python
data_error
ai_generated
true
ERROR: THESE PACKAGES DO NOT MATCH THE HASHES FROM THE REQUIREMENTS FILE. If you have updated the package versions, please update the hashes. Otherwise, examine the package contents carefully; someone may have tampered with them.
ID: python/pip-install-error-hash-mismatch
80%Fix Rate
87%Confidence
0Evidence
2025-02-14First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 3.x | active | — | — | — |
Root Cause
The downloaded package's hash does not match the hash specified in the requirements file, indicating a version mismatch or tampering.
generic中文
下载的包的哈希值与 requirements 文件中指定的哈希值不匹配,表明版本不匹配或篡改。
Workarounds
-
90% success
pip hash package.whl # then update requirements.txt with the new hash
-
85% success
pip freeze > requirements.txt && pip hash package.whl >> requirements.txt
-
80% success
pip download package --no-deps -d /tmp && pip install --require-hashes -r requirements.txt
Dead Ends
Common approaches that don't work:
-
80% fail
This bypasses security checks and is not recommended.
-
90% fail
The hash mismatch persists unless the package is updated.
-
95% fail
Force reinstall does not bypass hash verification.