You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub Actions向仓库推送代码失败,求解决办法

GitHub Actions PR审核后推送修改遇403权限问题的解决方案

核心原因

触发pull_request_review事件时,GitHub默认提供的GITHUB_TOKEN仅拥有只读权限,无法向仓库推送修改,这是导致403错误的主要原因。若你尝试过个人访问令牌(PAT)仍失败,大概率是令牌权限配置不对、Secrets未正确设置,或是工作流存在语法错误。

可行解决方案

方案一:使用具备写入权限的个人访问令牌(PAT)

  1. 生成合规的PAT
    登录GitHub,进入Settings > Developer settings > Personal access tokens > Tokens (classic),生成新令牌并勾选repo权限(获取仓库读写控制权),设置合理的过期时间。

  2. 将PAT存入仓库Secrets
    进入目标仓库的Settings > Secrets and variables > Actions > New repository secret,命名为REPO_WRITE_TOKEN(自定义名称,避免和默认GITHUB_TOKEN混淆),粘贴生成的PAT。

  3. 修正工作流配置
    重点修复缩进错误(原代码中steps未缩进在update-version job下,属于语法错误),同时调整checkout动作和推送逻辑:

name: Versioning

on:
  pull_request_review:
    types:
      - submitted

jobs:
  update-version:
    if: github.event.review.state == 'approved' && github.event.pull_request.state == 'open'
    runs-on: windows-latest
    permissions:
      contents: write
      pull-requests: read

    steps:
      - name: Checkout repository
        uses: actions/checkout@v4  # 升级到维护中的最新版本
        with:
          ref: ${{ github.event.pull_request.head.ref }}
          fetch-depth: 0
          persist-credentials: false  # 禁用默认只读token的自动存储

      - name: Update Version
        shell: pwsh
        run: |
          $baseRef = "${{ github.event.pull_request.base.ref }}"
          $headRef = "${{ github.event.pull_request.head.ref }}"
          
          $wixInstallerPath = "MyApp X86 Installer/Product.wxs"
          $wixInstaller = Get-Content -Path $wixInstallerPath
          $minor = [regex]::Match($wixInstaller, '(?<=<Product[^>]*Version=")\d+\.\d+\.(\d+)').Groups[1].Value
          $revision = [regex]::Match($wixInstaller, '(?<=<Product[^>]*Version="\d+\.\d+\.\d+\.)(\d+)').Groups[1].Value
          
          $oldVersion = "$baseRef.$minor.$revision"
          
          if ($headRef.StartsWith("feature-")) {
            $minor = [int]$minor + 1
            $revision = 0
          } else {
            $revision = [int]$revision + 1
          }

          $newVersion = "$baseRef.$minor.$revision"

          # 更新WiX版本号
          (Get-Content -Path $wixInstallerPath) -replace '(?<=<Product[^>]*Version=")\d+\.\d+\.\d+\.\d+', $newVersion | Set-Content -Path $wixInstallerPath
          
          # 使用自定义写入令牌
          $repoPath = "https://${{ secrets.REPO_WRITE_TOKEN }}@github.com/bioacesso/gerenciador-facial.git";
          
          # 提交并推送
          git config --global user.name "Mybot"
          git config --global user.email "github@myapp.net"
          git add -u
          git commit -m "Update version to $newVersion"
          git push --repo=$repoPath

方案二:提升默认GITHUB_TOKEN权限(仅限同仓库PR)

如果你的PR来自同一个仓库的分支(非fork仓库),可以直接通过声明权限提升默认令牌的写入能力:

  1. 在update-version job下添加权限配置:
permissions:
  contents: write
  pull-requests: read
  1. 推送时无需手动拼接仓库地址,直接使用默认远程:
git push origin ${{ github.event.pull_request.head.ref }}

额外注意事项

  • 原工作流的steps缩进错误会导致工作流执行异常,必须确保steps是update-version job的子节点。
  • 若PR来自fork仓库,GitHub出于安全限制,无法在工作流中向原仓库推送修改,这种情况建议调整为合并PR后再执行版本更新流程。

内容的提问来源于stack exchange,提问作者jairhumberto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 08:17:03