GitHub Action调用Search API无结果,是权限问题还是遗漏配置?
问题原因及解决方案
核心问题:GITHUB_TOKEN无Search API访问权限
你本地用个人访问令牌(PAT)能正常返回结果,但Action里用默认的GITHUB_TOKEN不行,本质是权限范围的差异:
- 个人PAT如果配置了
repo权限,能访问全局的Search API; - GitHub Action默认生成的
GITHUB_TOKEN仅拥有当前仓库的资源权限,无法调用全局的Search API,哪怕Workflow权限设为「Read and write」也没用。
解决方案1:改用仓库专属API(推荐)
放弃Search API,直接调用仓库的PR查询接口,这个接口属于仓库资源,GITHUB_TOKEN默认权限就能访问。修改后的完整Workflow代码如下:
name: Cleanup deploy-in-dev label on: workflow_dispatch: schedule: - cron: "15 1 * * *" jobs: cleanup: runs-on: ubuntu-latest steps: - name: Search label deploy-in-dev run: |- curl \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer ${GITHUB_TOKEN}" \ -H "X-GitHub-Api-Version: 2022-11-28" \ "https://api.github.com/repos/private-org/example/pulls?state=open&labels=deploy-in-dev" \ | grep "\"number\":" \ | sed 's/.*\"number\": \([0-9]*\),/\1/g' \ | while IFS= read -r pr_number; do echo "Found pr with label with pr number ${pr_number}" done
解决方案2:使用个人访问令牌(PAT)
如果一定要用Search API,需要在仓库的Secrets中添加你的PAT(命名为REPO_PAT),然后在Action中替换令牌:
# 仅修改run部分的Authorization行 run: |- curl \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer ${REPO_PAT}" \ -H "X-GitHub-Api-Version: 2022-11-28" \ "https://api.github.com/search/issues?q=repo:private-org/example+is:pull-request+is:open+label:deploy-in-dev" \ | grep "\"number\":" \ | sed 's/.*\"number\": \([0-9]*\),/\1/g' \ | while IFS= read -r pr_number; do echo "Found pr with label with pr number ${pr_number}" done
额外优化:显式声明权限
可以在jobs里显式声明PR读取权限,避免潜在的权限继承问题:
jobs: cleanup: runs-on: ubuntu-latest permissions: pull-requests: read steps: # ... 后续步骤不变
内容的提问来源于stack exchange,提问作者deflomu
相关产品推荐
相关产品推荐

