{"record":{"id":"c58bbe07b024dbc7","repo":"pypa/pip","slug":"the-editable-requirement-req-cannot-be-installed","errorCode":null,"errorMessage":"The editable requirement {req} cannot be installed when requiring hashes, because there is no single file to hash.","messagePattern":"The editable requirement (.+?) cannot be installed when requiring hashes, because there is no single file to hash\\.","errorType":"exception","errorClass":"InstallationError","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/operations/prepare.py","lineNumber":851,"sourceCode":"\n        download_location = join_within_directory(self.download_dir, link.filename)\n        if not os.path.exists(download_location):\n            shutil.copy(req.local_file_path, download_location)\n            download_path = display_path(download_location)\n            logger.info(\"Saved %s\", download_path)\n\n    def prepare_editable_requirement(\n        self,\n        req: InstallRequirement,\n    ) -> BaseDistribution:\n        \"\"\"Prepare an editable requirement.\"\"\"\n        assert req.editable, \"cannot prepare a non-editable req as editable\"\n\n        logger.info(\"Obtaining %s\", req)\n\n        with indent_log():\n            if self.require_hashes:\n                raise InstallationError(\n                    f\"The editable requirement {req} cannot be installed when \"\n                    \"requiring hashes, because there is no single file to \"\n                    \"hash.\"\n                )\n            req.ensure_has_source_dir(self.src_dir)\n            req.update_editable()\n            assert req.source_dir\n            req.download_info = direct_url_for_editable(req.unpacked_source_directory)\n\n            dist = _get_prepared_distribution(\n                req,\n                self.build_tracker,\n                self.build_env_installer,\n                self.build_isolation,\n                self.check_build_deps,\n                self.allow_editables,\n            )\n","sourceCodeStart":833,"sourceCodeEnd":869,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/operations/prepare.py#L833-L869","documentation":"Raised by prepare_editable_requirement (prepare.py:850) when --require-hashes mode is active and an editable requirement (-e) is being prepared. Editable installs point at a working tree/directory that changes over time, so there is no single immutable artifact to hash, making them fundamentally incompatible with hash verification.","triggerScenarios":"Calling 'pip install --require-hashes -e .' or including an editable requirement in a hashed install. The check is the very first thing prepare_editable_requirement does when self.require_hashes is True.","commonSituations":"Trying to lock down a project for reproducibility/security with --require-hashes while still developing an in-repo package with -e; a requirements file that combines hashes and an -e line.","solutions":["Build the project into a wheel/sdist and install the artifact with a hash instead of using -e.","Install the editable package in a separate step without --require-hashes.","Drop --require-hashes for the environment that needs the editable install."],"exampleFix":"# before\npip install --require-hashes -e .\n# after\npython -m build --wheel\npip install --require-hashes dist/MyProject-1.0-py3-none-any.whl --hash sha256:...","handlingStrategy":"validation","validationCode":"import sys\n\ndef has_editable_in_hashed_install(argv: list[str]) -> bool:\n    require_hashes = '--require-hashes' in argv or any('--hash=' in a for a in argv)\n    has_editable = '-e' in argv or any(a.startswith('-e') for a in argv)\n    return require_hashes and has_editable\n\nif __name__ == '__main__':\n    if has_editable_in_hashed_install(sys.argv):\n        print('ERROR: -e is incompatible with --require-hashes'); sys.exit(1)","typeGuard":"def is_editable_arg(arg: str) -> bool:\n    return arg == '-e' or arg.startswith('-e ') or arg == '--editable' or arg.startswith('--editable=')","tryCatchPattern":"from subprocess import run\n# Build the editable project to a wheel and install with hash instead.\nrun([\"python\", \"-m\", \"build\", \"--wheel\", project_dir], check=True)\nrun([\"pip\", \"install\", \"--require-hashes\", built_wheel], check=True)","preventionTips":["Never combine -e with --require-hashes.","Build local projects to wheels and hash them for locked installs.","Run editable installs in a separate non-hashed environment step."],"tags":["require-hashes","editable","hashing","security","pip"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}