python
auth_error
ai_generated
true
WARNING: The package 'internal-utils' was found on PyPI, but your organization's private index also hosts a package with the same name. pip selected PyPI because it has a higher version.
ID: python/pip-dependency-confusion-internal-package
80%Fix Rate
86%Confidence
0Evidence
2025-08-25First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
Root Cause
pip's default index priority allows a public package to shadow an internal package with the same name, a dependency-confusion attack vector.
generic中文
pip 的默认索引优先级允许公共包遮蔽同名的内部包,这是依赖混淆攻击的途径。
Workarounds
-
90% success
pip install --index-url https://internal.example.com/simple internal-utils
-
80% success
In pip.conf: `[global]\nindex-url = https://internal.example.com/simple\nextra-index-url = https://pypi.org/simple` and use a resolver that respects priority (e.g., uv with `--index-strategy unsafe-best-match` disabled).
-
95% success
Register placeholder packages on PyPI for all internal names to prevent squatting.
Dead Ends
Common approaches that don't work:
-
90% fail
Trusted-host only affects TLS verification, not index priority.
-
70% fail
Pinning the version does not prevent pip from fetching that version from PyPI if it exists there.
-
85% fail
Extra indexes are merged with PyPI, so the confusion risk remains.