GitHub Actions自动推送NuGet包至GitHub Packages遇授权问题求助
Let's break down your issues and fix them step by step:
Why You're Seeing These Errors
Authentication Failure (Direct Push)
GitHub Packages' NuGet feed doesn't support the--api-keyparameter like nuget.org does. Instead, it requires authentication via a GitHub username + Personal Access Token (PAT) as the password. That's why your direct push attempt threw an auth error.Password Encryption Error (Adding Source)
The Ubuntu runner (a non-Windows platform) doesn't support password encryption for NuGet sources. This is why thedotnet nuget add sourcecommand fails—we can avoid this entirely by skipping the source-add step.
Step-by-Step Fixes
1. Verify Your PAT Permissions
First, double-check that your PUBLISH_TO_GITHUB_COM token has the required scopes:
write:packages: Mandatory for pushing packages to GitHub Packagesrepo: Required if your repository is private (optional for public repos)
You can regenerate the token in GitHub's Settings > Developer settings > Personal access tokens and make sure these scopes are checked.
2. Update Your GitHub Actions Workflow
Remove the AddGithubSource step entirely, and modify the PushGithub step to authenticate correctly without adding a source. Here are two reliable approaches:
Option 1: Use Environment Variable (Recommended)
This leverages the NUGET_AUTH_TOKEN environment variable that dotnet nuget automatically recognizes for authentication:
- name: PushGithub env: NUGET_AUTH_TOKEN: ${{secrets.PUBLISH_TO_GITHUB_COM}} run: dotnet nuget push *.nupkg --source https://nuget.pkg.github.com/MintPlayer/index.json --username PieterjanDeClippel --skip-duplicate
Option 2: Directly Pass Credentials in Command
GitHub Actions automatically masks secrets in logs, so it's safe to pass your PAT directly as the password:
- name: PushGithub run: dotnet nuget push *.nupkg --source https://nuget.pkg.github.com/MintPlayer/index.json --username PieterjanDeClippel --password ${{secrets.PUBLISH_TO_GITHUB_COM}} --skip-duplicate
3. Quick Sanity Checks
- Ensure your NuGet package ID starts with your GitHub organization name (
MintPlayer), e.g.,MintPlayer.SeasonChecker— GitHub Packages enforces this to prevent namespace conflicts. - Confirm your PAT hasn't expired or been revoked.
After making these changes, your workflow should successfully push to both nuget.org and GitHub Packages.
内容的提问来源于stack exchange,提问作者Pieterjan

