如何在可调用GitHub Actions工作流中传递GITHUB_TOKEN给pip?
提问:如何在可调用工作流中传递GITHUB_TOKEN给
pip?是否需要额外配置? 我正尝试编写一组工作流,用于安装存储在私有GitHub仓库中的依赖包。存放包的仓库已启用“允许来自‘My Org’组织内仓库的访问”权限,GITHUB_TOKEN默认拥有写入权限。
我已在项目工作流中显式传递GITHUB_TOKEN来调用目标工作流,相关配置如下:
调用方工作流 .github/workflows/deploy_myproject.yaml
name: Deploy "My Project" to Sandbox run-name: 🚀 Deploying to sbx on: push: branches: - sandbox paths: - 'my_project/**' - .github/workflows/deploy_myproject.yaml jobs: deploy: uses: MyORG/github-actions/.github/workflows/call_pip_install.yaml@main secrets: GH_TOKEN: ${{secrets.GITHUB_TOKEN}} with: env_name: sandbox
被调用工作流 MyORG/github-actions/.github/workflows/call_pip_install.yaml
name: Deploy PIP run-name: 🚀 Deploying to ${{ inputs.env_name }} on: workflow_call: inputs: env_name: description: 'Target environment' required: true type: string default: "sandbox" secrets: GH_TOKEN: description: 'A token passed from the caller workflow' required: true jobs: deploy: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Set up Python 3.12 uses: actions/setup-python@v5 with: python-version: 3.12 - name: 'Set up Python & deploy' run: | python3 -m venv venv source ./venv/bin/activate echo "Installing dependencies" git config --global url."https://${{ secrets.GH_TOKEN }}@github".insteadOf https://github git config --list ./venv/bin/pip3 install -r requirements.txt -v
注:git config --list仅用于确认已配置url.https://***@github.insteadof=https://github
requirements.txt 内容
module-1 @ git+https://github.com/MyORG/module-1-repo@main module-2 @ git+https://github.com/MyORG/module-2-repo@main
我也曾尝试在被调用工作流中直接使用{{ github.token }}(按元注解说明应可跨工作流访问),但最终还是选择显式传递token以确保无误。两种方式下,工作流均失败,报错信息为:
fatal: could not read Password for 'https://***@github.com': No such device or address
若替换为个人访问令牌(PAT),相同配置可正常运行。我还尝试过修改requirements.txt的格式(替代全局git配置):
module-1 @ git+https://x-access-token:{GITHUB_TOKEN}@github.com/MyORG/module-1-repo@main module-1 @ git+https://oauth2:{GITHUB_TOKEN}@github.com/MyORG/module-1-repo@main
但均失败,报错信息为remote: Support for password authentication was removed on August 13, 2021.或类似内容。
我不想使用SSH密钥或传递PAT,因为它们是长期有效的密钥,我希望使用一次性的GITHUB_TOKEN解决问题。
内容的提问来源于stack exchange,提问作者the.Legend
相关产品推荐
相关产品推荐

