Git run: | git config --global user.email "github-actions[bot]@users.noreply.github.com" git config --global user.name "github-actions[bot]" - name: Install jq run: | sudo apt-get -y install jq - name: Update Config Params and Create Pull Requests run: | #urls=$(curl -sSL https://raw.githubusercontent.com/ubiquity/devpool-directory/development/projects.json | jq -r '.urls[]') urls="https://github.com/EtherealGlow/ubiquibot-pr-qa" for url in $urls do repoName=$(basename $url) ownerName=$(echo $url | awk -F/ '{print $(NF-1)}') git clone $url $repoName cd $repoName defaultBranch=$(git branch --show-current) ### update configs ### # The configurations update code goes here declare -A param_mapping=( ["evm-network-id"]="network-id chain-id" ["price-multiplier"]="base-multiplier" #add more configs as needed ) # Iterate over the mapping and perform updates using sed for new_param in "${!param_mapping[@]}" do old_params="${param_mapping[$new_param]}" for old_param in $old_params do sed -i "s/\b$old_param\b/$new_param/g" .github/ubiquibot-config.yml done done git add . git commit -m "fix: use latest ubiquibot config setup" gh pr create --base $defaultBranch --head $defaultBranch --fill cd .. done
可能的解决方向
1. 先修正分支逻辑——同分支无法创建PR
GitHub本身不允许基于同一个分支创建PR,你代码里用--base $defaultBranch --head $defaultBranch是不符合规则的,这大概率是核心问题!你需要先创建新分支再提交修改,比如:
# 替换原有的commit和pr创建步骤 git checkout -b update-ubiquibot-config git add . git commit -m "fix: use latest ubiquibot config setup" git push origin update-ubiquibot-config gh pr create --base $defaultBranch --head update-ubiquibot-config --fill
2. 确认GITHUB_TOKEN的实际权限范围
默认的GITHUB_TOKEN权限是受限的,即使你觉得开了所有权限,也要明确在工作流里声明所需权限:
jobs: build: runs-on: ubuntu-latest # 明确声明需要的权限 permissions: contents: write # 允许推送分支 pull-requests: write # 允许创建PR
3. 如果操作的是外部仓库,必须用PAT而非默认token
你代码里clone的是外部仓库(https://github.com/EtherealGlow/ubiquibot-pr-qa),默认的GITHUB_TOKEN只对当前工作流所在的仓库有访问权限,对外部仓库完全无效。这种情况你需要:
- 创建一个Personal Access Token (PAT),给它分配
repo权限 - 将PAT存入仓库的Secrets(比如命名为
EXTERNAL_REPO_PAT) - 替换工作流里的
GH_TOKEN:env: GH_TOKEN: ${{ secrets.EXTERNAL_REPO_PAT }}
4. 检查目标仓库的分支保护规则
如果目标仓库的默认分支开启了分支保护(比如要求PR必须有审核、禁止直接推送等),也可能导致创建PR失败,需要确认目标仓库的分支保护设置是否允许当前token操作。
总结
先修正分支创建的逻辑(必须用不同分支创建PR),再根据操作的仓库类型(当前/外部)配置对应的token权限,应该就能解决这个问题了。
备注:内容来源于stack exchange,提问作者me505
相关产品推荐
相关产品推荐

