python config_error ai_generated true

错误:在 --require-hashes 模式下,所有需求必须使用 == 固定版本。以下需求未固定: requests>=2.0

ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: requests>=2.0

ID: python/pip-frozen-requirements-out-of-date

其他格式: JSON · Markdown 中文 · English
80%修复率
88%置信度
0证据数
2025-10-05首次发现

版本兼容性

版本状态引入弃用备注
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

根因分析

哈希校验模式要求每个需求都使用 `==` 固定到确切版本,并附带 `--hash` 条目。

English

Hash-checking mode requires every requirement to be pinned to an exact version with `==` and accompanied by `--hash` entries.

generic

解决方案

  1. 95% 成功率
    pip install pip-tools && pip-compile --generate-hashes --allow-unsafe requirements.in
  2. 90% 成功率
    pip-compile --generate-hashes requirements.in  # then pip install --require-hashes -r requirements.txt

无效尝试

常见但无效的做法:

  1. 50% 失败

    Disables supply-chain integrity verification for the whole environment.

  2. 70% 失败

    Hashes must match the exact artifact pip downloads; manual entry is error-prone and often wrong.

  3. 90% 失败

    Does not satisfy the hash requirement for the top-level package.