# 错误：在 --require-hashes 模式下，所有需求必须使用 == 固定版本。以下需求未固定：
    requests>=2.0

- **ID:** `python/pip-frozen-requirements-out-of-date`
- **领域:** python
- **类别:** config_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

哈希校验模式要求每个需求都使用 `==` 固定到确切版本，并附带 `--hash` 条目。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   pip install pip-tools && pip-compile --generate-hashes --allow-unsafe requirements.in
   ```
2. **** (90% 成功率)
   ```
   pip-compile --generate-hashes requirements.in  # then pip install --require-hashes -r requirements.txt
   ```

## 无效尝试

- **** — Disables supply-chain integrity verification for the whole environment. (50% 失败率)
- **** — Hashes must match the exact artifact pip downloads; manual entry is error-prone and often wrong. (70% 失败率)
- **** — Does not satisfy the hash requirement for the top-level package. (90% 失败率)
