GHA_SECRET_FORK cicd auth_error ai_generated partial

错误:组织机密 MY_ORG_SECRET 未设置或为空。组织机密不适用于复刻仓库。

Error: Secret MY_ORG_SECRET is not set or is empty. Organization secrets are not available to forks.

ID: cicd/github-actions-secret-missing-org

其他格式: JSON · Markdown 中文 · English
80%修复率
88%置信度
1证据数
2023-11-15首次发现

版本兼容性

版本状态引入弃用备注
GitHub Actions hosted runners (ubuntu-22.04, ubuntu-24.04) active
GitHub Enterprise Server 3.8+ active

根因分析

GitHub Actions 工作流尝试从复刻仓库访问组织级机密,但 GitHub 安全策略禁止此操作,以防止机密泄露给外部贡献者。

English

GitHub Actions workflow attempts to access an organization-level secret from a forked repository, which is blocked by GitHub's security policy to prevent exposing secrets to external contributors.

generic

官方文档

https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#using-secrets-in-a-workflow

解决方案

  1. Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
  2. Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`

无效尝试

常见但无效的做法:

  1. 85% 失败

    Adding the secret as a repository-level secret on the fork does not work because the original workflow references the organization-level secret name and the fork cannot see it.

  2. 70% 失败

    Changing the workflow to use `env:` instead of `secrets:` does not resolve the issue as the secret value is still required and must come from a context that the fork cannot access.