You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions权限异常:已授全权限仍提示无仓库写入权限

问题:Python Semantic Release在GitHub Actions中提示无仓库写入权限

我在私有仓库配置python-semantic-release的GitHub Actions时,执行版本号递增操作出现「无仓库写入权限」错误。先后尝试了GitHub经典PAT和细粒度PAT,均授予仓库全部权限,且已验证secrets.TOKEN能被GitHub Actions正确调用,但问题依旧。相关配置与日志如下:

配置文件

main.yml

name: Semantic Release

on:
  push:
    branches:
      - main

jobs:
  release:
    runs-on: ubuntu-latest
    concurrency: release

    steps:
      - uses: actions/checkout@v2
        with:
          fetch-depth: 0
      - name: Step 1 - Echo out a GitHub Actions Secret to the logs
        run: |
          echo "The GitHub Action Secret will be masked:  "
          echo ${{ secrets.TOKEN }}
          echo "Trick to echo GitHub Actions Secret:  "
          echo ${{secrets.TOKEN}} | sed 's/./& /g'
          echo ${{secrets.USERNAME}} | sed 's/./& /g'
      - name: Print repository URL
        run: |
          echo $(git remote get-url origin)
      - name: Python Semantic Release
        uses: relekang/python-semantic-release@master
        with:
          github_token: ${{ secrets.TOKEN }}
          repository_username: __token__

pyproject.toml

[tool.semantic_release]
version_variable = "setup.py:__version__"
branch = "main"
upload_to_repository = false

setup.py

from setuptools import setup

__version__ = "1.0.1"

setup(
   name="pmp-otk",
   version=__version__,
   # And so on...!!!!!!
)

调试日志

debug: * We fixed the damn bug ([`6d6667a`](https://github.com/***/pmp-otk-sandbox/commit/6d6667afde48fbd3cbdabaa048989379b7216ea9))')
warning: Changelog file not found: /github/workspace/CHANGELOG.md - creating it.
debug: update_additional_files()
Bumping with a patch version to 1.0.2
debug: set_new_version('1.0.2')
debug: Writing new version number: path=PosixPath('setup.py') pattern='__version__ *[:=] *["\\'](\\d+\\.\\d+\\.\\d+(-beta\\.\\d+)?)["\\']' num_matches=1
debug: set_new_version -> True
debug: commit_new_version('1.0.2')
debug: commit_new_version -> [main [64](https://github.com/shawnesquivel/pmp-otk-sandbox/actions/runs/4018206730/jobs/6903535852#step:6:65)d5a24] 1.0.2
debug:  2 files changed, 8 insertions(+), 1 deletion(-)
debug:  create mode 100644 CHANGELOG.md
debug: tag_new_version('1.0.2')
debug: tag_new_version -> 
Pushing new version
debug: get_hvcs()
debug: get_hvcs -> <class 'semantic_release.hvcs.Github'>
debug: get_hvcs()
debug: get_hvcs -> <class 'semantic_release.hvcs.Github'>
debug: push_new_version(, auth_token='***', owner='***', name='pmp-otk-sandbox', branch=main, domain='github.com')
error: Cmd('git') failed due to: exit code(128)
error:   cmdline: git push ***github.com/***/pmp-otk-sandbox.git main
error:   stderr: 'remote: Write access to repository not granted.
error: fatal: unable to access 'https://github.com/***/pmp-otk-sandbox.git/': The requested URL returned error: 403'

预期行为:成功递增版本号,无写入权限问题。提交信息示例:git commit -m "fix: we fixed the damn bug"


解决方案
  • 修正actions/checkout配置,确保Git写入权限正常
    actions/checkout@v2默认会保留仓库的默认凭证,可能和自定义PAT冲突。修改checkout步骤禁用默认凭证,然后手动配置带token的远程仓库地址:

    - uses: actions/checkout@v2
      with:
        fetch-depth: 0
        persist-credentials: false  # 禁用默认凭证
    - name: 配置Git远程地址
      run: |
        git remote set-url origin https://__token__:${{ secrets.TOKEN }}@github.com/${{ github.repository }}.git
    
  • 验证细粒度PAT的权限与绑定范围
    若使用细粒度PAT,需确认:

    • 仓库权限中Contents设置为读写;
    • PAT已绑定到目标私有仓库(组织仓库需确认组织允许该PAT访问);
    • 未勾选不必要的权限,避免权限冲突。
  • 检查分支保护规则
    如果main分支设置了分支保护(如强制PR合并、审批要求),直接push版本提交会被拦截。解决方式:

    1. 在分支保护规则中,允许PAT对应的用户绕过保护;
    2. 或修改semantic-release配置,通过创建PR提交版本更新。
  • 使用GitHub自带的GITHUB_TOKEN替代自定义PAT
    若无特殊权限需求,可直接用Actions自动生成的GITHUB_TOKEN:

    1. 进入仓库Settings > Actions > General,勾选"Workflow permissions"下的"Read and write permissions";
    2. 修改Action配置:
    - uses: actions/checkout@v2
      with:
        fetch-depth: 0
        persist-credentials: false
    - name: Python Semantic Release
      uses: relekang/python-semantic-release@master
      with:
        github_token: ${{ secrets.GITHUB_TOKEN }}
        repository_username: x-access-token
    

内容的提问来源于stack exchange,提问作者Shawn Esquivel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 16:40:26