# 错误：索引 URL 'http://pypi.example.com/simple' 不安全。默认情况下 pip 要求所有索引 URL 使用 HTTPS。

- **ID:** `python/pip-index-url-http-blocked`
- **领域:** python
- **类别:** config_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

除非显式信任，否则 pip 拒绝纯 HTTP 索引 URL。内部镜像通常仅支持 HTTP，因此 pip 会阻止它们以防止 MITM 篡改。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   pip install --index-url http://pypi.example.com/simple --trusted-host pypi.example.com package
   ```
2. **** (92% 成功率)
   ```
   pip config set global.trusted-host pypi.example.com && pip config set global.index-url http://pypi.example.com/simple
   ```
3. **** (98% 成功率)
   ```
   Configure the mirror with a valid TLS cert; then use https:// URL
   ```

## 无效尝试

- **** — pip still refuses unless --trusted-host is added. (95% 失败率)
- **** — Same rejection; the env var does not imply trust. (90% 失败率)
