You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub Action发布NPM包遇E404错误,寻求解决指导

解决GitHub Action发布NPM包时的404错误

问题场景

使用GitHub Action发布包到NPM时,触发工作流后出现404错误,Workflow配置如下:

name: Publish to NPM
on:
  release:
    types: [published]
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: 'Check out the repo'
        uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
      - name: 'Install Node.js'
        uses: actions/setup-node@e33196f7422957bea03ed53f6fbb155025ffc7b8 # v3.7.0
        with:
          node-version-file: '.nvmrc'
          registry-url: 'https://registry.npmjs.org'
          # Defaults to the user or organization that owns the workflow file
          scope: '@org'
      - name: Install dependencies
        run: npm ci
      - name: Build the package
        run: npm run build
      - run: npm config set "//registry.npmjs.org/:_authToken" "\${NODE_AUTH_TOKEN}" --location=project
      - name: Publish package on NPM 📦
        run: npm publish --access public --tag latest
        env:
          NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
      - run: npm config delete "//registry.npmjs.org/:_authToken" --location=project
        if: always()

错误信息:

npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm ERR! code E404
npm ERR! 404 Not Found - PUT https://registry.npmjs.org/@org%2fpackage - Not found
npm ERR! 404 
npm ERR! 404  '@@org%/package@0.0.0' is not in this registry.
npm ERR! 404 
npm ERR! 404 Note that you can also install from a
npm ERR! 404 tarball, folder, http url, or git url.

解决方案

1. 检查并修正package.json的name字段

错误信息里的@@org%/package显示包名格式异常,这是核心问题:

  • 打开项目根目录的package.json,确保name字段严格为"@org/package"(替换成你的实际组织名和包名),不能有多余的@符号,也不能拼写错误。
  • 例如:如果你的组织是my-org,包名是my-package,则name应为"@my-org/my-package"。

2. 移除手动配置NPM令牌的步骤

actions/setup-node已经支持通过NODE_AUTH_TOKEN环境变量自动配置认证,手动执行npm config set/delete会导致冲突,直接删掉这两步:

# 删掉这两行
- run: npm config set "//registry.npmjs.org/:_authToken" "\${NODE_AUTH_TOKEN}" --location=project
- run: npm config delete "//registry.npmjs.org/:_authToken" --location=project
  if: always()

3. 确认NPM令牌的权限

  • 确保你的NPM令牌拥有发布权限(创建令牌时勾选publish权限)。
  • 如果是组织包,令牌所属账号必须是该NPM组织的成员,且拥有发布对应包的权限(可以在NPM组织后台确认)。

修复后的完整Workflow

name: Publish to NPM
on:
  release:
    types: [published]
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: 'Check out the repo'
        uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
      - name: 'Install Node.js'
        uses: actions/setup-node@e33196f7422957bea03ed53f6fbb155025ffc7b8 # v3.7.0
        with:
          node-version-file: '.nvmrc'
          registry-url: 'https://registry.npmjs.org'
          scope: '@org'
          # 这里直接配置authToken,不需要手动设置
          authToken: ${{ secrets.NPM_TOKEN }}
      - name: Install dependencies
        run: npm ci
      - name: Build the package
        run: npm run build
      - name: Publish package on NPM 📦
        run: npm publish --access public --tag latest

额外验证步骤

  • 本地先执行npm publish --dry-run,确认包名、版本等信息是否正确,没有格式错误。
  • 确认NPM组织中已经创建了对应的包(如果是首次发布,不需要提前创建,npm会自动创建,但需要账号有权限)。

内容的提问来源于stack exchange,提问作者Abhishek Kochar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 19:42:31