# 警告：在 PyPI 上找到了包 'internal-utils'，但您组织的私有索引也托管了同名包。由于 PyPI 上的版本更高，pip 选择了 PyPI。

- **ID:** `python/pip-dependency-confusion-internal-package`
- **领域:** python
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

pip 的默认索引优先级允许公共包遮蔽同名的内部包，这是依赖混淆攻击的途径。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (90% 成功率)
   ```
   pip install --index-url https://internal.example.com/simple internal-utils
   ```
2. **** (80% 成功率)
   ```
   In pip.conf: `[global]\nindex-url = https://internal.example.com/simple\nextra-index-url = https://pypi.org/simple` and use a resolver that respects priority (e.g., uv with `--index-strategy unsafe-best-match` disabled).
   ```
3. **** (95% 成功率)
   ```
   Register placeholder packages on PyPI for all internal names to prevent squatting.
   ```

## 无效尝试

- **** — Trusted-host only affects TLS verification, not index priority. (90% 失败率)
- **** — Pinning the version does not prevent pip from fetching that version from PyPI if it exists there. (70% 失败率)
- **** — Extra indexes are merged with PyPI, so the confusion risk remains. (85% 失败率)
