python auth_error ai_generated partial

错误:因依赖混淆无法安装:包 'internal-lib' 从公共 PyPI 而非私有索引解析

ERROR: Cannot install because of a dependency confusion: package 'internal-lib' resolved from public PyPI instead of private index

ID: python/pip-extra-index-url-dependency-confusion

其他格式: JSON · Markdown 中文 · English
80%修复率
86%置信度
0证据数
2024-10-05首次发现

版本兼容性

版本状态引入弃用备注
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

根因分析

使用 --extra-index-url 时,pip 会合并所有索引的候选包并选择最高版本。同名的恶意公共包如果版本更高,会遮蔽预期的私有包。

English

When --extra-index-url is used, pip merges candidates from all indexes and picks the highest version. A malicious public package with the same name and higher version can shadow the intended private one.

generic

解决方案

  1. 95% 成功率
    pip install --index-url https://private/simple 'internal-lib==1.2.3'
  2. 90% 成功率
    pip install --index-url https://private/simple --no-index internal-lib  # only if index has it
  3. 85% 成功率
    pip install -c constraints.txt --extra-index-url https://private/simple internal-lib

无效尝试

常见但无效的做法:

  1. 95% 失败

    Still merges with PyPI; the public version wins if higher.

  2. 90% 失败

    Trust does not affect resolution order.