# ERROR: THESE PACKAGES DO NOT MATCH THE HASHES FROM THE REQUIREMENTS FILE. If you have updated the package versions, please update the hashes. Otherwise, examine the package contents carefully; someone may have tampered with them.

- **ID:** `python/pip-install-error-hash-mismatch`
- **Domain:** python
- **Category:** data_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

The downloaded package's hash does not match the hash specified in the requirements file, indicating a version mismatch or tampering.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.x | active | — | — |

## Workarounds

1. **** (90% success)
   ```
   pip hash package.whl  # then update requirements.txt with the new hash
   ```
2. **** (85% success)
   ```
   pip freeze > requirements.txt && pip hash package.whl >> requirements.txt
   ```
3. **** (80% success)
   ```
   pip download package --no-deps -d /tmp && pip install --require-hashes -r requirements.txt
   ```

## Dead Ends

- **** — This bypasses security checks and is not recommended. (80% fail)
- **** — The hash mismatch persists unless the package is updated. (90% fail)
- **** — Force reinstall does not bypass hash verification. (95% fail)
