python config_error ai_generated true

ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: requests>=2.0

ID: python/pip-frozen-requirements-out-of-date

Also available as: JSON · Markdown · 中文
80%Fix Rate
88%Confidence
0Evidence
2025-10-05First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

Root Cause

Hash-checking mode requires every requirement to be pinned to an exact version with `==` and accompanied by `--hash` entries.

generic

中文

哈希校验模式要求每个需求都使用 `==` 固定到确切版本,并附带 `--hash` 条目。

Workarounds

  1. 95% success
    pip install pip-tools && pip-compile --generate-hashes --allow-unsafe requirements.in
  2. 90% success
    pip-compile --generate-hashes requirements.in  # then pip install --require-hashes -r requirements.txt

Dead Ends

Common approaches that don't work:

  1. 50% fail

    Disables supply-chain integrity verification for the whole environment.

  2. 70% fail

    Hashes must match the exact artifact pip downloads; manual entry is error-prone and often wrong.

  3. 90% fail

    Does not satisfy the hash requirement for the top-level package.