GitHub Actions中恢复私有NuGet包的认证问题求助
问题描述
尝试在GitHub Actions中恢复同一组织下的私有NuGet包时遇到以下问题:
使用nuget.config加PAT出现401未授权
配置了包含GitHub私有源和PAT的nuget.config,执行restore命令时返回:Response status code does not indicate success: 401 (Unauthorized)
对应的配置和脚本:<?xml version="1.0" encoding="utf-8"?> <configuration> <packageSources> <clear /> <add key="NuGet" value="https://api.nuget.org/v3/index.json" /> <add key="github" value="https://nuget.pkg.github.com/COMPANY/index.json" /> </packageSources> <packageSourceCredentials> <github> <add key="Username" value="USERNAME" /> <add key="ClearTextPassword" value="TOKEN" /> </github> </packageSourceCredentials> </configuration>- name: 'Restore packages' uses: actions/setup-dotnet@v1 env: NUGET_CREDENTIALPROVIDER_SESSIONTOKENCACHE_ENABLED: 0 # Disable token caching run: dotnet restore ${{ matrix.project_path }} --configfile nuget.config直接添加源提示源已存在
删除nuget.config后尝试手动添加源,报错源已存在:- name: 'Add GitHub Package Registry Source' run: dotnet nuget add source ${{ env.GITHUB_PACKAGES_SOURCE_URL }} --name GitHubPackages -u "USERNAME" -p ${{ secrets.MYTOKEN }} --store-password-in-clear-text - name: 'Add NuGet.org Source' run: dotnet nuget add source ${{ env.NUGET_PACKAGES_SOURCE_URL }} --name NuGetOrg - name: 'Restore packages' run: dotnet restore ${{ matrix.project_path }}清空源后仍报错找不到对应源
尝试遍历删除所有现有源,执行时返回:error: Unable to find any package source(s) matching name: https://nuget.pkg.github.com/COMPANY/index.json
对应的脚本:- name: 'Clear Existing NuGet Sources' run: | $existingSources = dotnet nuget list source --format "Short" foreach ($source in $existingSources) { dotnet nuget remove source $source } shell: pwsh
解决方案
方案一:修正nuget.config的使用(解决401错误)
首先注意你第一个脚本的YAML语法错误:run项被错误缩进在env下面,导致命令未正确执行。同时修正PAT的传递方式,不要硬编码:
修改nuget.config,用环境变量注入TOKEN:
<?xml version="1.0" encoding="utf-8"?> <configuration> <packageSources> <clear /> <add key="NuGet" value="https://api.nuget.org/v3/index.json" /> <add key="github" value="https://nuget.pkg.github.com/COMPANY/index.json" /> </packageSources> <packageSourceCredentials> <github> <add key="Username" value="USERNAME" /> <add key="ClearTextPassword" value="%GITHUB_PAT%" /> </github> </packageSourceCredentials> </configuration>修正Actions脚本的语法,正确传递密钥:
- name: Setup .NET uses: actions/setup-dotnet@v3 # 使用最新版本 with: dotnet-version: 'x.x.x' # 指定你需要的.NET版本 - name: Restore packages env: NUGET_CREDENTIALPROVIDER_SESSIONTOKENCACHE_ENABLED: 0 GITHUB_PAT: ${{ secrets.MYTOKEN }} # 引用仓库密钥中的PAT run: dotnet restore ${{ matrix.project_path }} --configfile nuget.config确认PAT权限:
- 必须勾选
read:packages权限 - 如果是组织级私有包,确保PAT的作用域是整个组织(而非单个仓库)
- 检查PAT是否未过期
- 必须勾选
方案二:正确管理NuGet源(解决源重复/找不到的问题)
你的清空源脚本错误地尝试用URL作为名称删除,而dotnet nuget remove source需要的是源的名称,不是URL。修正脚本:
- name: Clear Existing NuGet Sources shell: pwsh run: | # 提取所有源的名称(排除表头和空行) $sourceNames = dotnet nuget list source --format Short | Select-Object -Skip 1 | Where-Object { $_ -ne '' } | ForEach-Object { ($_ -split '\s+')[0] } foreach ($name in $sourceNames) { dotnet nuget remove source $name } - name: Add GitHub Packages Source run: dotnet nuget add source https://nuget.pkg.github.com/COMPANY/index.json --name GitHubPackages -u ANY_USERNAME -p ${{ secrets.MYTOKEN }} --store-password-in-clear-text # 注意:GitHub NuGet源的用户名可以是任意非空字符串,不需要真实用户名 - name: Restore packages run: dotnet restore ${{ matrix.project_path }} --source GitHubPackages --source https://api.nuget.org/v3/index.json
方案三:使用内置GITHUB_TOKEN(无需自定义PAT)
如果你的包和当前仓库属于同一组织,GitHub Actions的内置GITHUB_TOKEN默认拥有read:packages权限,可以直接使用,省去创建自定义PAT的步骤:
- name: Setup .NET uses: actions/setup-dotnet@v3 - name: Add GitHub Packages Source run: dotnet nuget add source https://nuget.pkg.github.com/COMPANY/index.json --name GitHubPackages -u ANY_USERNAME -p ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text - name: Restore packages run: dotnet restore ${{ matrix.project_path }}
内容的提问来源于stack exchange,提问作者Ahmed HM

