为何GitHub未正确应用id-token权限,其他权限却正常生效?
问题
配置GitHub Actions自动向PyPI推送包时,发现id-token权限未正确生效:作业日志仅显示metadata: read,但配置pages: write等其他服务权限可正常生效。已确认项目、组织及企业级别的GITHUB_TOKEN权限均设为“Read & Write”,完整配置代码如下:
name: Publish CLI distribution to PyPI and TestPyPI on: push jobs: build: name: Build Wheel Distribution runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Set up Python uses: actions/setup-python@v5 with: python-version: "3.11" - name: Install pypa/build run: >- python3 -m pip install build --user - name: Build a binary wheel and a source tarball run: python3 -m build - name: Store the distribution packages uses: actions/upload-artifact@v4 with: name: python-package-distributions path: dist/ publish-to-pypi: name: >- Publish to Production PyPi Server if: startsWith(github.ref, 'refs/tags/') # only publish to PyPI on tag pushes needs: - build runs-on: ubuntu-latest environment: name: pypi-prod url: https://pypi.org/p/<my project> permissions: id-token: write # IMPORTANT: mandatory for trusted publishing steps: - name: Download all the dists uses: actions/download-artifact@v4 with: name: python-package-distributions path: dist/ - name: Publish distribution to PyPI uses: pypa/gh-action-pypi-publish@release/v1 github-release: name: >- Sign Distribution and upload to GitHub Release needs: - publish-to-pypi runs-on: ubuntu-latest permissions: contents: write # IMPORTANT: mandatory for making GitHub Releases id-token: write # IMPORTANT: mandatory for sigstore steps: - name: Download all the dists uses: actions/download-artifact@v4 with: name: python-package-distributions path: dist/ - name: Sign the dists with Sigstore uses: sigstore/gh-action-sigstore-python@v2.1.1 with: inputs: >- ./dist/*.tar.gz ./dist/*.whl - name: Create GitHub Release env: GITHUB_TOKEN: ${{ github.token }} run: >- gh release create '${{ github.ref_name }}' --repo '${{ github.repository }}' --notes "" - name: Upload artifact signatures to GitHub Release env: GITHUB_TOKEN: ${{ github.token }} # Upload to GitHub Release using the `gh` CLI. # `dist/` contains the built packages, and the # sigstore-produced signatures and certificates. run: >- gh release upload '${{ github.ref_name }}' dist/** --repo '${{ github.repository }}' publish-to-testpypi: name: Publish Distribution to TestPyPI needs: - build runs-on: ubuntu-latest environment: name: pypi-test url: https://test.pypi.org/project/<my project>/ permissions: id-token: write pages: write steps: - name: Download all the dists uses: actions/download-artifact@v4 with: name: python-package-distributions path: dist/ - name: Publish distribution to TestPyPI uses: pypa/gh-action-pypi-publish@release/v1 with: repository-url: https://test.pypi.org/legacy/
可能的原因及解决办法
- 环境权限覆盖:
publish-to-pypi和publish-to-testpypi作业都关联了环境(environment字段),环境的权限设置会覆盖作业中的配置。进入仓库的Settings > Environments,找到对应的pypi-prod和pypi-test环境,检查Permissions部分,确保id-token权限设为Write。 - ID Token权限特殊性:
id-token权限不属于GITHUB_TOKEN默认的“Read & Write”权限范围,必须在作业或环境中明确声明id-token: write才能生效,全局权限设为读写不会自动继承该权限。 - 企业级限制:如果是企业级仓库,检查企业的GitHub Actions设置,确认是否开启了ID Token生成功能,或者是否限制了特定仓库使用ID Token。部分企业会禁用未授权仓库的ID Token生成。
- YAML语法缩进问题:再次确认
permissions块的缩进是否符合YAML规范,错误缩进会导致权限配置不生效,你的当前配置层级正确,但仍需排除此类低级错误。
内容的提问来源于stack exchange,提问作者cambrialas
相关产品推荐
相关产品推荐

