使用GitHub Actions向仓库推送代码失败,求解决办法
GitHub Actions PR审核后推送修改遇403权限问题的解决方案
核心原因
触发pull_request_review事件时,GitHub默认提供的GITHUB_TOKEN仅拥有只读权限,无法向仓库推送修改,这是导致403错误的主要原因。若你尝试过个人访问令牌(PAT)仍失败,大概率是令牌权限配置不对、Secrets未正确设置,或是工作流存在语法错误。
可行解决方案
方案一:使用具备写入权限的个人访问令牌(PAT)
生成合规的PAT
登录GitHub,进入Settings > Developer settings > Personal access tokens > Tokens (classic),生成新令牌并勾选repo权限(获取仓库读写控制权),设置合理的过期时间。将PAT存入仓库Secrets
进入目标仓库的Settings > Secrets and variables > Actions > New repository secret,命名为REPO_WRITE_TOKEN(自定义名称,避免和默认GITHUB_TOKEN混淆),粘贴生成的PAT。修正工作流配置
重点修复缩进错误(原代码中steps未缩进在update-versionjob下,属于语法错误),同时调整checkout动作和推送逻辑:
name: Versioning on: pull_request_review: types: - submitted jobs: update-version: if: github.event.review.state == 'approved' && github.event.pull_request.state == 'open' runs-on: windows-latest permissions: contents: write pull-requests: read steps: - name: Checkout repository uses: actions/checkout@v4 # 升级到维护中的最新版本 with: ref: ${{ github.event.pull_request.head.ref }} fetch-depth: 0 persist-credentials: false # 禁用默认只读token的自动存储 - name: Update Version shell: pwsh run: | $baseRef = "${{ github.event.pull_request.base.ref }}" $headRef = "${{ github.event.pull_request.head.ref }}" $wixInstallerPath = "MyApp X86 Installer/Product.wxs" $wixInstaller = Get-Content -Path $wixInstallerPath $minor = [regex]::Match($wixInstaller, '(?<=<Product[^>]*Version=")\d+\.\d+\.(\d+)').Groups[1].Value $revision = [regex]::Match($wixInstaller, '(?<=<Product[^>]*Version="\d+\.\d+\.\d+\.)(\d+)').Groups[1].Value $oldVersion = "$baseRef.$minor.$revision" if ($headRef.StartsWith("feature-")) { $minor = [int]$minor + 1 $revision = 0 } else { $revision = [int]$revision + 1 } $newVersion = "$baseRef.$minor.$revision" # 更新WiX版本号 (Get-Content -Path $wixInstallerPath) -replace '(?<=<Product[^>]*Version=")\d+\.\d+\.\d+\.\d+', $newVersion | Set-Content -Path $wixInstallerPath # 使用自定义写入令牌 $repoPath = "https://${{ secrets.REPO_WRITE_TOKEN }}@github.com/bioacesso/gerenciador-facial.git"; # 提交并推送 git config --global user.name "Mybot" git config --global user.email "github@myapp.net" git add -u git commit -m "Update version to $newVersion" git push --repo=$repoPath
方案二:提升默认GITHUB_TOKEN权限(仅限同仓库PR)
如果你的PR来自同一个仓库的分支(非fork仓库),可以直接通过声明权限提升默认令牌的写入能力:
- 在
update-versionjob下添加权限配置:
permissions: contents: write pull-requests: read
- 推送时无需手动拼接仓库地址,直接使用默认远程:
git push origin ${{ github.event.pull_request.head.ref }}
额外注意事项
- 原工作流的
steps缩进错误会导致工作流执行异常,必须确保steps是update-versionjob的子节点。 - 若PR来自fork仓库,GitHub出于安全限制,无法在工作流中向原仓库推送修改,这种情况建议调整为合并PR后再执行版本更新流程。
内容的提问来源于stack exchange,提问作者jairhumberto
相关产品推荐
相关产品推荐

