使用GitHub Action发布NPM包遇E404错误,寻求解决指导
解决GitHub Action发布NPM包时的404错误
问题场景
使用GitHub Action发布包到NPM时,触发工作流后出现404错误,Workflow配置如下:
name: Publish to NPM on: release: types: [published] jobs: build: runs-on: ubuntu-latest steps: - name: 'Check out the repo' uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 - name: 'Install Node.js' uses: actions/setup-node@e33196f7422957bea03ed53f6fbb155025ffc7b8 # v3.7.0 with: node-version-file: '.nvmrc' registry-url: 'https://registry.npmjs.org' # Defaults to the user or organization that owns the workflow file scope: '@org' - name: Install dependencies run: npm ci - name: Build the package run: npm run build - run: npm config set "//registry.npmjs.org/:_authToken" "\${NODE_AUTH_TOKEN}" --location=project - name: Publish package on NPM 📦 run: npm publish --access public --tag latest env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - run: npm config delete "//registry.npmjs.org/:_authToken" --location=project if: always()
错误信息:
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access npm ERR! code E404 npm ERR! 404 Not Found - PUT https://registry.npmjs.org/@org%2fpackage - Not found npm ERR! 404 npm ERR! 404 '@@org%/package@0.0.0' is not in this registry. npm ERR! 404 npm ERR! 404 Note that you can also install from a npm ERR! 404 tarball, folder, http url, or git url.
解决方案
1. 检查并修正package.json的name字段
错误信息里的@@org%/package显示包名格式异常,这是核心问题:
- 打开项目根目录的
package.json,确保name字段严格为"@org/package"(替换成你的实际组织名和包名),不能有多余的@符号,也不能拼写错误。 - 例如:如果你的组织是
my-org,包名是my-package,则name应为"@my-org/my-package"。
2. 移除手动配置NPM令牌的步骤
actions/setup-node已经支持通过NODE_AUTH_TOKEN环境变量自动配置认证,手动执行npm config set/delete会导致冲突,直接删掉这两步:
# 删掉这两行 - run: npm config set "//registry.npmjs.org/:_authToken" "\${NODE_AUTH_TOKEN}" --location=project - run: npm config delete "//registry.npmjs.org/:_authToken" --location=project if: always()
3. 确认NPM令牌的权限
- 确保你的NPM令牌拥有发布权限(创建令牌时勾选
publish权限)。 - 如果是组织包,令牌所属账号必须是该NPM组织的成员,且拥有发布对应包的权限(可以在NPM组织后台确认)。
修复后的完整Workflow
name: Publish to NPM on: release: types: [published] jobs: build: runs-on: ubuntu-latest steps: - name: 'Check out the repo' uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 - name: 'Install Node.js' uses: actions/setup-node@e33196f7422957bea03ed53f6fbb155025ffc7b8 # v3.7.0 with: node-version-file: '.nvmrc' registry-url: 'https://registry.npmjs.org' scope: '@org' # 这里直接配置authToken,不需要手动设置 authToken: ${{ secrets.NPM_TOKEN }} - name: Install dependencies run: npm ci - name: Build the package run: npm run build - name: Publish package on NPM 📦 run: npm publish --access public --tag latest
额外验证步骤
- 本地先执行
npm publish --dry-run,确认包名、版本等信息是否正确,没有格式错误。 - 确认NPM组织中已经创建了对应的包(如果是首次发布,不需要提前创建,npm会自动创建,但需要账号有权限)。
内容的提问来源于stack exchange,提问作者Abhishek Kochar
相关产品推荐
相关产品推荐

