{
  "id": "python/pip-dependency-confusion-internal-package",
  "signature": "WARNING: The package 'internal-utils' was found on PyPI, but your organization's private index also hosts a package with the same name. pip selected PyPI because it has a higher version.",
  "signature_zh": "警告：在 PyPI 上找到了包 'internal-utils'，但您组织的私有索引也托管了同名包。由于 PyPI 上的版本更高，pip 选择了 PyPI。",
  "regex": "WARNING:\\ The\\ package\\ 'internal\\-utils'\\ was\\ found\\ on\\ PyPI,\\ but\\ your\\ organization's\\ private\\ index\\ also\\ hosts\\ a\\ package\\ with\\ the\\ same\\ name\\.\\ pip\\ selected\\ PyPI\\ because\\ it\\ has\\ a\\ higher\\ version\\.",
  "domain": "python",
  "category": "auth_error",
  "subcategory": null,
  "root_cause": "pip's default index priority allows a public package to shadow an internal package with the same name, a dependency-confusion attack vector.",
  "root_cause_type": "generic",
  "root_cause_zh": "pip 的默认索引优先级允许公共包遮蔽同名的内部包，这是依赖混淆攻击的途径。",
  "versions": [
    {
      "version": "3.8",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "3.9",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "3.10",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "3.11",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "3.12",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    }
  ],
  "os_specific": {},
  "dead_ends": [
    {
      "action": "",
      "why_fails": "Trusted-host only affects TLS verification, not index priority.",
      "fail_rate": 0.9,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "Pinning the version does not prevent pip from fetching that version from PyPI if it exists there.",
      "fail_rate": 0.7,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "Extra indexes are merged with PyPI, so the confusion risk remains.",
      "fail_rate": 0.85,
      "condition": "",
      "sources": []
    }
  ],
  "workarounds": [
    {
      "action": "",
      "success_rate": 0.9,
      "how": "pip install --index-url https://internal.example.com/simple internal-utils",
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "success_rate": 0.8,
      "how": "In pip.conf: `[global]\\nindex-url = https://internal.example.com/simple\\nextra-index-url = https://pypi.org/simple` and use a resolver that respects priority (e.g., uv with `--index-strategy unsafe-best-match` disabled).",
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "success_rate": 0.95,
      "how": "Register placeholder packages on PyPI for all internal names to prevent squatting.",
      "condition": "",
      "sources": []
    }
  ],
  "workarounds_zh": [],
  "transition_graph": {
    "leads_to": [],
    "preceded_by": [],
    "frequently_confused_with": []
  },
  "official_doc_url": null,
  "official_doc_section": null,
  "error_code": null,
  "verification_tier": "ai_generated",
  "confidence": 0.86,
  "fix_success_rate": 0.8,
  "resolvable": "true",
  "first_seen": "2025-08-25",
  "last_confirmed": "2025-01-01",
  "last_updated": "2025-01-01",
  "evidence_count": 0,
  "tags": [],
  "locale": "en",
  "aliases": []
}