You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions修改版本后推送仓库遇403权限错误求助

GitHub Actions推送版本更新时403权限错误问题

我有一个Django认证应用,正在搭建CI/CD流程,实现代码推送到GitHub仓库后同步到生产服务器。根目录的__init__.py仅用于存储版本号,初始内容如下:

__version__ = "1.0.0"

工作流逻辑是:推送时检查提交消息,含"patch"则补丁位+1(如1.0.0→1.0.1),含"minor"则次版本位+1(如1.0.0→1.1.0)。现在要把修改后的__init__.py推回仓库时,出现403错误:

remote: Permission to TheHunter597/djangoAuthApp.git denied to github-actions[bot].
fatal: unable to access 'https://github.com/TheHunter597/djangoAuthApp.git/': The requested URL returned error: 403

我尝试了多种方法均未解决:

  • 方法1:使用全权限PAT(存储在GH_PAT Secrets中)
- name: update git repo
        continue-on-error: true
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --global user.email "thehunter597777@gmail.com"
          git config --global user.name "TheHunter597"
          git remote set-url origin https://x-access-token:${GH_PAT}@github.com/TheHunter597/djangoAuthApp.git
          git add .
          git commit -m "Bump version to ${{ steps.get_required_version.outputs.version }} [skip ci]"
          git push
  • 方法2:用户名+PAT方式设置远程仓库
- name: update git repo 5
        continue-on-error: true
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --global user.email "thehunter597777@gmail.com"
          git config --global user.name "TheHunter597"
          git remote set-url origin https://TheHunter597:$GH_PAT@github.com/TheHunter597/djangoAuthApp.git
          git push
  • 方法3:用户名+密码方式
- name: update git repo 7
        continue-on-error: true
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --global user.email "thehunter597777@gmail.com"
          git config --global user.name "TheHunter597"
          git remote set-url origin https://TheHunter597:${{secrets.PASSWORD}}@github.com/TheHunter597/djangoAuthApp.git
          git push
  • 方法4:使用gh cli和GITHUB_TOKEN登录
- name: update git repo 8
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --global user.email "thehunter597777@gmail.com"
          git config --global user.name "TheHunter597"
          echo ${{ secrets.GITHUB_TOKEN }} | gh auth login --with-token
          git push

所有方法均返回相同错误,相关操作在formatting-tests分支。


解决建议

  1. 检查PAT的权限配置

    • 确保PAT勾选了repo全权限(包含public_repo、repo:status等子权限)
    • 确认PAT所属账号是仓库拥有者或具备写入权限的协作者
    • 若仓库属于企业组织,需在PAT设置中启用SAML单点登录(SSO)授权
  2. 修复Checkout步骤的配置
    默认的actions/checkout可能使用浅克隆,需修改为完整克隆并禁用默认凭证:

    - uses: actions/checkout@v4
      with:
        fetch-depth: 0 # 获取完整仓库历史
        persist-credentials: false # 禁用默认GITHUB_TOKEN,避免权限冲突
    
  3. 规范推送命令
    明确指定推送分支,并使用动态变量避免硬编码:

    - name: Push version update
      env:
        PAT: ${{ secrets.GH_PAT }}
      run: |
        git config user.name "TheHunter597"
        git config user.email "thehunter597777@gmail.com"
        git remote set-url origin https://${{ github.actor }}:${PAT}@github.com/${{ github.repository }}.git
        git add __init__.py
        git commit -m "Bump version to ${{ steps.get_required_version.outputs.version }} [skip ci]"
        git push origin ${{ github.ref_name }}
    
  4. 检查分支保护规则
    若目标分支开启了分支保护,需确保PAT所属账号拥有绕过保护规则的权限,或该账号在允许推送的用户列表中。

内容的提问来源于stack exchange,提问作者Mohamed Hossam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 02:55:14