自动创建PR无法触发Github Workflows的问题求助
我实现了一个每周运行一次的GitHub Actions Workflow,用于自动更新项目所有依赖并创建包含变更的PR,配置如下:
name: Automatic dependency update "on": workflow_dispatch: null schedule: - cron: 0 0 * * 1 jobs: update: name: Update to latest versions runs-on: - self-hosted - default-runner steps: - name: Checkout Project uses: actions/checkout@v2 - name: Install Java uses: actions/setup-java@v2 - name: Update Versions run: | ./gradlew useLatestVersions --info - name: Commit and open PR uses: peter-evans/create-pull-request@v3 with: commit-message: Update to latest versions committer: Update Bot <workflow@xxx.com> branch: auto-dependency-update base: dev delete-branch: true title: Automatic dependency update draft: false team-reviewers: XX/teamname body: Automated gradle dependency updates
但这个PR无法触发合并所需的常规Build pipeline Workflow,其配置如下:
name: Build pipeline "on": workflow_dispatch: null pull_request: branches: - dev push: branches: - '!master' - '**' defaults: run: shell: bash jobs: build: name: Compile runs-on: - self-hosted - default-runner steps: - name: Checkout code uses: actions/checkout@v2 - uses: actions/setup-java@v2 - name: Compile code run: | ./gradlew classes testClasses --info # ...
手动向该分支推送内容时Workflow会触发,但依赖更新Workflow自动创建分支并提交后却无法触发。我不想通过benc-uk/workflow-dispatch@v1等方式显式触发,希望保持更新机制的通用性,请问该如何解决?
这个问题的核心原因是GitHub Actions的默认token权限限制:当Workflow通过内置的GITHUB_TOKEN执行创建分支、提交代码等操作时,GitHub会自动跳过后续的Workflow触发,避免出现循环执行的情况。
要解决这个问题,无需显式触发Workflow,只需调整依赖更新Workflow的两处配置即可:
给
actions/checkout步骤添加persist-credentials: false
默认情况下,actions/checkout会将GITHUB_TOKEN写入本地git配置,导致后续提交操作默认使用这个受限的token。关闭该选项后,后续提交不会自动使用内置token。在
peter-evans/create-pull-request中指定自定义的个人访问令牌(PAT)
创建一个拥有repo权限的PAT,将其存储为仓库的Secrets(例如命名为DEPENDENCY_UPDATE_PAT),然后在PR创建步骤中指定使用这个token。
调整后的依赖更新Workflow配置如下:
name: Automatic dependency update "on": workflow_dispatch: null schedule: - cron: 0 0 * * 1 jobs: update: name: Update to latest versions runs-on: - self-hosted - default-runner steps: - name: Checkout Project uses: actions/checkout@v2 with: persist-credentials: false # 关闭默认的GITHUB_TOKEN自动写入 - name: Install Java uses: actions/setup-java@v2 - name: Update Versions run: | ./gradlew useLatestVersions --info - name: Commit and open PR uses: peter-evans/create-pull-request@v3 with: commit-message: Update to latest versions committer: Update Bot <workflow@xxx.com> branch: auto-dependency-update base: dev delete-branch: true title: Automatic dependency update draft: false team-reviewers: XX/teamname body: Automated gradle dependency updates token: ${{ secrets.DEPENDENCY_UPDATE_PAT }} # 使用自定义PAT
调整后,PR创建时的提交操作会使用你自定义的PAT,而非受限的内置GITHUB_TOKEN,GitHub就会正常触发Build pipeline Workflow,同时保持更新机制的通用性,无需额外的显式触发步骤。
内容的提问来源于stack exchange,提问作者Jens Baitinger

