{"record":{"id":"edcb5d7952625a5a","repo":"pypa/pip","slug":"require-hashes-and-no-require-hashes-are-mutua","errorCode":null,"errorMessage":"--require-hashes and --no-require-hashes are mutually exclusive","messagePattern":"--require-hashes and --no-require-hashes are mutually exclusive","errorType":"exception","errorClass":"CommandError","httpStatus":null,"severity":"error","filePath":"src/pip/_internal/cli/req_command.py","lineNumber":431,"sourceCode":"                if not check_requires_python(\n                    requires_python=script_requires_python,\n                    version_info=target_python.py_version_info,\n                ):\n                    raise UnsupportedPythonVersion(\n                        f\"Script {script!r} requires a different Python: \"\n                        f\"{target_python.py_version} not in {script_requires_python!r}\"\n                    )\n\n            for req in script_metadata.get(\"dependencies\", []):\n                req_to_add = install_req_from_req_string(\n                    req,\n                    isolated=options.isolated_mode,\n                    user_supplied=True,\n                )\n                requirements.append(req_to_add)\n\n        if options.require_hashes and options.no_require_hashes:\n            raise CommandError(\n                \"--require-hashes and --no-require-hashes are mutually exclusive\"\n            )\n\n        # If any requirement has hash options, enable hash checking for all\n        # requirements, unless this mechanism has been explicitly disabled\n        # with --no-require-hashes.\n        if not options.no_require_hashes and any(\n            req.has_hash_options for req in requirements\n        ):\n            options.require_hashes = True\n\n        if not (\n            args\n            or options.editables\n            or options.requirements\n            or options.dependency_groups\n            or options.requirements_from_scripts\n        ):","sourceCodeStart":413,"sourceCodeEnd":449,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/cli/req_command.py#L413-L449","documentation":"Raised as CommandError in RequirementCommand.get_requirements (req_command.py:431) when both --require-hashes and --no-require-hashes are set on the same invocation. Hash-checking mode enforces that every requirement (including transitive deps) carries a hash, providing tamper resistance; --no-require-hashes disables the auto-enabling of that mode when hashed requirements are seen (lines 438-441). Supplying both directly contradicts itself, so pip rejects the combination at line 430.","triggerScenarios":"`pip install --require-hashes --no-require-hashes -r requirements.txt`.","commonSituations":"Combining a hardened/locked install command (which sets --require-hashes) with a global pip config or env that injects --no-require-hashes; editing a script and leaving both flags in.","solutions":["Remove one flag: use --require-hashes to enforce hashes, or --no-require-hashes to disable auto-enabling.","Check pip.conf / PIP_* environment variables for a stray inherited --no-require-hashes or --require-hashes."],"exampleFix":"# before\npip install --require-hashes --no-require-hashes -r requirements.txt\n# after\npip install --require-hashes -r requirements.txt","handlingStrategy":"validation","validationCode":"# Reject contradictory hash flags before invoking pip.\ndef validate_hash_flags(opts):\n    if opts.get(\"require_hashes\") and opts.get(\"no_require_hashes\"):\n        raise ValueError(\"--require-hashes and --no-require-hashes are mutually exclusive\")\n    return True","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Audit pip.conf and PIP_* env vars for inherited hash flags that conflict with CLI args."],"tags":["cli-options","hashes","conflict","command-error"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}