You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何GitHub未正确应用id-token权限,其他权限却正常生效?

问题

配置GitHub Actions自动向PyPI推送包时,发现id-token权限未正确生效:作业日志仅显示metadata: read,但配置pages: write等其他服务权限可正常生效。已确认项目、组织及企业级别的GITHUB_TOKEN权限均设为“Read & Write”,完整配置代码如下:

name: Publish CLI distribution to PyPI and TestPyPI

on: push

jobs:
  build:
    name: Build Wheel Distribution
    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@v4
      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: "3.11"
      - name: Install pypa/build
        run: >-
          python3 -m
          pip install
          build
          --user
      - name: Build a binary wheel and a source tarball
        run: python3 -m build
      - name: Store the distribution packages
        uses: actions/upload-artifact@v4
        with:
          name: python-package-distributions
          path: dist/

  publish-to-pypi:
    name: >-
      Publish to Production PyPi Server
    if: startsWith(github.ref, 'refs/tags/') # only publish to PyPI on tag pushes
    needs:
      - build
    runs-on: ubuntu-latest
    environment:
      name: pypi-prod
      url: https://pypi.org/p/<my project>
    permissions:
      id-token: write # IMPORTANT: mandatory for trusted publishing

    steps:
      - name: Download all the dists
        uses: actions/download-artifact@v4
        with:
          name: python-package-distributions
          path: dist/
      - name: Publish distribution to PyPI
        uses: pypa/gh-action-pypi-publish@release/v1

  github-release:
    name: >-
      Sign Distribution and upload to GitHub Release
    needs:
      - publish-to-pypi
    runs-on: ubuntu-latest

    permissions:
      contents: write # IMPORTANT: mandatory for making GitHub Releases
      id-token: write # IMPORTANT: mandatory for sigstore

    steps:
      - name: Download all the dists
        uses: actions/download-artifact@v4
        with:
          name: python-package-distributions
          path: dist/
      - name: Sign the dists with Sigstore
        uses: sigstore/gh-action-sigstore-python@v2.1.1
        with:
          inputs: >-
            ./dist/*.tar.gz
            ./dist/*.whl
      - name: Create GitHub Release
        env:
          GITHUB_TOKEN: ${{ github.token }}
        run: >-
          gh release create
          '${{ github.ref_name }}'
          --repo '${{ github.repository }}'
          --notes ""
      - name: Upload artifact signatures to GitHub Release
        env:
          GITHUB_TOKEN: ${{ github.token }}
        # Upload to GitHub Release using the `gh` CLI.
        # `dist/` contains the built packages, and the
        # sigstore-produced signatures and certificates.
        run: >-
          gh release upload
          '${{ github.ref_name }}' dist/**
          --repo '${{ github.repository }}'

  publish-to-testpypi:
    name: Publish Distribution to TestPyPI
    needs:
      - build
    runs-on: ubuntu-latest

    environment:
      name: pypi-test
      url: https://test.pypi.org/project/<my project>/

    permissions:
      id-token: write
      pages: write

    steps:
      - name: Download all the dists
        uses: actions/download-artifact@v4
        with:
          name: python-package-distributions
          path: dist/
      - name: Publish distribution to TestPyPI
        uses: pypa/gh-action-pypi-publish@release/v1
        with:
          repository-url: https://test.pypi.org/legacy/

可能的原因及解决办法

  • 环境权限覆盖:publish-to-pypi和publish-to-testpypi作业都关联了环境(environment字段),环境的权限设置会覆盖作业中的配置。进入仓库的Settings > Environments,找到对应的pypi-prod和pypi-test环境,检查Permissions部分,确保id-token权限设为Write。
  • ID Token权限特殊性:id-token权限不属于GITHUB_TOKEN默认的“Read & Write”权限范围,必须在作业或环境中明确声明id-token: write才能生效,全局权限设为读写不会自动继承该权限。
  • 企业级限制:如果是企业级仓库,检查企业的GitHub Actions设置,确认是否开启了ID Token生成功能,或者是否限制了特定仓库使用ID Token。部分企业会禁用未授权仓库的ID Token生成。
  • YAML语法缩进问题:再次确认permissions块的缩进是否符合YAML规范,错误缩进会导致权限配置不生效,你的当前配置层级正确,但仍需排除此类低级错误。

内容的提问来源于stack exchange,提问作者cambrialas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 16:04:53