ci: fall back to a PAT and self-diagnose the publish step
publish / npm (push) Failing after 31s

The first tagged run failed inside the publish step within a second, which is the shape of an auth rejection rather than a build problem. The step now prefers a repository NPM_TOKEN secret when one exists, prints the effective registry and a masked token, and runs npm whoami so a re-run names the cause instead of just failing.
This commit is contained in:
pyh
2026-09-30 11:05:33 +08:00
parent 37468d6ac9
commit 733f0ba456
2 changed files with 33 additions and 9 deletions
+8 -2
View File
@@ -77,13 +77,19 @@ npm config set //gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken=<带 pa
### 发布到 Gitea 的 npm 仓库
仓库自带工作流 [`.gitea/workflows/publish.yml`](.gitea/workflows/publish.yml):推送 `v*` 标签(或在 Actions 页面手动运行)就会把当前版本发布到 `https://gitea.iwake.top/api/packages/dsh-plugin/npm/`,用的是 Gitea 内置的任务令牌,不需要额外配置密钥。
仓库自带工作流 [`.gitea/workflows/publish.yml`](.gitea/workflows/publish.yml):推送 `v*` 标签(或在 Actions 页面手动 Run workflow)就会把该版本发布到 `https://gitea.iwake.top/api/packages/dsh-plugin/npm/`。工作流会校验标签与 `package.json` 的版本一致,不一致直接失败。
```bash
git tag -a v1.0.1 -m "v1.0.1" && git push origin v1.0.1
```
前提:实例启用了 Actions 并注册了 runner(`runs-on` 的标签要与 runner 一致),且 Actions 的令牌权限没有把 `packages` 限制成只读(组织 Settings → Actions → General)。
发布凭据按顺序取:仓库 secret `NPM_TOKEN`(带 `package` 写权限的个人访问令牌)→ 没有则退回 Gitea 内置任务令牌 `${{ secrets.GITEA_TOKEN }}`(工作流已声明 `permissions: packages: write`)。
前提与排查:
- 实例启用了 Actions 并注册了 runner(`runs-on: ubuntu-latest` 要与 runner 的标签一致);
- 若组织把 Actions 令牌上限设成只读,或任务令牌对包命名空间没有写权限,发布步骤会很快失败:在仓库 Settings → Actions → Secrets 添加 `NPM_TOKEN` 即可,工作流会自动改用它;
- 失败时先看该步骤日志里 `npm whoami` 的输出:打印出用户名说明令牌可用(错误就只可能是版本已存在或包名不合法),报 `E401/E403` 则是令牌无效或权限不足。
手工发布等价于: