PR合并触发GitHub自动Release失败(403错误)的排查求助
问题描述
我尝试在每次PR合并时自动创建Release,使用的是softprops/action-gh-release@v1 Action。但每次合并PR后,Action执行到Create GitHub release步骤时失败,报错信息如下:
⚠️ GitHub release failed with status: 403
undefined
手动触发该Action可成功创建Release,在本地fork上运行该Action也能正常执行。我设置了允许执行Action的用户列表,考虑是否需要添加GitHub默认用户,现咨询两个问题:
- GitHub执行Action的默认用户(actor)名称是什么?
- 该问题是否可能由其他原因导致?
我的Workflow配置如下:
name: Automated Releases env: CHANNEL: 'last' PRERELEASE: 'false' on: pull_request: types: [closed] branches: - main workflow_dispatch: branches: - main permissions: contents: write id-token: write # Cancel in-progress jobs or runs for the current workflow run concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: last_release: runs-on: ubuntu-22.04 steps: - name: checkout branch uses: actions/checkout@v3 with: ref: main - name: Get Configuration id: configuration uses: rgarcia-phi/json-to-variables with: filename: './.github/workflows/config.json' prefix: config - name: Install Node.js 18.x uses: actions/setup-node@v3 with: node-version: 18.x - name: Set POSTFIX value id: set_postfix_value uses: ./.github/workflows/set-postfix-value with: PRERELEASE: ${{ env.PRERELEASE }} - name: Env Vars Configure id: env_vars_configure uses: ./.github/workflows/env-vars-configure with: CHANNEL: ${{ env.CHANNEL }} REF: ${{ github.ref }} POSTFIX: ${{ steps.set_postfix_value.outputs.postfix }} - name: Install Dependencies run: npm ci - name: Build plugin uses: ./.github/workflows/build-plugin with: PACKAGE_VERSION: ${{ env.PACKAGE_VERSION }} BUILD_SCRIPT_PATH: "./.github/scripts/build-zip.sh" - name: Create GitHub release. # It always fails here. uses: softprops/action-gh-release@v1 with: tag_name: ${{ env.PACKAGE_VERSION }} target_commitish: ${{ env.CLEAN_REF }} files: release-*.zip body: "Automated release for ${{ env.PACKAGE_VERSION }}" prerelease: ${{ env.PRERELEASE }}
解答
1. GitHub执行Action的默认用户(actor)名称
当Workflow由PR合并触发时,执行Action的默认actor是github-actions[bot],用户名全称就是这个,ID为41898282。如果你的仓库设置了允许执行Action的用户列表,需要把这个用户添加进去。
2. 其他可能的原因
除了用户权限列表的问题,还可能是以下原因:
- PR来自fork仓库的权限限制:如果PR是从fork仓库提交的,GitHub会限制合并PR时触发的Workflow权限,哪怕你在配置里设置了
contents: write,也可能没有足够权限创建Release。可以考虑把触发事件改成push(合并到main分支后触发),或者在仓库设置中开启“允许fork仓库的Workflow访问仓库的机密和权限”(注意这个选项有安全风险)。 GITHUB_TOKEN权限受限:虽然配置了permissions: contents: write,但pull_request closed事件中,默认的GITHUB_TOKEN实际权限可能被限制。可以尝试显式指定token参数,使用拥有仓库写入权限的个人访问令牌(PAT)代替默认的GITHUB_TOKEN,但要做好PAT的安全管理。- 标签已存在:如果
${{ env.PACKAGE_VERSION }}对应的标签已经存在,创建Release时会返回403错误。可以在创建前添加步骤检查标签是否存在,或者确保版本号每次唯一。 - 环境变量未正确赋值:比如
CLEAN_REF或PACKAGE_VERSION没正确设置,导致API请求参数错误,间接引发权限报错。可以在Workflow中加步骤打印这些环境变量的值,确认是否正确。
内容的提问来源于stack exchange,提问作者DavSev
相关产品推荐
相关产品推荐

