pypa/pip · error · CommandError

--require-hashes and --no-require-hashes are mutually…

Error message

--require-hashes and --no-require-hashes are mutually exclusive

What it means

Raised as CommandError in RequirementCommand.get_requirements (req_command.py:431) when both --require-hashes and --no-require-hashes are set on the same invocation. Hash-checking mode enforces that every requirement (including transitive deps) carries a hash, providing tamper resistance; --no-require-hashes disables the auto-enabling of that mode when hashed requirements are seen (lines 438-441). Supplying both directly contradicts itself, so pip rejects the combination at line 430.

Solutions

  1. Remove one flag: use --require-hashes to enforce hashes, or --no-require-hashes to disable auto-enabling.
  2. Check pip.conf / PIP_* environment variables for a stray inherited --no-require-hashes or --require-hashes.

Example fix

# before
pip install --require-hashes --no-require-hashes -r requirements.txt
# after
pip install --require-hashes -r requirements.txt
Defensive patterns

Strategy: validation

Validate before calling

# Reject contradictory hash flags before invoking pip.
def validate_hash_flags(opts):
    if opts.get("require_hashes") and opts.get("no_require_hashes"):
        raise ValueError("--require-hashes and --no-require-hashes are mutually exclusive")
    return True

Prevention

When it happens

Trigger: `pip install --require-hashes --no-require-hashes -r requirements.txt`.

Common situations: Combining a hardened/locked install command (which sets --require-hashes) with a global pip config or env that injects --no-require-hashes; editing a script and leaving both flags in.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/edcb5d7952625a5a. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_internal/cli/req_command.py:431

                if not check_requires_python(
                    requires_python=script_requires_python,
                    version_info=target_python.py_version_info,
                ):
                    raise UnsupportedPythonVersion(
                        f"Script {script!r} requires a different Python: "
                        f"{target_python.py_version} not in {script_requires_python!r}"
                    )

            for req in script_metadata.get("dependencies", []):
                req_to_add = install_req_from_req_string(
                    req,
                    isolated=options.isolated_mode,
                    user_supplied=True,
                )
                requirements.append(req_to_add)

        if options.require_hashes and options.no_require_hashes:
            raise CommandError(
                "--require-hashes and --no-require-hashes are mutually exclusive"
            )

        # If any requirement has hash options, enable hash checking for all
        # requirements, unless this mechanism has been explicitly disabled
        # with --no-require-hashes.
        if not options.no_require_hashes and any(
            req.has_hash_options for req in requirements
        ):
            options.require_hashes = True

        if not (
            args
            or options.editables
            or options.requirements
            or options.dependency_groups
            or options.requirements_from_scripts
        ):

View on GitHub (pinned to f399c37189)