Github Actions推送PR后关联CI停止运行问题求助
问题:GitHub Actions自动提交后关联CI工作流未触发
现象
- 在仓库Secrets中配置了包含GitHub个人令牌的
ACCESS_TOKEN - 通过GitHub Actions实现自动化文本校对流程:当Pull Request中出现
correction评论时,触发工作流对分支内的.tex文件进行校对并自动提交推送
自动化校对工作流(correction_CALLED)配置
name: correction_CALLED on: workflow_dispatch: issue_comment: types: - created - edited jobs: job_correction_CALLED: if: (github.event.issue.pull_request != null) && github.event.comment.body == 'correction' runs-on: ubuntu-latest env: # if DIFF_CHECK=0 then **/**.tex files was not changed by textlint. DIFF_CHECK: 0 steps: - name: Github-Script uses: actions/github-script@v2 id: set-target-branch with: github-token: ${{ secrets.ACCESS_TOKEN }} result-encoding: string script: | const pull_request = await github.pulls.get({ owner: context.repo.owner, repo: context.repo.repo, pull_number: context.issue.number }) return pull_request.data.head.ref - name: Checkout uses: actions/checkout@v3 with: ref: ${{ steps.set-target-branch.outputs.result }} - name: Clone uses: actions/checkout@v3 with: repository: MIZOGUCHIKoki/ConfigFiles path: ConfigFiles - name: Copy files to current directory run: | cp ./ConfigFiles/tex_textlint/package.json ./ cp ./ConfigFiles/tex_textlint/.textlintrc.json ./ cp ./ConfigFiles/tex_textlint/package-lock.json ./ cp ./ConfigFiles/.gitconfig ./ - name: Setup-node uses: actions/setup-node@v3 with: node-version: 14 cache: 'npm' - name: Install packages via packages.json run: | npm install - name: Correct run: | npx textlint --fix **/**.tex - name: Remove useless files if: ${{ always() }} run: | rm -rf ConfigFiles node_modules package-lock.json package.json .textlintrc.json .gitconfig - name: Check changed files run: | git diff >> diff.txt if [ -s diff.txt ]; then echo "DIFF_CHECK=1" >> $GITHUB_ENV fi - name: Commit to current branch if: ${{ env.DIFF_CHECK == 1 }} run: | git config user.name github-actions git config user.email 41898282+github-actions[bot]@users.noreply.github.com git commit -am "Proofreading" git push
问题描述
上述工作流完成校对并推送代码后,原本应该触发的关联CI工作流run-textlint并未运行。
期望触发的run-textlint工作流配置
name: run-textlint on: push: paths: - '**/**.tex' pull_request_target: paths: - '**/**.tex' jobs: run-textlint_WF: uses: MIZOGUCHIKoki/ConfigFiles/.github/workflows/textlint_main.yml@main secrets: gh_token: ${{ secrets.ACCESS_TOKEN }}
已对该工作流的触发条件进行修改:
- pull_request: + pull_request_target:
解决方案
1. 确保个人令牌拥有workflow权限
生成GitHub个人令牌(PAT)时,必须勾选workflow权限,只有拥有该权限的令牌触发的推送,才能触发后续的工作流。
2. 修改推送步骤,显式使用令牌认证
在correction_CALLED工作流的Commit to current branch步骤中,将git push替换为显式使用令牌的认证方式,避免默认凭证导致的触发限制:
git push https://${{ secrets.ACCESS_TOKEN }}@github.com/${{ github.repository }}.git
修改后的完整步骤:
- name: Commit to current branch if: ${{ env.DIFF_CHECK == 1 }} run: | git config user.name github-actions git config user.email 41898282+github-actions[bot]@users.noreply.github.com git commit -am "Proofreading" git push https://${{ secrets.ACCESS_TOKEN }}@github.com/${{ github.repository }}.git
3. 优化路径匹配规则
将run-textlint工作流中的路径匹配**/**.tex改为更简洁准确的**/*.tex,确保能匹配所有子目录下的.tex文件:
on: push: paths: - '**/*.tex' pull_request_target: paths: - '**/*.tex'
4. 确认触发逻辑匹配需求
如果你的需求是PR源分支推送后触发工作流,pull_request_target事件针对的是PR的目标分支,可能不符合预期。可以考虑添加pull_request事件并指定synchronize类型,覆盖PR源分支更新的场景:
on: push: paths: - '**/*.tex' pull_request_target: paths: - '**/*.tex' pull_request: types: [synchronize] paths: - '**/*.tex'
内容的提问来源于stack exchange,提问作者Koki MIZOGUCHI
相关产品推荐
相关产品推荐

