# ERROR: THESE PACKAGES DO NOT MATCH THE HASHES FROM THE REQUIREMENTS FILE. If you have updated the package versions, please update the hashes. Otherwise, examine the package contents carefully; someone may have tampered with them.

- **ID:** `python/pip-hash-mismatch-download`
- **Domain:** python
- **Category:** auth_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

A requirements file with --hash=sha256:... pins a specific artifact hash. The downloaded wheel/sdist has a different hash, usually because the version was updated without regenerating hashes, or a different platform wheel was resolved.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   pip install pip-tools && pip-compile --generate-hashes requirements.in
   ```
2. **** (88% success)
   ```
   Add another --hash=sha256:<newhash> line to the package entry
   ```
3. **** (80% success)
   ```
   pip download --only-binary=:all: --platform manylinux2014_x86_64 --python-version 311 package && pip hash *.whl
   ```

## Dead Ends

- **** — Hash checking still applies to the directly requested package. (85% fail)
- **** — Disables supply-chain protection entirely; defeats the purpose of the pin. (30% fail)
