发布NuGet包到GitHub Packages时GITHUB_TOKEN报403 Forbidden
问题描述
我参考相关文档配置了GitHub Actions工作流,用于构建、测试并发布.NET库到GitHub Packages,但推送时遇到403权限错误:
Pushing MagicLibrary.0.1.3.nupkg to 'https://nuget.pkg.github.com/vivere-dally'...
PUT https://nuget.pkg.github.com/vivere-dally/
warn : Your request could not be authenticated by the GitHub Packages service. Please ensure your access token is valid and has the appropriate scopes configured.
Forbidden https://nuget.pkg.github.com/vivere-dally/ 218ms
error: Response status code does not indicate success: 403 (Forbidden).
我的工作流文件如下:
# This workflow will build a .NET project # For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-net name: Release on: push: tags: - "v[0-9]+.[0-9]+.[0-9]+" jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Verify commit exists in origin/main run: | git fetch --no-tags --prune --depth=1 origin +refs/heads/*:refs/remotes/origin/* git branch --remote --contains | grep origin/main - name: Set VERSION env var from tag run: echo "VERSION=${GITHUB_REF/refs\/tags\/v/}" >> $GITHUB_ENV - name: Setup .NET uses: actions/setup-dotnet@v3 with: dotnet-version: 6.0.x - name: Restore dependencies run: dotnet restore working-directory: ./MagicLibrary - name: Build run: dotnet build --configuration Release /p:Version=${VERSION} --no-restore working-directory: ./MagicLibrary - name: Test run: dotnet test --configuration Release /p:Version=${VERSION} --no-build --verbosity normal working-directory: ./MagicLibrary - name: Pack run: dotnet pack --configuration Release /p:Version=${VERSION} --no-build --output . working-directory: ./MagicLibrary - name: Push run: dotnet nuget push MagicLibrary.${VERSION}.nupkg --source "https://nuget.pkg.github.com/vivere-dally/index.json" --api-key ${{ secrets.GITHUB_TOKEN }} working-directory: ./MagicLibrary
请问为何GITHUB_TOKEN没有所需的权限?
原因及解决方法
默认的GITHUB_TOKEN权限不足,无法推送包到GitHub Packages,核心原因及解决方式如下:
1. 默认权限范围受限
GitHub Actions提供的默认GITHUB_TOKEN仅拥有contents: read基础权限,而推送NuGet包需要packages: write权限。你需要在工作流中显式声明权限:
修改工作流的jobs.build部分,添加permissions配置:
jobs: build: runs-on: ubuntu-latest permissions: contents: read packages: write # 新增该权限,允许推送包到GitHub Packages
2. 包所有权与仓库不匹配
如果你的NuGet包ID前缀和当前仓库的用户名/组织名不一致(比如你的目标是vivere-dally),默认GITHUB_TOKEN会因所有权不匹配被拒绝。需确保:
- 包ID的前缀与你的GitHub用户名或组织名完全一致
- 工作流运行在对应所有权的仓库中
额外备选方案
若上述配置后仍报错,可以使用**个人访问令牌(PAT)**替代默认GITHUB_TOKEN:
- 在GitHub账号设置中创建一个PAT,勾选
write:packages和read:packages权限 - 将该PAT添加到仓库的Secrets中(命名为
GH_PAT) - 修改Push步骤的命令:
dotnet nuget push MagicLibrary.${VERSION}.nupkg --source "https://nuget.pkg.github.com/vivere-dally/index.json" --api-key ${{ secrets.GH_PAT }}
内容的提问来源于stack exchange,提问作者Vivere

