使用GitHub Actions发布至GitHub npm包时遭遇认证错误
问题:GitHub Actions发布npm包到GitHub Packages时认证失败
尝试用GitHub Actions将编译proto文件的TypeScript包发布到GitHub Packages,执行时收到错误:npm ERR! need auth You need to authorize this machine using npm adduser`
错误日志显示npm试图登录https://registry.npmjs.org/,而非目标的GitHub Packages仓库。
相关文件
工作流文件
workflow_dispatch: # 从Actions标签手动触发 jobs: publish-gpr: runs-on: ubuntu-latest permissions: contents: read packages: write steps: - uses: actions/checkout@v3 - uses: actions/setup-node@v3 with: node-version: 18.10.0 registry-url: https://npm.pkg.github.com/ - run: git config user.email "****g@gmail.com" - run: git config user.name "*****" - name: Install protoc run: | sudo apt-get update -qq sudo apt-get install -qq protobuf-compiler - name: Install deps run: | cd packages/protobuff && yarn install - name: Build run: | cd packages/protobuff && yarn run build - name: Authenticate with npm run: echo "//npm.pkg.github.com/:_authToken=\${NODE_AUTH_TOKEN}" > ~/.npmrc env: NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: publish to github run: | cd packages/protobuff && npm publish env: NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
package.json
{ "name": "@techcare/protobuff", "version": "1.0.0", "main": "dist/index.js", "license": "MIT", "repository": "git@github.com:nikolabozicbg/techcare.git", "scripts": { "precommit": "yarn install && yarn run lint && yarn run --silent build", "build": "rm -rf ./dist && yarn build:proto && tsc", "build:proto": "./bin/protobuild", "publish:github": "npm publish --registry https://npm.pkg.github.com/ --ignore-scripts" }, "dependencies": { "@grpc/grpc-js": "^1.9.12", "@nestjs/common": "^10.2.10", "@nestjs/core": "^10.2.10", "@nestjs/microservices": "^10.2.10", "reflect-metadata": "^0.1.13", "rxjs": "^7.1.0" }, "resolutions": { "rxjs": "^7.1.0" }, "devDependencies": { "ts-proto": "^1.69.0" } }
错误日志
Run cd packages/protobuff && npm publish npm notice npm notice 📦 @techcare/protobuff@1.0.0 npm notice === Tarball Contents === npm notice 467B bin/protobuild npm notice 131B dist/index.d.ts npm notice 172B dist/index.d.ts.map npm notice 284B dist/index.js npm notice 675B dist/ts-proto-gen/test.d.ts npm notice 609B dist/ts-proto-gen/test.d.ts.map npm notice 1.2kB dist/ts-proto-gen/test.js npm notice 770B package.json npm notice 209B protos/test.proto npm notice 156B src/index.ts npm notice 1.3kB src/ts-proto-gen/test.ts npm notice 315B tsconfig.json npm notice === Tarball Details === npm notice name: @techcare/protobuff npm notice version: 1.0.0 npm notice filename: @techcare/protobuff-1.0.0.tgz npm notice package size: 2.2 kB npm notice unpacked size: 6.3 kB npm notice shasum: 4839e75cb3bbdccc9d624ff6a15f05ae25c05bbb npm notice integrity: sha512-/KAXMamz97Kkm[...]hEOqHct7iea6w== npm notice total files: 12 npm notice npm ERR! code ENEEDAUTH npm ERR! need auth This command requires you to be logged in to https://registry.npmjs.org/ npm ERR! need auth You need to authorize this machine using `npm adduser` npm ERR! A complete log of this run can be found in: npm ERR! /home/runner/.npm/_logs/2023-12-04T14_06_12_215Z-debug-0.log Error: Process completed with exit code 1.
解决方案
方案1:调用已定义的发布脚本
你的package.json已经写好了publish:github脚本,该脚本默认指定了GitHub Packages的仓库地址,直接在工作流中调用即可:
- name: publish to github run: | cd packages/protobuff && npm run publish:github env: NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
方案2:发布时显式指定registry
如果不想用脚本,直接在npm publish命令后追加仓库地址参数:
- name: publish to github run: | cd packages/protobuff && npm publish --registry=https://npm.pkg.github.com/ env: NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
方案3:优化setup-node配置,自动处理认证
actions/setup-node支持通过auth-token参数自动配置认证信息,无需手动生成.npmrc文件,同时确保registry配置生效:
- uses: actions/setup-node@v3 with: node-version: 18.10.0 registry-url: https://npm.pkg.github.com/ auth-token: ${{ secrets.GITHUB_TOKEN }}
之后可以删除手动生成.npmrc的步骤,后续执行npm publish会默认使用GitHub Packages。
方案4:在package.json中配置默认发布仓库
在package.json中添加publishConfig字段,指定默认发布到GitHub Packages,后续无需每次都加参数:
{ // ...其他配置 "publishConfig": { "registry": "https://npm.pkg.github.com/" } }
内容的提问来源于stack exchange,提问作者Nikola Božić
相关产品推荐
相关产品推荐

