Maven依赖图谱更新失败求助:Resource not accessible by integration错误
问题
配置maven.yml让项目构建时更新依赖图谱,却持续报错:
Error: Response body: { "message": "Resource not accessible by integration", "documentation_url": "https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository" } Error: Resource not accessible by integration Error: HttpError: Resource not accessible by integration at /home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:5317:1 at processTicksAndRejections (node:internal/process/task_queues:96:5) /home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:396 function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } ^ Error: Failed to submit snapshot: HttpError: Resource not accessible by integration at /home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:499:1 at Generator.throw (<anonymous>) at rejected (/home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:396:1) at processTicksAndRejections (node:internal/process/task_queues:96:5)
已在.github目录中添加dependabot.yml,不确定失败原因,求解决。
当前配置文件
maven.yml
name: Java CI with Maven on: push: branches: [ "master" ] pull_request: branches: [ "master" ] jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Set up JDK 17 uses: graalvm/setup-graalvm@v1 with: java-version: '17.0.7' distribution: 'graalvm' # See 'Options' for all available distributions github-token: ${{ secrets.GITHUB_TOKEN }} cache: 'maven' check-for-updates: 'true' - name: Build with Maven run: mvn -B package --file pom.xml # Optional: Uploads the full dependency graph to GitHub to improve the quality of Dependabot alerts this repository can receive - name: Update dependency graph uses: advanced-security/maven-dependency-submission-action@571e99aab1055c2e71a1e2309b9691de18d6b7d6 with: github-token: ${{ secrets.YOUR_PERSONAL_ACCESS_TOKEN }}
dependabot.yml
version: 2 updates: - package-ecosystem: "maven" # See documentation for possible values directory: "/" # Location of package manifests: pom.xml schedule: interval: "weekly"
解决方案
这个错误是提交依赖图谱的权限不足导致的,按以下步骤排查修复:
检查Personal Access Token(PAT)权限
你使用的YOUR_PERSONAL_ACCESS_TOKEN必须具备repo权限(私有仓库)或public_repo权限(公有仓库),同时要确保该token已正确添加到仓库Secrets中,名称和配置里的YOUR_PERSONAL_ACCESS_TOKEN完全一致。尝试改用默认GITHUB_TOKEN
多数情况下,GitHub Actions提供的GITHUB_TOKEN已具备提交依赖图谱的权限,无需额外创建PAT。修改Update dependency graph步骤的token配置:- name: Update dependency graph uses: advanced-security/maven-dependency-submission-action@571e99aab1055c2e71a1e2309b9691de18d6b7d6 with: github-token: ${{ secrets.GITHUB_TOKEN }}确认仓库Dependency Graph功能已开启
进入仓库Settings->Code security and analysis页面,确保Dependency graph选项处于启用状态。私有仓库可能需要开启GitHub Advanced Security才能使用该功能。检查Action触发条件
依赖提交Action在PR触发时可能存在额外权限限制,若仅需在push到master时更新依赖图谱,可暂时移除pull_request触发条件,或确保PR触发时的token拥有足够权限。
内容的提问来源于stack exchange,提问作者kyleryan1291
相关产品推荐
相关产品推荐

