GitHub Actions执行NPM发布失败,报错ERR! code ENEEDAUTH
解决GitHub Actions发布npm包时的ENEEDAUTH认证错误
问题描述
按照GitHub官方指南使用细粒度权限向包注册表认证,执行npm publish时失败,报错提示需要登录到GitHub npm注册表。
报错信息
npm ERR! code ENEEDAUTH npm ERR! need auth This command requires you to be logged in to https://npm.pkg.github.com npm ERR! need auth You need to authorize this machine using `npm adduser`
相关配置文件
package.json
{ "name": "@charneykaye/banana", "version": "4.0.6", "repository": "git@github.com:charneykaye/banana", "description": "made by artists in a new algorithmic medium", "bin": { "banana": "./lib/index.js" }, "author": "Charney Kaye <charney@xj.io>", "license": "MIT", "scripts": { "start": "nodemon --watch 'src/**/*.ts' --exec 'ts-node' src/index.ts", "start:windows": "nodemon --watch 'src/**/*.ts' --exec \"npx ts-node\" src/index.ts", "create": "npm run build && npm run test", "banana": "npx ts-node ./src/index.ts", "test": "tsc -p . && jest --coverage --verbose --runInBand" }, "dependencies": { "commander": "^10.0.0", "figlet": "^1.5.2", "octokit": "^1.8.0" }, "devDependencies": { "@babel/core": "^7.20.12", "@babel/preset-env": "^7.20.2", "@babel/preset-typescript": "^7.18.6", "@jest/globals": "^29.4.1", "@types/jest": "^29.4.0", "@types/node": "^18.11.18", "babel-jest": "^29.4.1", "jest": "^29.4.1", "nodemon": "^2.0.20", "ts-jest": "^29.0.5", "ts-node": "^10.9.1", "typescript": "^4.9.5" }, "publishConfig": { "registry": "https://npm.pkg.github.com" }, "jest": { "preset": "ts-jest", "testEnvironment": "node", "testMatch": [ "**/__tests__/**test.ts", "**/__tests__/**test.tsx" ] } }
.github/workflows/ci.yml
name: "CI Build & Publish" on: push: branches: - main jobs: CI: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v2 - name: Setup Node.js uses: actions/setup-node@v3 with: node-version: 18.14 cache: 'npm' - name: Install npm packages run: npm install - name: Unit tests run: npm test - name: Build Banana run: npm run banana -- --build --env prod - uses: actions/upload-artifact@v3 with: name: banana path: ./build/ - name: Publish NPM package run: npm publish
.npmrc
@charneykaye:registry=https://npm.pkg.github.com
解决方案
报错核心原因是GitHub Actions执行npm publish时未提供有效认证信息,按以下步骤修复:
1. 创建细粒度个人访问令牌(PAT)
在GitHub账号的Settings > Developer settings > Fine-grained personal access tokens页面生成令牌:
- 选择目标仓库,授予
Packages权限下的Write权限; - 若需读取仓库内容,同时授予
Contents权限下的Read权限; - 保存生成的令牌。
2. 添加仓库机密
在目标仓库的Settings > Secrets and variables > Actions > Repository secrets中添加新机密:
- 名称设为
NPM_PUBLISH_TOKEN; - 值填入刚才生成的细粒度PAT。
3. 修改CI工作流配置
更新.github/workflows/ci.yml文件,做两处关键修改:
3.1 配置Node.js环境的注册表信息
在Setup Node.js步骤中添加注册表URL和作用域:
- name: Setup Node.js uses: actions/setup-node@v3 with: node-version: 18.14 cache: 'npm' registry-url: 'https://npm.pkg.github.com' scope: '@charneykaye'
3.2 传递认证令牌到发布步骤
在Publish NPM package步骤中注入认证令牌:
- name: Publish NPM package run: npm publish env: NODE_AUTH_TOKEN: ${{ secrets.NPM_PUBLISH_TOKEN }}
可选:设置工作流权限
在jobs节点下添加权限配置,确保工作流拥有必要操作权限:
jobs: CI: runs-on: ubuntu-latest permissions: packages: write contents: read
修改后的完整ci.yml如下:
name: "CI Build & Publish" on: push: branches: - main jobs: CI: runs-on: ubuntu-latest permissions: packages: write contents: read steps: - name: Checkout uses: actions/checkout@v2 - name: Setup Node.js uses: actions/setup-node@v3 with: node-version: 18.14 cache: 'npm' registry-url: 'https://npm.pkg.github.com' scope: '@charneykaye' - name: Install npm packages run: npm install - name: Unit tests run: npm test - name: Build Banana run: npm run banana -- --build --env prod - uses: actions/upload-artifact@v3 with: name: banana path: ./build/ - name: Publish NPM package run: npm publish env: NODE_AUTH_TOKEN: ${{ secrets.NPM_PUBLISH_TOKEN }}
完成以上修改后,GitHub Actions执行npm publish时会自动使用令牌完成认证,不会再出现登录要求的错误。
内容的提问来源于stack exchange,提问作者Nick Charney Kaye
相关产品推荐
相关产品推荐

