如何使Github Package Registry中的包“消失”?实操遇阻求助
First, let's confirm the official GitHub note:
You can't directly "delete" a package, but it will "disappear" once all its versions are removed.
Since you're dealing with an accidentally published Gradle package caused by a typo in your publish task, here's how to resolve this—first fixing your GraphQL API issues, then covering a simpler alternative if you have the GitHub CLI set up.
Fixing the GraphQL API Workflow (To Get Package & Version IDs)
Your earlier query failed because of JSON parsing errors in your curl command—you used double quotes around the entire payload, which conflicted with the double quotes inside the GraphQL query. Let's fix that step by step:
Step 1: Retrieve the Package ID & Its Version IDs
Use this corrected curl command (replace placeholders with your actual organization name and access token):
curl -X POST \ -H "Accept: application/vnd.github.package-deletes-preview+json" \ -H "Authorization: bearer YOUR_ACCESS_TOKEN" \ -d '{ "query": "query { organization(login: \"YOUR_ORGANIZATION_ACCOUNT\") { registryPackages(packageType: MAVEN) { edges { node { name id versions { edges { node { id } } } } } } }" }' \ https://api.github.com/graphql
- I added
packageType: MAVENto filter results to your Gradle-compatible package, making it easier to locate the accidental one. - The payload is wrapped in single quotes, with internal double quotes escaped using
\to avoid shell parsing conflicts.
This will return a JSON object containing your target package's id and all its associated version ids.
Step 2: Delete Each Package Version
Once you have a packageVersionId, use this mutation command to delete that version (replace the ID placeholder):
curl -X POST \ -H "Accept: application/vnd.github.package-deletes-preview+json" \ -H "Authorization: bearer YOUR_ACCESS_TOKEN" \ -d '{ "query": "mutation { deletePackageVersion(input:{packageVersionId:\"YOUR_PACKAGE_VERSION_ID\"}) { success }}" }' \ https://api.github.com/graphql
Run this command for every version of the accidental package. Once all versions are deleted, the package will no longer appear in the GitHub Package Registry.
Simpler Alternative: Use GitHub CLI (gh)
If you have the GitHub CLI installed and authenticated, this is far more straightforward:
- List all Maven/Gradle packages in your organization to confirm the target package name:
gh package list --org YOUR_ORGANIZATION_ACCOUNT --type maven - Delete all versions of the accidental package in one go (replace
PACKAGE_NAMEwith your package's name):gh package delete YOUR_ORGANIZATION_ACCOUNT/PACKAGE_NAME --yes
This command will wipe every version of the package immediately, and the package will disappear right after.
Troubleshooting Permissions
- Ensure your access token has the
write:packagesanddelete:packagesscopes. You can create a new token with these permissions in your GitHub account's Settings > Developer settings > Personal access tokens. - For the GraphQL API Explorer: You can paste a custom token with the required scopes into the "Headers" section (add a header named
Authorizationwith valuebearer YOUR_CUSTOM_TOKEN).
内容的提问来源于stack exchange,提问作者hb0

