GitHub Actions权限异常:已授全权限仍提示无仓库写入权限
问题:Python Semantic Release在GitHub Actions中提示无仓库写入权限
我在私有仓库配置python-semantic-release的GitHub Actions时,执行版本号递增操作出现「无仓库写入权限」错误。先后尝试了GitHub经典PAT和细粒度PAT,均授予仓库全部权限,且已验证secrets.TOKEN能被GitHub Actions正确调用,但问题依旧。相关配置与日志如下:
配置文件
main.yml
name: Semantic Release on: push: branches: - main jobs: release: runs-on: ubuntu-latest concurrency: release steps: - uses: actions/checkout@v2 with: fetch-depth: 0 - name: Step 1 - Echo out a GitHub Actions Secret to the logs run: | echo "The GitHub Action Secret will be masked: " echo ${{ secrets.TOKEN }} echo "Trick to echo GitHub Actions Secret: " echo ${{secrets.TOKEN}} | sed 's/./& /g' echo ${{secrets.USERNAME}} | sed 's/./& /g' - name: Print repository URL run: | echo $(git remote get-url origin) - name: Python Semantic Release uses: relekang/python-semantic-release@master with: github_token: ${{ secrets.TOKEN }} repository_username: __token__
pyproject.toml
[tool.semantic_release] version_variable = "setup.py:__version__" branch = "main" upload_to_repository = false
setup.py
from setuptools import setup __version__ = "1.0.1" setup( name="pmp-otk", version=__version__, # And so on...!!!!!! )
调试日志
debug: * We fixed the damn bug ([`6d6667a`](https://github.com/***/pmp-otk-sandbox/commit/6d6667afde48fbd3cbdabaa048989379b7216ea9))') warning: Changelog file not found: /github/workspace/CHANGELOG.md - creating it. debug: update_additional_files() Bumping with a patch version to 1.0.2 debug: set_new_version('1.0.2') debug: Writing new version number: path=PosixPath('setup.py') pattern='__version__ *[:=] *["\\'](\\d+\\.\\d+\\.\\d+(-beta\\.\\d+)?)["\\']' num_matches=1 debug: set_new_version -> True debug: commit_new_version('1.0.2') debug: commit_new_version -> [main [64](https://github.com/shawnesquivel/pmp-otk-sandbox/actions/runs/4018206730/jobs/6903535852#step:6:65)d5a24] 1.0.2 debug: 2 files changed, 8 insertions(+), 1 deletion(-) debug: create mode 100644 CHANGELOG.md debug: tag_new_version('1.0.2') debug: tag_new_version -> Pushing new version debug: get_hvcs() debug: get_hvcs -> <class 'semantic_release.hvcs.Github'> debug: get_hvcs() debug: get_hvcs -> <class 'semantic_release.hvcs.Github'> debug: push_new_version(, auth_token='***', owner='***', name='pmp-otk-sandbox', branch=main, domain='github.com') error: Cmd('git') failed due to: exit code(128) error: cmdline: git push ***github.com/***/pmp-otk-sandbox.git main error: stderr: 'remote: Write access to repository not granted. error: fatal: unable to access 'https://github.com/***/pmp-otk-sandbox.git/': The requested URL returned error: 403'
预期行为:成功递增版本号,无写入权限问题。提交信息示例:git commit -m "fix: we fixed the damn bug"
解决方案
修正actions/checkout配置,确保Git写入权限正常
actions/checkout@v2默认会保留仓库的默认凭证,可能和自定义PAT冲突。修改checkout步骤禁用默认凭证,然后手动配置带token的远程仓库地址:- uses: actions/checkout@v2 with: fetch-depth: 0 persist-credentials: false # 禁用默认凭证 - name: 配置Git远程地址 run: | git remote set-url origin https://__token__:${{ secrets.TOKEN }}@github.com/${{ github.repository }}.git验证细粒度PAT的权限与绑定范围
若使用细粒度PAT,需确认:- 仓库权限中
Contents设置为读写; - PAT已绑定到目标私有仓库(组织仓库需确认组织允许该PAT访问);
- 未勾选不必要的权限,避免权限冲突。
- 仓库权限中
检查分支保护规则
如果main分支设置了分支保护(如强制PR合并、审批要求),直接push版本提交会被拦截。解决方式:- 在分支保护规则中,允许PAT对应的用户绕过保护;
- 或修改semantic-release配置,通过创建PR提交版本更新。
使用GitHub自带的GITHUB_TOKEN替代自定义PAT
若无特殊权限需求,可直接用Actions自动生成的GITHUB_TOKEN:- 进入仓库Settings > Actions > General,勾选"Workflow permissions"下的"Read and write permissions";
- 修改Action配置:
- uses: actions/checkout@v2 with: fetch-depth: 0 persist-credentials: false - name: Python Semantic Release uses: relekang/python-semantic-release@master with: github_token: ${{ secrets.GITHUB_TOKEN }} repository_username: x-access-token
内容的提问来源于stack exchange,提问作者Shawn Esquivel
相关产品推荐
相关产品推荐

