# 错误：这些包与需求文件中的哈希值不匹配。如果你更新了包版本，请更新哈希值。否则，请仔细检查包内容；可能有人篡改了它们。

- **ID:** `python/pip-hash-mismatch-download`
- **领域:** python
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

带有 --hash=sha256:... 的 requirements 文件固定了特定产物的哈希值。下载的 wheel/sdist 哈希不同，通常是因为版本更新后未重新生成哈希，或者解析到了不同的平台 wheel。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   pip install pip-tools && pip-compile --generate-hashes requirements.in
   ```
2. **** (88% 成功率)
   ```
   Add another --hash=sha256:<newhash> line to the package entry
   ```
3. **** (80% 成功率)
   ```
   pip download --only-binary=:all: --platform manylinux2014_x86_64 --python-version 311 package && pip hash *.whl
   ```

## 无效尝试

- **** — Hash checking still applies to the directly requested package. (85% 失败率)
- **** — Disables supply-chain protection entirely; defeats the purpose of the pin. (30% 失败率)
