You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Maven依赖图谱更新失败求助:Resource not accessible by integration错误

问题

配置maven.yml让项目构建时更新依赖图谱,却持续报错:

Error: Response body:
{
  "message": "Resource not accessible by integration",
  "documentation_url": "https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository"
}
Error: Resource not accessible by integration
Error: HttpError: Resource not accessible by integration
    at /home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:5317:1
    at processTicksAndRejections (node:internal/process/task_queues:96:5)

/home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:396
        function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
^
Error: Failed to submit snapshot: HttpError: Resource not accessible by integration
    at /home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:499:1
    at Generator.throw (<anonymous>)
    at rejected (/home/runner/work/_actions/advanced-security/maven-dependency-submission-action/571e99aab1055c2e71a1e2309b9691de18d6b7d6/webpack:/maven-dependency-tree-action/node_modules/@github/dependency-submission-toolkit/dist/index.js:396:1)
    at processTicksAndRejections (node:internal/process/task_queues:96:5)

已在.github目录中添加dependabot.yml,不确定失败原因,求解决。

当前配置文件

maven.yml

name: Java CI with Maven

on:
  push:
    branches: [ "master" ]
  pull_request:
    branches: [ "master" ]

jobs:
  build:

    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@v3
      - name: Set up JDK 17
        uses: graalvm/setup-graalvm@v1
        with:
          java-version: '17.0.7'
          distribution: 'graalvm' # See 'Options' for all available distributions
          github-token: ${{ secrets.GITHUB_TOKEN }}
          cache: 'maven'
          check-for-updates: 'true'
      - name: Build with Maven
        run: mvn -B package --file pom.xml

      # Optional: Uploads the full dependency graph to GitHub to improve the quality of Dependabot alerts this repository can receive
      - name: Update dependency graph
        uses: advanced-security/maven-dependency-submission-action@571e99aab1055c2e71a1e2309b9691de18d6b7d6
        with:
          github-token: ${{ secrets.YOUR_PERSONAL_ACCESS_TOKEN }}

dependabot.yml

version: 2
updates:
  - package-ecosystem: "maven" # See documentation for possible values
    directory: "/" # Location of package manifests: pom.xml
    schedule:
      interval: "weekly"
解决方案

这个错误是提交依赖图谱的权限不足导致的,按以下步骤排查修复:

  • 检查Personal Access Token(PAT)权限
    你使用的YOUR_PERSONAL_ACCESS_TOKEN必须具备repo权限(私有仓库)或public_repo权限(公有仓库),同时要确保该token已正确添加到仓库Secrets中,名称和配置里的YOUR_PERSONAL_ACCESS_TOKEN完全一致。

  • 尝试改用默认GITHUB_TOKEN
    多数情况下,GitHub Actions提供的GITHUB_TOKEN已具备提交依赖图谱的权限,无需额外创建PAT。修改Update dependency graph步骤的token配置:

    - name: Update dependency graph
      uses: advanced-security/maven-dependency-submission-action@571e99aab1055c2e71a1e2309b9691de18d6b7d6
      with:
        github-token: ${{ secrets.GITHUB_TOKEN }}
    
  • 确认仓库Dependency Graph功能已开启
    进入仓库Settings -> Code security and analysis页面,确保Dependency graph选项处于启用状态。私有仓库可能需要开启GitHub Advanced Security才能使用该功能。

  • 检查Action触发条件
    依赖提交Action在PR触发时可能存在额外权限限制,若仅需在push到master时更新依赖图谱,可暂时移除pull_request触发条件,或确保PR触发时的token拥有足够权限。

内容的提问来源于stack exchange,提问作者kyleryan1291

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 14:36:34