{"record":{"id":"c891aa1a416ec578","repo":"pypa/pip","slug":"can-t-verify-hashes-for-these-requirements-because","errorCode":null,"errorMessage":"Can't verify hashes for these requirements because we don't have a way to hash version control repositories:","messagePattern":"Can't verify hashes for these requirements because we don't have a way to hash version control repositories:","errorType":"exception","errorClass":"VcsHashUnsupported","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/operations/prepare.py","lineNumber":474,"sourceCode":"            parallel_builds=parallel_builds,\n        )\n        req.ensure_pristine_source_checkout()\n\n    def _get_linked_req_hashes(self, req: InstallRequirement) -> Hashes:\n        # By the time this is called, the requirement's link should have\n        # been checked so we can tell what kind of requirements req is\n        # and raise some more informative errors than otherwise.\n        # (For example, we can raise VcsHashUnsupported for a VCS URL\n        # rather than HashMissing.)\n        if not self.require_hashes:\n            return req.hashes(trust_internet=True)\n\n        # We could check these first 2 conditions inside unpack_url\n        # and save repetition of conditions, but then we would\n        # report less-useful error messages for unhashable\n        # requirements, complaining that there's no hash provided.\n        if req.link.is_vcs:\n            raise VcsHashUnsupported()\n        if req.link.is_existing_dir():\n            raise DirectoryUrlHashUnsupported()\n\n        # Unpinned packages are asking for trouble when a new version\n        # is uploaded.  This isn't a security check, but it saves users\n        # a surprising hash mismatch in the future.\n        # file:/// URLs aren't pinnable, so don't complain about them\n        # not being pinned.\n        if not req.is_direct and not req.is_pinned:\n            raise HashUnpinned()\n\n        # If known-good hashes are missing for this requirement,\n        # shim it with a facade object that will provoke hash\n        # computation and then raise a HashMissing exception\n        # showing the user what the hash should be.\n        return req.hashes(trust_internet=False) or MissingHashes()\n\n    def _fetch_metadata_only(","sourceCodeStart":456,"sourceCodeEnd":492,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/operations/prepare.py#L456-L492","documentation":"Raised by _get_linked_req_hashes (prepare.py:473) as VcsHashUnsupported when pip is in --require-hashes mode and the requirement resolves to a VCS URL (git+/hg+/svn+/bzr+). pip cannot compute a stable cryptographic hash over a version-control checkout, so hash-verification mode is incompatible with VCS requirements.","triggerScenarios":"Running with --require-hashes (or a hashed requirements file) while installing a VCS requirement like 'git+https://.../repo.git'. Detected via req.link.is_vcs before hashes are checked.","commonSituations":"A locked/hashed requirements file that accidentally includes a -e git+... editable or a VCS direct reference; mixing a security-pinned environment with a development VCS dependency.","solutions":["Remove the VCS requirement from the hashed installation set, or install it separately without --require-hashes.","Vendor the VCS project into a local wheel/sdist and pin a hash for that artifact instead.","If only a fixed commit is needed, build a wheel from the checkout and reference the wheel with its hash.","Do not use --require-hashes for environments that legitimately need editable/VCS installs."],"exampleFix":"# before\npip install --require-hashes -r locked.txt   # locked.txt contains: git+https://example/repo.git\n# after: build & hash an artifact instead\npip wheel --no-deps git+https://example/repo.git@<commit> -w ./wheels\npip install --require-hashes ./wheels/Repo-1.0-py3-none-any.whl --hash sha256:...","handlingStrategy":"validation","validationCode":"# Detect VCS requirements before running pip with --require-hashes so they can be excluded/converted.\nfrom pip._internal.vcs import vcs\n\ndef is_vcs_requirement(line: str) -> bool:\n    low = line.lower()\n    return any(low.startswith(s + ':') or low.startswith(s + '+') for s in vcs.all_schemes)\n\ndef no_vcs_in_hashed_file(path: str) -> bool:\n    with open(path) as f:\n        return not any(is_vcs_requirement(l.split('#')[0].strip()) for l in f if l.strip())","typeGuard":"from pip._internal.vcs import vcs\n\ndef is_vcs_url(url: str) -> bool:\n    low = url.lower()\n    return any(low.startswith(s + ':') or low.startswith(s + '+') for s in vcs.all_schemes)","tryCatchPattern":"from subprocess import run, CalledProcessError\ntry:\n    run([\"pip\", \"install\", \"--require-hashes\", \"-r\", req_file], check=True)\nexcept CalledProcessError:\n    # Fallback: build VCS deps into hashed artifacts first.\n    run([\"pip\", \"wheel\", \"--no-deps\", vcs_url, \"-w\", \"./wheels\"], check=True)","preventionTips":["Keep VCS requirements out of hashed requirement sets.","Convert VCS deps to built wheels and hash the artifacts.","Validate requirement files for VCS schemes before enabling --require-hashes."],"tags":["require-hashes","vcs","hashing","security","pip"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}