You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置npm通过Token访问私有GitHub仓库:HTTPS设置失效问题

问题描述

我需要在GitHub Actions中,为一个私有仓库安装另一个未发布到npm、仅托管在GitHub的私有仓库。已经在目标仓库配置了名为TOKEN的密钥,但执行npm install时遇到Git SSH认证错误(错误码128),提示SSH权限问题及仓库未找到。

尝试过的解决方案但未完全生效:

  1. 配置Git全局替换,将SSH地址转为带Token的HTTPS:
git config --global url."https://${{ secrets.TOKEN }}:x-oauth-basic@github.com/".insteadOf "ssh://git@github.com/"

直接用Token克隆仓库成功,证明Token有效,但npm install仍尝试使用SSH。

  1. 在.npmrc中配置GitHub Packages:
echo "//npm.pkg.github.com/:_authToken=${{ secrets.TOKEN }}" > ~/.npmrc
echo "@your-org:registry=https://npm.pkg.github.com/" >> ~/.npmrc

SSH权限问题消失,但仍提示仓库找不到,且错误显示npm仍在使用SSH协议。

当前工作流文件如下:

name: Run test

on:
  push:
    branches:
      - "**"
  pull_request:
    types: [opened, synchronize]

jobs:
  test:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout code
        uses: actions/checkout@v2
        with:
          fetch-depth: 0 # Fetch all history to ensure all dependencies are included

      - name: Test Git Clone
        run: |
          git clone https://${{ secrets.TOKEN }}:x-oauth-basic@github.com/org/repo.git

      - name: Set up .npmrc for private repo
        run: |
          echo "//npm.pkg.github.com/:_authToken=${{ secrets.TOKEN }}" > ~/.npmrc
          echo "@your-org:registry=https://npm.pkg.github.com/" >> ~/.npmrc

      - name: Set up Git to use HTTPS with Token
        run: |
          git config --global url."https://${{ secrets.TOKEN }}:x-oauth-basic@github.com/".insteadOf "ssh://git@github.com/"

      - name: Install dependencies
        run: |
          npm install

      - name: Run tests
        run: npm test

如何确保npm install正确使用带Token的HTTPS URL访问私有GitHub仓库?

解决方案

1. 补充Git地址替换规则

当前配置仅覆盖了ssh://git@github.com/格式,但npm可能直接使用git@github.com:org/repo.git这种SSH写法,需要添加第二条替换规则:

git config --global url."https://${{ secrets.TOKEN }}@github.com/".insteadOf "git@github.com:"

这条规则会将git@github.com:org/repo.git自动转换为https://<TOKEN>@github.com/org/repo.git,覆盖npm可能调用的所有SSH地址格式。

2. 调整工作流步骤顺序

将Git配置步骤移到代码Checkout之前,避免checkout后本地Git配置或依赖引用提前触发SSH请求。调整后的步骤:

steps:
  - name: Set up Git to use HTTPS with Token
    run: |
      git config --global url."https://${{ secrets.TOKEN }}:x-oauth-basic@github.com/".insteadOf "ssh://git@github.com/"
      git config --global url."https://${{ secrets.TOKEN }}@github.com/".insteadOf "git@github.com:"

  - name: Checkout code
    uses: actions/checkout@v2
    with:
      fetch-depth: 0

  - name: Set up .npmrc for private repo
    run: |
      echo "//npm.pkg.github.com/:_authToken=${{ secrets.TOKEN }}" > ~/.npmrc
      echo "@your-org:registry=https://npm.pkg.github.com/" >> ~/.npmrc

  - name: Install dependencies
    run: npm install

  - name: Run tests
    run: npm test

3. 验证Git配置生效

在安装依赖前添加步骤,确认全局Git配置是否正确:

git config --global --list | grep url

输出应包含两条url.insteadOf规则。

4. 检查package.json依赖写法

确保私有仓库依赖的写法符合规范,比如:

"dependencies": {
  "@your-org/private-repo": "git+ssh://git@github.com/your-org/private-repo.git#main",
  // 或使用GitHub简写格式
  "@your-org/private-repo": "github:your-org/private-repo#main"
}

额外注意事项

  • 确保TOKEN拥有repo权限(生成Token时勾选repo范围),否则无法读取私有仓库。
  • x-oauth-basic是固定占位符,无需替换,直接使用https://${{ secrets.TOKEN }}@github.com/格式即可正常认证。

内容的提问来源于stack exchange,提问作者waq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 02:17:09