python
config_error
ai_generated
true
错误:索引 URL 'http://pypi.example.com/simple' 不安全。默认情况下 pip 要求所有索引 URL 使用 HTTPS。
ERROR: The index URL 'http://pypi.example.com/simple' is not secure. pip requires HTTPS for all index URLs by default.
ID: python/pip-index-url-http-blocked
80%修复率
88%置信度
0证据数
2024-09-03首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
根因分析
除非显式信任,否则 pip 拒绝纯 HTTP 索引 URL。内部镜像通常仅支持 HTTP,因此 pip 会阻止它们以防止 MITM 篡改。
English
pip refuses plain HTTP index URLs unless explicitly trusted. Internal mirrors are often HTTP-only, so pip blocks them to prevent MITM tampering.
解决方案
-
95% 成功率
pip install --index-url http://pypi.example.com/simple --trusted-host pypi.example.com package
-
92% 成功率
pip config set global.trusted-host pypi.example.com && pip config set global.index-url http://pypi.example.com/simple
-
98% 成功率
Configure the mirror with a valid TLS cert; then use https:// URL
无效尝试
常见但无效的做法:
-
95% 失败
pip still refuses unless --trusted-host is added.
-
90% 失败
Same rejection; the env var does not imply trust.