{"record":{"id":"15d656510d98293f","repo":"pypa/pip","slug":"invalid-requirement-req-string-r-exc","errorCode":null,"errorMessage":"Invalid requirement: {req_string!r}: {exc}","messagePattern":"Invalid requirement: (.+?): (.+?)","errorType":"validation","errorClass":"InstallationError","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/req/constructors.py","lineNumber":457,"sourceCode":"        isolated=isolated,\n        hash_options=hash_options,\n        config_settings=config_settings,\n        constraint=constraint,\n        extras=parts.extras,\n        user_supplied=user_supplied,\n    )\n\n\ndef install_req_from_req_string(\n    req_string: str,\n    comes_from: InstallRequirement | None = None,\n    isolated: bool = False,\n    user_supplied: bool = False,\n) -> InstallRequirement:\n    try:\n        req = get_requirement(req_string)\n    except InvalidRequirement as exc:\n        raise InstallationError(f\"Invalid requirement: {req_string!r}: {exc}\")\n\n    domains_not_allowed = [\n        PyPI.file_storage_domain,\n        TestPyPI.file_storage_domain,\n    ]\n    if (\n        req.url\n        and comes_from\n        and comes_from.link\n        and comes_from.link.netloc in domains_not_allowed\n    ):\n        # Explicitly disallow pypi packages that depend on external urls\n        raise InstallationError(\n            \"Packages installed from PyPI cannot depend on packages \"\n            \"which are not also hosted on PyPI.\\n\"\n            f\"{comes_from.name} depends on {req} \"\n        )\n","sourceCodeStart":439,"sourceCodeEnd":475,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/req/constructors.py#L439-L475","documentation":"This variant of 'Invalid requirement' comes from install_req_from_req_string(), which is used to build InstallRequirements from already-parsed dependency strings (e.g. from package metadata Requires-Dist, or from resolver/lock-file data). The string failed packaging.requirements.Requirement parsing.","triggerScenarios":"A package's Requires-Dist metadata contains a malformed PEP 508 string. A lock file or pylock file references a requirement string that cannot be parsed. The resolver passes a dependency string that has a syntax error.","commonSituations":"Upstream package published with broken metadata (rare but happens). A vendored packaging library that is too old to understand newer PEP 508 features like direct URL references. Corrupted or hand-edited lock files. Version mismatch between pip and its vendored packaging.","solutions":["Identify which package's metadata contains the bad string (the comes_from / dependency chain context helps)","Pin to a different version of the offending package that has valid metadata","Upgrade pip to get a newer vendored packaging library that supports the syntax","Report the metadata bug to the upstream package maintainer"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"from pip._vendor.packaging.requirements import Requirement, InvalidRequirement\n\ndef safe_parse_requirement(req_string: str) -> Requirement | None:\n    \"\"\"Returns None if the string is not a valid requirement.\"\"\"\n    try:\n        return Requirement(req_string)\n    except InvalidRequirement:\n        return None","typeGuard":"from pip._vendor.packaging.requirements import Requirement, InvalidRequirement\n\ndef is_parseable_requirement(req_string: str) -> bool:\n    \"\"\"Type guard: True if req_string is valid PEP 508.\"\"\"\n    try:\n        Requirement(req_string)\n        return True\n    except InvalidRequirement:\n        return False","tryCatchPattern":"from pip._internal.exceptions import InstallationError\n\ntry:\n    ireq = install_req_from_req_string(req_string, comes_from=parent)\nexcept InstallationError as e:\n    logger.error(\"Bad metadata from %s: %s\", parent, e)\n    # skip this dependency or pin an alternate version of the parent\n    continue","preventionTips":["Pin packages to versions known to have valid metadata","Upgrade pip to ensure the vendored packaging library supports modern PEP 508 features","Report broken metadata to the upstream package maintainer"],"tags":["pip","pep508","metadata","resolver","parsing"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}