You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions执行NPM发布失败,报错ERR! code ENEEDAUTH

解决GitHub Actions发布npm包时的ENEEDAUTH认证错误

问题描述

按照GitHub官方指南使用细粒度权限向包注册表认证,执行npm publish时失败,报错提示需要登录到GitHub npm注册表。

报错信息

npm ERR! code ENEEDAUTH
npm ERR! need auth This command requires you to be logged in to https://npm.pkg.github.com
npm ERR! need auth You need to authorize this machine using `npm adduser`

相关配置文件

package.json

{
  "name": "@charneykaye/banana",
  "version": "4.0.6",
  "repository": "git@github.com:charneykaye/banana",
  "description": "made by artists in a new algorithmic medium",
  "bin": {
    "banana": "./lib/index.js"
  },
  "author": "Charney Kaye <charney@xj.io>",
  "license": "MIT",
  "scripts": {
    "start": "nodemon --watch 'src/**/*.ts' --exec 'ts-node' src/index.ts",
    "start:windows": "nodemon --watch 'src/**/*.ts' --exec \"npx ts-node\" src/index.ts",
    "create": "npm run build && npm run test",
    "banana": "npx ts-node ./src/index.ts",
    "test": "tsc -p . && jest --coverage --verbose --runInBand"
  },
  "dependencies": {
    "commander": "^10.0.0",
    "figlet": "^1.5.2",
    "octokit": "^1.8.0"
  },
  "devDependencies": {
    "@babel/core": "^7.20.12",
    "@babel/preset-env": "^7.20.2",
    "@babel/preset-typescript": "^7.18.6",
    "@jest/globals": "^29.4.1",
    "@types/jest": "^29.4.0",
    "@types/node": "^18.11.18",
    "babel-jest": "^29.4.1",
    "jest": "^29.4.1",
    "nodemon": "^2.0.20",
    "ts-jest": "^29.0.5",
    "ts-node": "^10.9.1",
    "typescript": "^4.9.5"
  },
  "publishConfig": {
    "registry": "https://npm.pkg.github.com"
  },
  "jest": {
    "preset": "ts-jest",
    "testEnvironment": "node",
    "testMatch": [
      "**/__tests__/**test.ts",
      "**/__tests__/**test.tsx"
    ]
  }
}

.github/workflows/ci.yml

name: "CI Build & Publish"

on:
  push:
    branches:
      - main

jobs:
  CI:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout
        uses: actions/checkout@v2

      - name: Setup Node.js
        uses: actions/setup-node@v3
        with:
          node-version: 18.14
          cache: 'npm'

      - name: Install npm packages
        run: npm install

      - name: Unit tests
        run: npm test

      - name: Build Banana
        run: npm run banana -- --build --env prod

      - uses: actions/upload-artifact@v3
        with:
          name: banana
          path: ./build/

      - name: Publish NPM package
        run: npm publish

.npmrc

@charneykaye:registry=https://npm.pkg.github.com

解决方案

报错核心原因是GitHub Actions执行npm publish时未提供有效认证信息,按以下步骤修复:

1. 创建细粒度个人访问令牌(PAT)

在GitHub账号的Settings > Developer settings > Fine-grained personal access tokens页面生成令牌:

  • 选择目标仓库,授予Packages权限下的Write权限;
  • 若需读取仓库内容,同时授予Contents权限下的Read权限;
  • 保存生成的令牌。

2. 添加仓库机密

在目标仓库的Settings > Secrets and variables > Actions > Repository secrets中添加新机密:

  • 名称设为NPM_PUBLISH_TOKEN;
  • 值填入刚才生成的细粒度PAT。

3. 修改CI工作流配置

更新.github/workflows/ci.yml文件,做两处关键修改:

3.1 配置Node.js环境的注册表信息

在Setup Node.js步骤中添加注册表URL和作用域:

- name: Setup Node.js
  uses: actions/setup-node@v3
  with:
    node-version: 18.14
    cache: 'npm'
    registry-url: 'https://npm.pkg.github.com'
    scope: '@charneykaye'

3.2 传递认证令牌到发布步骤

在Publish NPM package步骤中注入认证令牌:

- name: Publish NPM package
  run: npm publish
  env:
    NODE_AUTH_TOKEN: ${{ secrets.NPM_PUBLISH_TOKEN }}

可选:设置工作流权限

在jobs节点下添加权限配置,确保工作流拥有必要操作权限:

jobs:
  CI:
    runs-on: ubuntu-latest
    permissions:
      packages: write
      contents: read

修改后的完整ci.yml如下:

name: "CI Build & Publish"

on:
  push:
    branches:
      - main

jobs:
  CI:
    runs-on: ubuntu-latest
    permissions:
      packages: write
      contents: read

    steps:
      - name: Checkout
        uses: actions/checkout@v2

      - name: Setup Node.js
        uses: actions/setup-node@v3
        with:
          node-version: 18.14
          cache: 'npm'
          registry-url: 'https://npm.pkg.github.com'
          scope: '@charneykaye'

      - name: Install npm packages
        run: npm install

      - name: Unit tests
        run: npm test

      - name: Build Banana
        run: npm run banana -- --build --env prod

      - uses: actions/upload-artifact@v3
        with:
          name: banana
          path: ./build/

      - name: Publish NPM package
        run: npm publish
        env:
          NODE_AUTH_TOKEN: ${{ secrets.NPM_PUBLISH_TOKEN }}

完成以上修改后,GitHub Actions执行npm publish时会自动使用令牌完成认证,不会再出现登录要求的错误。

内容的提问来源于stack exchange,提问作者Nick Charney Kaye

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 17:31:57