python
auth_error
ai_generated
partial
错误:因依赖混淆无法安装:包 'internal-lib' 从公共 PyPI 而非私有索引解析
ERROR: Cannot install because of a dependency confusion: package 'internal-lib' resolved from public PyPI instead of private index
ID: python/pip-extra-index-url-dependency-confusion
80%修复率
86%置信度
0证据数
2024-10-05首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
根因分析
使用 --extra-index-url 时,pip 会合并所有索引的候选包并选择最高版本。同名的恶意公共包如果版本更高,会遮蔽预期的私有包。
English
When --extra-index-url is used, pip merges candidates from all indexes and picks the highest version. A malicious public package with the same name and higher version can shadow the intended private one.
解决方案
-
95% 成功率
pip install --index-url https://private/simple 'internal-lib==1.2.3'
-
90% 成功率
pip install --index-url https://private/simple --no-index internal-lib # only if index has it
-
85% 成功率
pip install -c constraints.txt --extra-index-url https://private/simple internal-lib
无效尝试
常见但无效的做法:
-
95% 失败
Still merges with PyPI; the public version wins if higher.
-
90% 失败
Trust does not affect resolution order.