You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I was reading the documentation and I find this statement about package indexes could be misleading:
Here's an example of setting up the default environment to look at 2 private indices (using context formatting for authentication) before finally falling back to PyPI:
As far as I know this can be true, but one could be tricked into thinking that he could safely set the PIP_INDEX_URL to its private pypi repository and be safe from "dependency confusion" (some pip context, and uv). Is that correct or I am unaware of some extra hatch specific feature?
I was reading the documentation and I find this statement about package indexes could be misleading:
As far as I know this can be true, but one could be tricked into thinking that he could safely set the
PIP_INDEX_URL
to its private pypi repository and be safe from "dependency confusion" (somepip
context, and uv). Is that correct or I am unaware of some extra hatch specific feature?Poetry provides an interesting feature for sourcing dependencies to specific repositories, is this currently possible with hatch?
The text was updated successfully, but these errors were encountered: