You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions无法拉取私有依赖仓库,请求排查原因

问题排查:Poetry在GitHub Action中拉取私有仓库依赖失败

报错信息

Failed to clone , check your git configuration and permissions for this repository.

at /opt/hostedtoolcache/Python/3.11.7/x64/lib/python3.11/site-packages/poetry/vcs/git/backend.py:233 in _clone_legacy
167 229│
168 230│ try:
157 231│ SystemGit.clone(url, target)
158 232│ except CalledProcessError:
159 → 233│ raise PoetryConsoleError(
160 234│ f"Failed to clone {url}, check your git configuration and permissions"
161 235│ " for this repository."
162 236│ )
163 237│
164
165Cannot install .

当前GitHub Action配置片段

name: Python tests

on:
  workflow_dispatch:
  push:
    branches:
      - main
  pull_request:
    branches:
      - '*'

jobs:
  build:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout repository
        uses: actions/checkout@v3
        with:
          submodules: 'true'
          token: ${{ secrets.GIT_CREDENTIALS }}
          persist-credentials: true

      - name: Set up git
        run: |
          git config --global url.https://<my-username>:${{ secrets.GIT_CREDENTIALS }}@github.com/.insteadOf https://github.com/

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: 3.11

      - name: Install Poetry
        run: |
          python -m pip install --upgrade pip
          pip install poetry

已确认私有仓库对当前仓库的GitHub Actions开放权限,以下是可能的问题点及解决方法:

可能的问题点及修复方案

  • Git凭证替换未覆盖SSH协议:如果你的pyproject.toml中私有仓库依赖用的是SSH格式(如git+ssh://git@github.com/xxx/xxx.git),当前配置只替换了HTTPS地址,Poetry克隆时仍会用SSH导致权限失败。
    修复:添加SSH地址的凭证替换,或把依赖改成HTTPS格式。添加SSH替换的命令:

    git config --global url."https://<my-username>:${{ secrets.GIT_CREDENTIALS }}@github.com/".insteadOf "git@github.com:"
    
  • persist-credentials干扰自定义配置:actions/checkout的persist-credentials: true会在checkout后把仓库的GITHUB_TOKEN写入本地git配置,覆盖你设置的全局url.insteadOf规则,导致凭证失效。
    修复:将persist-credentials设为false:

    - name: Checkout repository
      uses: actions/checkout@v3
      with:
        submodules: 'true'
        token: ${{ secrets.GIT_CREDENTIALS }}
        persist-credentials: false
    
  • GIT_CREDENTIALS权限或格式问题:确认GIT_CREDENTIALS是拥有私有仓库读取权限的个人访问令牌(PAT),需勾选repo权限;同时检查<my-username>是否替换成了实际的GitHub用户名,占位符会导致凭证格式错误。

  • 缺失Poetry依赖安装步骤:当前配置仅安装了Poetry,但未执行poetry install命令(虽不是克隆失败的直接原因,但需补充完成流程):

    - name: Install dependencies
      run: poetry install --no-root
    

内容的提问来源于stack exchange,提问作者aryan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 18:10:25