# ERROR: Cannot install because of a dependency confusion: package 'internal-lib' resolved from public PyPI instead of private index

- **ID:** `python/pip-extra-index-url-dependency-confusion`
- **Domain:** python
- **Category:** auth_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

When --extra-index-url is used, pip merges candidates from all indexes and picks the highest version. A malicious public package with the same name and higher version can shadow the intended private one.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   pip install --index-url https://private/simple 'internal-lib==1.2.3'
   ```
2. **** (90% success)
   ```
   pip install --index-url https://private/simple --no-index internal-lib  # only if index has it
   ```
3. **** (85% success)
   ```
   pip install -c constraints.txt --extra-index-url https://private/simple internal-lib
   ```

## Dead Ends

- **** — Still merges with PyPI; the public version wins if higher. (95% fail)
- **** — Trust does not affect resolution order. (90% fail)
