python auth_error ai_generated true

WARNING: The package 'internal-utils' was found on PyPI, but your organization's private index also hosts a package with the same name. pip selected PyPI because it has a higher version.

ID: python/pip-dependency-confusion-internal-package

Also available as: JSON · Markdown · 中文
80%Fix Rate
86%Confidence
0Evidence
2025-08-25First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

Root Cause

pip's default index priority allows a public package to shadow an internal package with the same name, a dependency-confusion attack vector.

generic

中文

pip 的默认索引优先级允许公共包遮蔽同名的内部包,这是依赖混淆攻击的途径。

Workarounds

  1. 90% success
    pip install --index-url https://internal.example.com/simple internal-utils
  2. 80% success
    In pip.conf: `[global]\nindex-url = https://internal.example.com/simple\nextra-index-url = https://pypi.org/simple` and use a resolver that respects priority (e.g., uv with `--index-strategy unsafe-best-match` disabled).
  3. 95% success
    Register placeholder packages on PyPI for all internal names to prevent squatting.

Dead Ends

Common approaches that don't work:

  1. 90% fail

    Trusted-host only affects TLS verification, not index priority.

  2. 70% fail

    Pinning the version does not prevent pip from fetching that version from PyPI if it exists there.

  3. 85% fail

    Extra indexes are merged with PyPI, so the confusion risk remains.