GitHub Actions无法拉取私有依赖仓库,请求排查原因
报错信息
Failed to clone
, check your git configuration and permissions for this repository. at /opt/hostedtoolcache/Python/3.11.7/x64/lib/python3.11/site-packages/poetry/vcs/git/backend.py:233 in _clone_legacy
167 229│
168 230│ try:
157 231│ SystemGit.clone(url, target)
158 232│ except CalledProcessError:
159 → 233│ raise PoetryConsoleError(
160 234│ f"Failed to clone {url}, check your git configuration and permissions"
161 235│ " for this repository."
162 236│ )
163 237│
164
165Cannot install.
当前GitHub Action配置片段
name: Python tests on: workflow_dispatch: push: branches: - main pull_request: branches: - '*' jobs: build: runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v3 with: submodules: 'true' token: ${{ secrets.GIT_CREDENTIALS }} persist-credentials: true - name: Set up git run: | git config --global url.https://<my-username>:${{ secrets.GIT_CREDENTIALS }}@github.com/.insteadOf https://github.com/ - name: Set up Python uses: actions/setup-python@v4 with: python-version: 3.11 - name: Install Poetry run: | python -m pip install --upgrade pip pip install poetry
已确认私有仓库对当前仓库的GitHub Actions开放权限,以下是可能的问题点及解决方法:
可能的问题点及修复方案
Git凭证替换未覆盖SSH协议:如果你的
pyproject.toml中私有仓库依赖用的是SSH格式(如git+ssh://git@github.com/xxx/xxx.git),当前配置只替换了HTTPS地址,Poetry克隆时仍会用SSH导致权限失败。
修复:添加SSH地址的凭证替换,或把依赖改成HTTPS格式。添加SSH替换的命令:git config --global url."https://<my-username>:${{ secrets.GIT_CREDENTIALS }}@github.com/".insteadOf "git@github.com:"persist-credentials干扰自定义配置:actions/checkout的persist-credentials: true会在checkout后把仓库的GITHUB_TOKEN写入本地git配置,覆盖你设置的全局url.insteadOf规则,导致凭证失效。
修复:将persist-credentials设为false:- name: Checkout repository uses: actions/checkout@v3 with: submodules: 'true' token: ${{ secrets.GIT_CREDENTIALS }} persist-credentials: falseGIT_CREDENTIALS权限或格式问题:确认
GIT_CREDENTIALS是拥有私有仓库读取权限的个人访问令牌(PAT),需勾选repo权限;同时检查<my-username>是否替换成了实际的GitHub用户名,占位符会导致凭证格式错误。缺失Poetry依赖安装步骤:当前配置仅安装了Poetry,但未执行
poetry install命令(虽不是克隆失败的直接原因,但需补充完成流程):- name: Install dependencies run: poetry install --no-root
内容的提问来源于stack exchange,提问作者aryan

