You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在可调用GitHub Actions工作流中传递GITHUB_TOKEN给pip?

提问:如何在可调用工作流中传递GITHUB_TOKEN给pip?是否需要额外配置?

我正尝试编写一组工作流,用于安装存储在私有GitHub仓库中的依赖包。存放包的仓库已启用“允许来自‘My Org’组织内仓库的访问”权限,GITHUB_TOKEN默认拥有写入权限。

我已在项目工作流中显式传递GITHUB_TOKEN来调用目标工作流,相关配置如下:

调用方工作流 .github/workflows/deploy_myproject.yaml

name: Deploy "My Project" to Sandbox
run-name: 🚀 Deploying to sbx
on:
  push:
    branches:
      - sandbox
    paths:
      - 'my_project/**'
      - .github/workflows/deploy_myproject.yaml

jobs:
  deploy:
    uses: MyORG/github-actions/.github/workflows/call_pip_install.yaml@main
    secrets:
      GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
    with:
      env_name: sandbox

被调用工作流 MyORG/github-actions/.github/workflows/call_pip_install.yaml

name: Deploy PIP
run-name: 🚀 Deploying to ${{ inputs.env_name }}

on:
  workflow_call:
  
    inputs:
      env_name:
        description: 'Target environment'
        required: true
        type: string
        default: "sandbox"

    secrets:
      GH_TOKEN:
        description: 'A token passed from the caller workflow'
        required: true

jobs:
  deploy:
    runs-on: ubuntu-latest
    
    steps:
      - uses: actions/checkout@v3
      - name: Set up Python 3.12
        uses: actions/setup-python@v5
        with:
          python-version: 3.12
      - name: 'Set up Python & deploy'
        run:  |
          python3 -m venv venv
          source ./venv/bin/activate

          echo "Installing dependencies"

          git config --global url."https://${{ secrets.GH_TOKEN }}@github".insteadOf https://github
          git config --list
          ./venv/bin/pip3 install -r requirements.txt -v

注:git config --list仅用于确认已配置url.https://***@github.insteadof=https://github

requirements.txt 内容

module-1 @ git+https://github.com/MyORG/module-1-repo@main
module-2 @ git+https://github.com/MyORG/module-2-repo@main

我也曾尝试在被调用工作流中直接使用{{ github.token }}(按元注解说明应可跨工作流访问),但最终还是选择显式传递token以确保无误。两种方式下,工作流均失败,报错信息为:

fatal: could not read Password for 'https://***@github.com': No such device or address

若替换为个人访问令牌(PAT),相同配置可正常运行。我还尝试过修改requirements.txt的格式(替代全局git配置):

module-1 @ git+https://x-access-token:{GITHUB_TOKEN}@github.com/MyORG/module-1-repo@main
module-1 @ git+https://oauth2:{GITHUB_TOKEN}@github.com/MyORG/module-1-repo@main

但均失败,报错信息为remote: Support for password authentication was removed on August 13, 2021.或类似内容。

我不想使用SSH密钥或传递PAT,因为它们是长期有效的密钥,我希望使用一次性的GITHUB_TOKEN解决问题。


内容的提问来源于stack exchange,提问作者the.Legend

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 02:57:07