You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CircleCI中semantic-release报EINVALIDGHTOKEN无效GitHub令牌求助

问题:CircleCI结合semantic-release自动化发布时出现EINVALIDGHTOKEN错误

我在用CircleCI配合semantic-release做自动化发布时,碰到了EINVALIDGHTOKEN错误,提示GitHub令牌无效。我已经在CircleCI的环境变量里配置了GitHub个人访问令牌和NPM令牌,NPM令牌验证通过,但GitHub令牌一直验证失败。以下是相关配置文件和错误日志,求帮忙排查解决。


相关配置文件

config.yml

version: 2.1
orbs:
  node: circleci/node@1.1.6
jobs:
  test-build-and-publish:
    executor:
      name: node/default
    steps:
      - checkout
      - node/with-cache:
          steps:
            - run:
                name: Install nvm
                command: |
                  cd ..
                  curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.36.0/install.sh | bash
                  echo 'export NVM_DIR=$HOME/.nvm' >> $BASH_ENV
                  echo 'source $NVM_DIR/nvm.sh' >> $BASH_ENV
            - run:
                name: Set node to version required by application for future circleci steps
                command: |
                  cd ..
                  nvm install 16.17.1
                  NODE_VERSION=$(node -v)
                  nvm alias default ${NODE_VERSION//v}
            - run: yarn install            #  Install dependencies
            - run: yarn semantic-release   #  Release to npm
workflows:
  test-build-and-publish:
    jobs:
      - test-build-and-publish

release.config.js

{
    "branches": [
        {name: 'main'},
      ],
    "plugins": [
      "@semantic-release/commit-analyzer",
      "@semantic-release/release-notes-generator",
      ["@semantic-release/github", {
        "assets": ["dist/**"]
        }],
      ["@semantic-release/exec", {
        "prepareCmd": "./update-version.sh ${nextRelease.version}",
       }],
      "@semantic-release/git"
    ],
    "preset": "react"
  }

package.json(相关片段)

{ ...
"release": {
    "branches": [
      "main",
      "next"
    ],
    "tagFormat": "v${version}",
    "verifyConditions": [
      "@semantic-release/changelog",
      "@semantic-release/github",
      "@semantic-release/npm"
    ],
    "prepare": [
      "@semantic-release/changelog",
      "@semantic-release/npm"
    ],
    "publish": [
      "@semantic-release/github",
      "@semantic-release/npm"
    ],
    "fail": [
      "@semantic-release/github"
    ],
    "githubUrl": "https://github.ibm.com",
    "githubApiPathPrefix": "/api/v3"
  }
 }

错误日志

yarn run v1.22.15
$ semantic-release
[8:46:42 AM] [semantic-release] › ℹ  Running semantic-release version 19.0.5
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/changelog"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/github"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/npm"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "analyzeCommits" from "@semantic-release/commit-analyzer"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "generateNotes" from "@semantic-release/release-notes-generator"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "prepare" from "@semantic-release/changelog"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "prepare" from "@semantic-release/npm"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "publish" from "@semantic-release/github"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "publish" from "@semantic-release/npm"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "addChannel" from "@semantic-release/npm"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "addChannel" from "@semantic-release/github"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "success" from "@semantic-release/github"
[8:46:42 AM] [semantic-release] › ✔  Loaded plugin "fail" from "@semantic-release/github"
[8:46:43 AM] [semantic-release] › ✔  Run automated release from branch main on repository https://github.com/dhaval1624/dp-react.git
[8:46:43 AM] [semantic-release] › ✔  Allowed to push to the Git repository
[8:46:43 AM] [semantic-release] › ℹ  Start step "verifyConditions" of plugin "@semantic-release/changelog"
[8:46:43 AM] [semantic-release] › ✔  Completed step "verifyConditions" of plugin "@semantic-release/changelog"
[8:46:43 AM] [semantic-release] › ℹ  Start step "verifyConditions" of plugin "@semantic-release/github"
[8:46:43 AM] [semantic-release] [@semantic-release/github] › ℹ  Verify GitHub authentication (https://github.ibm.com/api/v3)
[8:46:43 AM] [semantic-release] › ✖  Failed step "verifyConditions" of plugin "@semantic-release/github"
[8:46:43 AM] [semantic-release] › ℹ  Start step "verifyConditions" of plugin "@semantic-release/npm"
[8:46:43 AM] [semantic-release] [@semantic-release/npm] › ℹ  Verify authentication for registry https://registry.npmjs.org/
[8:46:43 AM] [semantic-release] [@semantic-release/npm] › ℹ  Reading npm config from /home/circleci/project/.npmrc
[8:46:43 AM] [semantic-release] [@semantic-release/npm] › ℹ  Wrote NPM_TOKEN to /tmp/c6eeec1742267b199ff3674c478e84bb/.npmrc
dhaval164
[8:46:44 AM] [semantic-release] › ✔  Completed step "verifyConditions" of plugin "@semantic-release/npm"
[8:46:44 AM] [semantic-release] › ℹ  Start step "fail" of plugin "@semantic-release/github"
[8:46:44 AM] [semantic-release] [@semantic-release/github] › ℹ  Verify GitHub authentication (https://github.ibm.com/api/v3)
[8:46:44 AM] [semantic-release] › ✖  Failed step "fail" of plugin "@semantic-release/github"
[8:46:44 AM] [semantic-release] › ✖  EINVALIDGHTOKEN Invalid GitHub token.
The GitHub token configured in the GH_TOKEN or GITHUB_TOKEN environment variable must be a valid personal token allowing to push to the repository dhaval1624/dp-react.

Please make sure to set the GH_TOKEN or GITHUB_TOKEN environment variable in your CI with the exact value of the GitHub personal token.

[8:46:44 AM] [semantic-release] › ✖  EINVALIDGHTOKEN Invalid GitHub token.
The GitHub token configured in the GH_TOKEN or GITHUB_TOKEN environment variable must be a valid personal token allowing to push to the repository dhaval1624/dp-react.

Please make sure to set the GH_TOKEN or GITHUB_TOKEN environment variable in your CI with the exact value of the GitHub personal token.

AggregateError: 
    SemanticReleaseError: Invalid GitHub token.
        at module.exports (/home/circleci/project/node_modules/@semantic-release/github/lib/get-error.js:6:10)
        at module.exports (/home/circleci/project/node_modules/@semantic-release/github/lib/verify.js:87:21)
        at async verifyConditions (/home/circleci/project/node_modules/@semantic-release/github/index.js:27:3)
        at async validator (/home/circleci/project/node_modules/semantic-release/lib/plugins/normalize.js:34:24)
        at async /home/circleci/project/node_modules/semantic-release/lib/plugins/pipeline.js:37:34
        at async Promise.all (index 0)
        at async next (/home/circleci/project/node_modules/p-reduce/index.js:16:18)
    at /home/circleci/project/node_modules/semantic-release/lib/plugins/pipeline.js:54:11
    at processTicksAndRejections (node:internal/process/task_queues:96:5)
    at async Object.pluginsConf.<computed> [as verifyConditions] (/home/circleci/project/node_modules/semantic-release/lib/plugins/index.js:80:11)
    at async run (/home/circleci/project/node_modules/semantic-release/index.js:103:3)
    at async module.exports (/home/circleci/project/node_modules/semantic-release/index.js:269:22)
    at async module.exports (/home/circleci/project/node_modules/semantic-release/cli.js:55:5)error Command failed with exit code 1.
info Visit https://yarnpkg.com/en/docs/cli/run for documentation about this command.

Exited with code exit status 1

解决方案

1. 确认令牌环境变量名称

针对GitHub企业版(github.ibm.com),semantic-release优先读取GH_TOKEN环境变量,而非公共GitHub常用的GITHUB_TOKEN。检查CircleCI项目设置中的环境变量名称是否为GH_TOKEN,且值无多余空格或换行。

2. 检查GitHub令牌权限

生成的个人访问令牌必须具备以下权限:

  • 完整的repo权限(支持提交代码、创建发布版本)
  • 若涉及包发布,需勾选write:packages权限
    确保令牌未过期,且权限范围覆盖需求。

3. 统一配置文件,修复企业版地址缺失问题

你同时存在release.config.js和package.json中的release配置,semantic-release会优先读取release.config.js,但该文件的GitHub插件未配置企业版地址,导致验证时可能指向公共GitHub。修改release.config.js的GitHub插件配置:

["@semantic-release/github", {
  "assets": ["dist/**"],
  "githubUrl": "https://github.ibm.com",
  "githubApiPathPrefix": "/api/v3"
}],

或删除其中一个配置文件,避免冲突。

4. 验证令牌在CircleCI中的可用性

在CircleCI的job中添加临时调试步骤(验证后立即删除,避免令牌泄露):

- run:
    name: Check GH_TOKEN
    command: echo $GH_TOKEN

确认环境变量正常加载。

5. 简化Node环境配置

原配置手动安装nvm可能导致环境变量传递问题,改用CircleCI node orb的官方命令管理版本:

- node/install:
    node-version: '16.17.1'

替换原有的nvm安装步骤,确保环境稳定。


内容的提问来源于stack exchange,提问作者Dhaval Parmar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 00:15:44