# ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not:
    requests>=2.0

- **ID:** `python/pip-frozen-requirements-out-of-date`
- **Domain:** python
- **Category:** config_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

Hash-checking mode requires every requirement to be pinned to an exact version with `==` and accompanied by `--hash` entries.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   pip install pip-tools && pip-compile --generate-hashes --allow-unsafe requirements.in
   ```
2. **** (90% success)
   ```
   pip-compile --generate-hashes requirements.in  # then pip install --require-hashes -r requirements.txt
   ```

## Dead Ends

- **** — Disables supply-chain integrity verification for the whole environment. (50% fail)
- **** — Hashes must match the exact artifact pip downloads; manual entry is error-prone and often wrong. (70% fail)
- **** — Does not satisfy the hash requirement for the top-level package. (90% fail)
