GitHub Actions修改版本后推送仓库遇403权限错误求助
GitHub Actions推送版本更新时403权限错误问题
我有一个Django认证应用,正在搭建CI/CD流程,实现代码推送到GitHub仓库后同步到生产服务器。根目录的__init__.py仅用于存储版本号,初始内容如下:
__version__ = "1.0.0"
工作流逻辑是:推送时检查提交消息,含"patch"则补丁位+1(如1.0.0→1.0.1),含"minor"则次版本位+1(如1.0.0→1.1.0)。现在要把修改后的__init__.py推回仓库时,出现403错误:
remote: Permission to TheHunter597/djangoAuthApp.git denied to github-actions[bot]. fatal: unable to access 'https://github.com/TheHunter597/djangoAuthApp.git/': The requested URL returned error: 403
我尝试了多种方法均未解决:
- 方法1:使用全权限PAT(存储在GH_PAT Secrets中)
- name: update git repo continue-on-error: true env: GH_PAT: ${{ secrets.GH_PAT }} run: | git config --global user.email "thehunter597777@gmail.com" git config --global user.name "TheHunter597" git remote set-url origin https://x-access-token:${GH_PAT}@github.com/TheHunter597/djangoAuthApp.git git add . git commit -m "Bump version to ${{ steps.get_required_version.outputs.version }} [skip ci]" git push
- 方法2:用户名+PAT方式设置远程仓库
- name: update git repo 5 continue-on-error: true env: GH_PAT: ${{ secrets.GH_PAT }} run: | git config --global user.email "thehunter597777@gmail.com" git config --global user.name "TheHunter597" git remote set-url origin https://TheHunter597:$GH_PAT@github.com/TheHunter597/djangoAuthApp.git git push
- 方法3:用户名+密码方式
- name: update git repo 7 continue-on-error: true env: GH_PAT: ${{ secrets.GH_PAT }} run: | git config --global user.email "thehunter597777@gmail.com" git config --global user.name "TheHunter597" git remote set-url origin https://TheHunter597:${{secrets.PASSWORD}}@github.com/TheHunter597/djangoAuthApp.git git push
- 方法4:使用gh cli和GITHUB_TOKEN登录
- name: update git repo 8 env: GH_PAT: ${{ secrets.GH_PAT }} run: | git config --global user.email "thehunter597777@gmail.com" git config --global user.name "TheHunter597" echo ${{ secrets.GITHUB_TOKEN }} | gh auth login --with-token git push
所有方法均返回相同错误,相关操作在formatting-tests分支。
解决建议
检查PAT的权限配置
- 确保PAT勾选了
repo全权限(包含public_repo、repo:status等子权限) - 确认PAT所属账号是仓库拥有者或具备写入权限的协作者
- 若仓库属于企业组织,需在PAT设置中启用SAML单点登录(SSO)授权
- 确保PAT勾选了
修复Checkout步骤的配置
默认的actions/checkout可能使用浅克隆,需修改为完整克隆并禁用默认凭证:- uses: actions/checkout@v4 with: fetch-depth: 0 # 获取完整仓库历史 persist-credentials: false # 禁用默认GITHUB_TOKEN,避免权限冲突规范推送命令
明确指定推送分支,并使用动态变量避免硬编码:- name: Push version update env: PAT: ${{ secrets.GH_PAT }} run: | git config user.name "TheHunter597" git config user.email "thehunter597777@gmail.com" git remote set-url origin https://${{ github.actor }}:${PAT}@github.com/${{ github.repository }}.git git add __init__.py git commit -m "Bump version to ${{ steps.get_required_version.outputs.version }} [skip ci]" git push origin ${{ github.ref_name }}检查分支保护规则
若目标分支开启了分支保护,需确保PAT所属账号拥有绕过保护规则的权限,或该账号在允许推送的用户列表中。
内容的提问来源于stack exchange,提问作者Mohamed Hossam
相关产品推荐
相关产品推荐

