python
config_error
ai_generated
true
ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: requests>=2.0
ID: python/pip-frozen-requirements-out-of-date
80%Fix Rate
88%Confidence
0Evidence
2025-10-05First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
Root Cause
Hash-checking mode requires every requirement to be pinned to an exact version with `==` and accompanied by `--hash` entries.
generic中文
哈希校验模式要求每个需求都使用 `==` 固定到确切版本,并附带 `--hash` 条目。
Workarounds
-
95% success
pip install pip-tools && pip-compile --generate-hashes --allow-unsafe requirements.in
-
90% success
pip-compile --generate-hashes requirements.in # then pip install --require-hashes -r requirements.txt
Dead Ends
Common approaches that don't work:
-
50% fail
Disables supply-chain integrity verification for the whole environment.
-
70% fail
Hashes must match the exact artifact pip downloads; manual entry is error-prone and often wrong.
-
90% fail
Does not satisfy the hash requirement for the top-level package.