You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions工作流推送失败(权限拒绝)求助

GitHub Actions工作流推送失败(403权限错误)

我几天前创建了首个GitHub Actions工作流,用于自动化Next.js应用的若干脚本,但始终无法正常运行。尝试过多种修改来解决权限问题均无效,以下是我的automated-data-updates.yml文件:

name: Automated Data Updates

on:
  schedule:
    # Friday script - Fridays at 14:00 UTC (2:00 PM)
    - cron: "0 14 * * 5"
    # Tuesday script - Tuesdays at 07:00 UTC (7:00 AM)
    - cron: "0 7 * * 2"
    # Fetch players - Fridays at 15:00 UTC
    - cron: "0 15 * * 5"
    # Fetch players - Mondays at 15:00 UTC
    - cron: "0 15 * * 1"
    # Fetch players - Wednesdays at 15:00 UTC
    - cron: "0 15 * * 3"
  workflow_dispatch: # Allow manual triggering

jobs:
  friday-update:
    if: github.event.schedule == '0 14 * * 5' || (github.event_name == 'workflow_dispatch' && github.event.inputs.script == 'friday')
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4
        # Removed 'with: token: ${{ secrets.GITHUB_TOKEN }}'

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: "18"
          cache: "npm"

      - name: Install dependencies
        run: npm ci

      - name: Run Friday Script
        run: npm run friday-check
        env:
          USERNAME: ${{ secrets.USERNAME }}
          PASSWORD: ${{ secrets.PASSWORD }}

      - name: Debug GH_PAT
        run: echo "GH_PAT is set ${{ secrets.GH_PAT != '' }}"

      - name: Commit and push changes
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --local user.email "action@github.com"
          git config --local user.name "GitHub Action"
          git add app/data/players/*.json
          if git diff --staged --quiet; then
            echo "No changes to commit"
          else
            git commit -m "🤖 Weekly GameShape & DMI update - $(date +'%Y-%m-%d')"
            git remote set-url origin https://x-access-token:${GH_PAT}@github.com/${{ github.repository }}
            git remote -v
            git push origin main
          fi

      - name: Trigger Netlify rebuild
        run: |
          curl -X POST -d {} ${{ secrets.NETLIFY_BUILD_HOOK }}

  tuesday-check:
    if: github.event.schedule == '0 7 * * 2' || (github.event_name == 'workflow_dispatch' && github.event.inputs.script == 'tuesday')
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4
        # Removed 'with: token: ${{ secrets.GITHUB_TOKEN }}'

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: "18"
          cache: "npm"

      - name: Install dependencies
        run: npm ci

      - name: Run Tuesday Script
        run: npm run monday-check
        env:
          USERNAME: ${{ secrets.USERNAME }}
          PASSWORD: ${{ secrets.PASSWORD }}

      - name: Debug GH_PAT
        run: echo "GH_PAT is set ${{ secrets.GH_PAT != '' }}"

      - name: Commit and push changes
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --local user.email "action@github.com"
          git config --local user.name "GitHub Action"
          git add app/data/teams/*.json app/data/players/*.json
          if git diff --staged --quiet; then
            echo "No new players found"
          else
            git commit -m "🆕 New players check - $(date +'%Y-%m-%d')"
            git remote set-url origin https://x-access-token:${GH_PAT}@github.com/${{ github.repository }}
            git remote -v
            git push origin main
          fi

      - name: Trigger Netlify rebuild
        run: |
          curl -X POST -d {} ${{ secrets.NETLIFY_BUILD_HOOK }}

  fetch-players:
    if: github.event.schedule == '0 15 * * 5' || github.event.schedule == '0 15 * * 1' || github.event.schedule == '0 15 * * 3' || (github.event_name == 'workflow_dispatch' && github.event.inputs.script == 'fetch-players')
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4
        # Removed 'with: token: ${{ secrets.GITHUB_TOKEN }}'

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: "18"
          cache: "npm"

      - name: Install dependencies
        run: npm ci

      - name: Run Fetch Players Script
        run: npm run fetch-players
        env:
          USERNAME: ${{ secrets.USERNAME }}
          PASSWORD: ${{ secrets.PASSWORD_2 }}

      - name: Debug GH_PAT
        run: echo "GH_PAT is set ${{ secrets.GH_PAT != '' }}"

      - name: Commit and push changes
        env:
          GH_PAT: ${{ secrets.GH_PAT }}
        run: |
          git config --local user.email "action@github.com"
          git config --local user.name "GitHub Action"
          git add app/data/scoutedPlayers/*.json
          if git diff --staged --quiet; then
            echo "No changes to commit"
          else
            git commit -m "🤖 Scouted players update - $(date +'%Y-%m-%d')"
            git remote set-url origin https://x-access-token:${GH_PAT}@github.com/${{ github.repository }}
            git remote -v
            git push origin main
          fi

      - name: Trigger Netlify rebuild
        run: |
          curl -X POST -d {} ${{ secrets.NETLIFY_BUILD_HOOK }}

补充信息:

  • PAT处于活跃状态,未过期
  • PAT由仓库所有者账号创建,具备推送权限
  • 无分支保护规则
  • PAT在本地可正常执行推送操作

工作流运行时,推送步骤总会失败,报错信息如下:

remote: Permission to user/repo.git denied to github-actions[bot].
fatal: unable to access 'https://github.com/user/repo/': The requested URL returned error: 403
Error: Process completed with exit code 128.

内容的提问来源于stack exchange,提问作者FlowRan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 10:44:51