# 错误：因依赖混淆无法安装：包 'internal-lib' 从公共 PyPI 而非私有索引解析

- **ID:** `python/pip-extra-index-url-dependency-confusion`
- **领域:** python
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

使用 --extra-index-url 时，pip 会合并所有索引的候选包并选择最高版本。同名的恶意公共包如果版本更高，会遮蔽预期的私有包。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   pip install --index-url https://private/simple 'internal-lib==1.2.3'
   ```
2. **** (90% 成功率)
   ```
   pip install --index-url https://private/simple --no-index internal-lib  # only if index has it
   ```
3. **** (85% 成功率)
   ```
   pip install -c constraints.txt --extra-index-url https://private/simple internal-lib
   ```

## 无效尝试

- **** — Still merges with PyPI; the public version wins if higher. (95% 失败率)
- **** — Trust does not affect resolution order. (90% 失败率)
